Overview

A CloudWatch Alarm that triggers if there is API activity in the account without MFA (Multi-Factor Authentication).

Configuration Templates

Items
2
Size
1.0 KB
Missing Parameters
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
  CloudWatchAlarm:
    Type: 'AWS::CloudWatch::Alarm'
    Properties:
      AlarmName: no_mfa_api_activity
      AlarmDescription: >-
        A CloudWatch Alarm that triggers if there is API activity in the account
        without MFA (Multi-Factor Authentication).
      MetricName: ApiActivityWithoutMFACount
      Namespace: CloudTrailMetrics
      Statistic: Sum
      Period: '300'
      EvaluationPeriods: '1'
      Threshold: '1'
      ComparisonOperator: GreaterThanOrEqualToThreshold
      AlarmActions:
        - ''
      TreatMissingData: notBreaching
  MetricFilter:
    Type: 'AWS::Logs::MetricFilter'
    Properties:
      LogGroupName: ''
      FilterPattern: '{ $.userIdentity.sessionContext.attributes.mfaAuthenticated != "true" }'
      MetricTransformations:
        - MetricValue: '1'
          MetricNamespace: CloudTrailMetrics
          MetricName: ApiActivityWithoutMFACount
Parameters: {}
Metadata: {}
Conditions: {}

Actions


Customize Cf Template

Alarm Configuration


Metric Filter Configuration


* Required field

Sources and Documentation

Configuration Source: AWS Dpcumentation

Additional Documentation: