Elasticsearch domains should have error logging to CloudWatch Logs enabled

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This control confirms whether Elasticsearch domains are configured to forward error logs to CloudWatch Logs.

It’s recommended to enable error logging for Elasticsearch domains and forward these logs to CloudWatch Logs for retention and analysis. Error logs from the domain can play a key role in security and access audits and can help in diagnosing availability issues.

Remediation

For details on how to activate log publishing, refer to the Enabling log publishing (console) section in the Amazon OpenSearch Service Developer Guide.