Watch Desk posted an update
AWS has added CloudWatch analytics for Route 53 Global Resolver and DNS Firewall, giving network teams a way to inspect DNS query patterns and check how firewall rules are working.
Why it mattersCustomers can filter metrics for events such as blocked queries or DNS response codes, then set alarms. AWS gives one example: alerting when more than 10 DNS queries are blocked for a VPC within an hour. The analytics are available in Regions where the services are supported. CloudWatch charges apply to metrics customers opt into, so the new dashboard is not quite a free lunch.
Discuss: Should cloud providers make security analytics opt-in, or enable useful monitoring by default even when it can add costs?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.