Choose the MemoryDB cluster for which you want to enable audit logging. Click on the cluster name to access its details page.
Enable Amazon CloudWatch Logs
In the cluster details page, navigate to the Logging section.
Click on Modify to edit the logging settings.
Select the option to enable CloudWatch Logs.
Choose an existing CloudWatch log group or create a new one to store the logs generated by the MemoryDB cluster activities.
Optionally, you can specify a log retention period to define how long the logs will be stored.
Click Apply Changes to enable CloudWatch Logs for the MemoryDB cluster.
Configure CloudWatch Logs
Open the CloudWatch console by navigating to CloudWatch in the AWS Management Console.
In the left-side menu, click on Logs.
Create a new log group or select an existing log group that will store the MemoryDB logs.
Configure log retention settings based on your retention requirements. Logs can be stored for a specific number of days or indefinitely.
Define any necessary log group permissions to control access to the logs.
Optionally, set up log exports or alarms for specific log events or patterns if needed.
Verify Logging Status
Wait a few minutes for the changes to propagate and the logging configuration to take effect.
Refresh the cluster details page to see the updated logging status.
Verify that CloudWatch Logs is enabled for the MemoryDB cluster.
Monitor and Analyze Logs
Navigate to the CloudWatch console and select the log group that stores the MemoryDB logs.
Monitor the logs to gain insights into the activities and operations performed on your MemoryDB cluster.
Use CloudWatch Logs features, such as log searching, filtering, and visualization, to analyze the logs and identify any security or operational issues.
Establish appropriate log monitoring and alerting mechanisms to proactively identify and respond to potential security incidents or operational anomalies.
Expected Result
CloudWatch Logs is enabled for all MemoryDB clusters with appropriate log groups and retention periods configured.
Remediation
Using AWS Console
Follow the audit procedure steps to enable CloudWatch Logs for each MemoryDB cluster and configure appropriate log retention and monitoring.
Default Value
Audit logging is not enabled by default for Amazon MemoryDB for Redis.
8.1 Establish and Maintain an Audit Log Management Process
X
X
X
v7
6.2 Activate audit logging
X
X
X
Profile
Level 1 | Manual
1---2name: cis-aws-database-6-43description: Ensure Audit Logging is Enabled4---56# 6.4 Ensure Audit Logging is Enabled (Manual)78## Description910Enabling audit logging on Amazon MemoryDB allows you to capture and store logs of activities performed on your clusters.1112## Rationale1314It captures and saves logs of activities that took place in the cluster.1516## Impact1718Reduces risks of any fraud since worker activity is being monitored and tracked.1920## Audit Procedure2122### Using AWS Console23241. Sign into the AWS Management Console25 - Sign into the AWS Management Console at https://console.aws.amazon.com/ with your AWS account credentials.26272. Open the Amazon MemoryDB Console28 - Navigate to the service using the `Find Services` search bar or by directly accessing the console at https://console.aws.amazon.com/memorydb/.29303. Select the Cluster31 - Choose the MemoryDB cluster for which you want to enable audit logging. Click on the cluster name to access its details page.32334. Enable Amazon CloudWatch Logs34 - In the cluster details page, navigate to the `Logging` section.35 - Click on `Modify` to edit the logging settings.36 - Select the option to enable CloudWatch Logs.37 - Choose an existing CloudWatch log group or create a new one to store the logs generated by the MemoryDB cluster activities.38 - Optionally, you can specify a log retention period to define how long the logs will be stored.39 - Click `Apply Changes` to enable CloudWatch Logs for the MemoryDB cluster.40415. Configure CloudWatch Logs42 - Open the CloudWatch console by navigating to `CloudWatch` in the AWS Management Console.43 - In the left-side menu, click on `Logs`.44 - Create a new log group or select an existing log group that will store the MemoryDB logs.45 - Configure log retention settings based on your retention requirements. Logs can be stored for a specific number of days or indefinitely.46 - Define any necessary log group permissions to control access to the logs.47 - Optionally, set up log exports or alarms for specific log events or patterns if needed.48496. Verify Logging Status50 - Wait a few minutes for the changes to propagate and the logging configuration to take effect.51 - Refresh the cluster details page to see the updated logging status.52 - Verify that CloudWatch Logs is enabled for the MemoryDB cluster.53547. Monitor and Analyze Logs55 - Navigate to the CloudWatch console and select the log group that stores the MemoryDB logs.56 - Monitor the logs to gain insights into the activities and operations performed on your MemoryDB cluster.57 - Use CloudWatch Logs features, such as log searching, filtering, and visualization, to analyze the logs and identify any security or operational issues.58 - Establish appropriate log monitoring and alerting mechanisms to proactively identify and respond to potential security incidents or operational anomalies.5960## Expected Result6162CloudWatch Logs is enabled for all MemoryDB clusters with appropriate log groups and retention periods configured.6364## Remediation6566### Using AWS Console6768Follow the audit procedure steps to enable CloudWatch Logs for each MemoryDB cluster and configure appropriate log retention and monitoring.6970## Default Value7172Audit logging is not enabled by default for Amazon MemoryDB for Redis.7374## References75761. https://aws.amazon.com/products/databases/7778## CIS Controls7980| Controls Version | Control | IG 1 | IG 2 | IG 3 |81| ---------------- | ---------------------------------------------------------- | ---- | ---- | ---- |82| v8 | 8.1 Establish and Maintain an Audit Log Management Process | X | X | X |83| v7 | 6.2 Activate audit logging | X | X | X |8485## Profile8687Level 1 | Manual
Run npx skillmds@latest add cyberstrikeus/cis-aws-database-6-4 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Ensure Audit Logging is Enabled It is listed under DevOps & Infra on SkillMD.
SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
cyberstrikeus (@cyberstrikeus) published this skill. Their other Agent Skills are listed on their SkillMD profile.