Elasticsearch domains should have audit logs enabled

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This control confirms that audit logging is enabled for Elasticsearch domains. Audit logs allow extensive customization, enabling the monitoring of user activities in Elasticsearch clusters. This includes tracking both successful and failed authentication attempts, OpenSearch requests, index modifications, and incoming search queries. This check only verifies that audit logging is enabled, and does not require specific parameters.

Remediation

For detailed instructions on enabling audit logging, see Enabling audit logs in the Amazon OpenSearch Service Developer Guide.