CloudWatch Observability Admin Service

2026/08/03 - CloudWatch Observability Admin Service - 9 updated api methods

Changes  Launch CMK support for Telemetry Enablement Organization and Account Rules.

CreateCentralizationRuleForOrganization (updated) Link ¶
Changes (request)
{'Rule': {'Destination': {'DestinationLogsConfiguration': {'LogsEncryptionConfiguration': {'EncryptionScope': 'ENCRYPTED_SOURCE_ONLY '
                                                                                                              '| '
                                                                                                              'NEW_DESTINATION_LOG_GROUPS'}}}}}

Creates a centralization rule that applies across an Amazon Web Services Organization. This operation can only be called by the organization's management account or a delegated administrator account.

See also: AWS API Documentation

Request Syntax

client.create_centralization_rule_for_organization(
    RuleName='string',
    Rule={
        'Source': {
            'Regions': [
                'string',
            ],
            'Scope': 'string',
            'SourceLogsConfiguration': {
                'LogGroupSelectionCriteria': 'string',
                'DataSourceSelectionCriteria': 'string',
                'EncryptedLogGroupStrategy': 'ALLOW'|'SKIP'
            },
            'SourceMetricsConfiguration': {
                'MetricsSelectionCriteria': 'string'
            }
        },
        'Destination': {
            'Region': 'string',
            'Account': 'string',
            'DestinationLogsConfiguration': {
                'LogsEncryptionConfiguration': {
                    'EncryptionStrategy': 'CUSTOMER_MANAGED'|'AWS_OWNED',
                    'KmsKeyArn': 'string',
                    'EncryptionConflictResolutionStrategy': 'ALLOW'|'SKIP',
                    'EncryptionScope': 'ENCRYPTED_SOURCE_ONLY'|'NEW_DESTINATION_LOG_GROUPS'
                },
                'BackupConfiguration': {
                    'Region': 'string',
                    'KmsKeyArn': 'string'
                },
                'LogGroupNameConfiguration': {
                    'LogGroupNamePattern': 'string'
                }
            },
            'DestinationMetricsConfiguration': {
                'BackupConfiguration': {
                    'Region': 'string'
                }
            }
        }
    },
    Tags={
        'string': 'string'
    }
)
type RuleName:

string

param RuleName:

[REQUIRED]

A unique name for the organization-wide centralization rule being created.

type Rule:

dict

param Rule:

[REQUIRED]

The configuration details for the organization-wide centralization rule, including the source configuration and the destination configuration to centralize telemetry data across the organization.

  • Source (dict) -- [REQUIRED]

    Configuration determining the source of the telemetry data to be centralized.

    • Regions (list) -- [REQUIRED]

      The list of source regions from which telemetry data should be centralized.

      • (string) --

    • Scope (string) --

      The organizational scope from which telemetry data should be centralized, specified using organization id, accounts or organizational unit ids.

    • SourceLogsConfiguration (dict) --

      Log specific configuration for centralization source log groups.

      • LogGroupSelectionCriteria (string) --

        The selection criteria that specifies which source log groups to centralize. The selection criteria uses the same format as OAM link filters.

      • DataSourceSelectionCriteria (string) --

        The selection criteria that specifies which data sources to centralize. The selection criteria uses the same filter expression format as LogGroupSelectionCriteria, but operates on DataSourceName and DataSourceType operands. When both LogGroupSelectionCriteria and DataSourceSelectionCriteria are specified, a log event must match both criteria to be centralized.

      • EncryptedLogGroupStrategy (string) -- [REQUIRED]

        A strategy determining whether to centralize source log groups that are encrypted with customer managed KMS keys (CMK). ALLOW will consider CMK encrypted source log groups for centralization while SKIP will skip CMK encrypted source log groups from centralization.

    • SourceMetricsConfiguration (dict) --

      Metric specific configuration for centralization source metrics.

      • MetricsSelectionCriteria (string) --

        The filter expression that selects which source metrics to centralize. Currently, only * (all metrics) is supported. Other values return a validation error.

  • Destination (dict) -- [REQUIRED]

    Configuration determining where the telemetry data should be centralized, backed up, as well as encryption configuration for the primary and backup destinations.

    • Region (string) -- [REQUIRED]

      The primary destination region to which telemetry data should be centralized.

    • Account (string) --

      The destination account (within the organization) to which the telemetry data should be centralized.

    • DestinationLogsConfiguration (dict) --

      Log specific configuration for centralization destination log groups.

      • LogsEncryptionConfiguration (dict) --

        The encryption configuration for centralization destination log groups.

        • EncryptionStrategy (string) -- [REQUIRED]

          Configuration that determines the encryption strategy of the destination log groups. CUSTOMER_MANAGED uses the configured KmsKeyArn to encrypt newly created destination log groups.

        • KmsKeyArn (string) --

          KMS Key ARN belonging to the primary destination account and region, to encrypt newly created central log groups in the primary destination.

        • EncryptionConflictResolutionStrategy (string) --

          Conflict resolution strategy for centralization if the encryption strategy is set to CUSTOMER_MANAGED and the destination log group is encrypted with an AWS_OWNED KMS Key. ALLOW lets centralization go through while SKIP prevents centralization into the destination log group.

        • EncryptionScope (string) --

          Determines which newly created destination log groups are encrypted with the configured KmsKeyArn when EncryptionStrategy is CUSTOMER_MANAGED.

          If you set this to ENCRYPTED_SOURCE_ONLY (the default), only destination log groups whose source log group is encrypted with a customer managed KMS key use the configured KmsKeyArn. Destination log groups derived from Amazon Web Services owned encrypted source log groups remain Amazon Web Services owned encrypted.

          If you set this to NEW_DESTINATION_LOG_GROUPS, every new destination log group created by this rule uses the configured KmsKeyArn, regardless of the source log group's encryption posture.

          This field is not valid when EncryptionStrategy is AWS_OWNED.

      • BackupConfiguration (dict) --

        Configuration defining the backup region and an optional KMS key for the backup destination.

        • Region (string) -- [REQUIRED]

          Logs specific backup destination region within the primary destination account to which log data should be centralized.

        • KmsKeyArn (string) --

          KMS Key ARN belonging to the primary destination account and backup region, to encrypt newly created central log groups in the backup destination.

      • LogGroupNameConfiguration (dict) --

        Configuration that specifies a naming pattern for destination log groups created during centralization. The pattern supports static text and dynamic variables that are replaced with source attributes when log groups are created.

        • LogGroupNamePattern (string) -- [REQUIRED]

          The pattern used to generate destination log group names during centralization. The pattern can contain static text and dynamic variables that are replaced with source attributes. If a variable cannot be resolved, it inherits the value from its parent variable in the hierarchy. The pattern must be between 1 and 512 characters.

          Supported variables:

          • ${source.logGroup} — The original log group name from the source account.

          • ${source.accountId} — The Amazon Web Services account ID where the log originated.

          • ${source.region} — The Amazon Web Services Region where the log originated.

          • ${source.org.id} — The Amazon Web Services Organization ID of the source account.

          • ${source.org.ouId} — The organizational unit ID of the source account.

          • ${source.org.rootId} — The organization Root ID.

          • ${source.org.path} — The organizational path from account to root.

    • DestinationMetricsConfiguration (dict) --

      Metric specific configuration for centralization destination metrics.

      • BackupConfiguration (dict) --

        Configuration defining the backup region for the metrics backup destination.

        • Region (string) -- [REQUIRED]

          Metrics specific backup destination region within the primary destination account to which metrics data should be centralized.

type Tags:

dict

param Tags:

The key-value pairs to associate with the organization telemetry rule resource for categorization and management purposes.

  • (string) --

    • (string) --

rtype:

dict

returns:

Response Syntax

{
    'RuleArn': 'string'
}

Response Structure

  • (dict) --

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the created organization centralization rule.

CreateTelemetryRule (updated) Link ¶
Changes (request)
{'Rule': {'DestinationConfiguration': {'KmsKeyArn': 'string'}}}

Creates a telemetry rule that defines how telemetry should be configured for Amazon Web Services resources in your account. The rule specifies which resources should have telemetry enabled and how that telemetry data should be collected based on resource type, telemetry type, and selection criteria.

See also: AWS API Documentation

Request Syntax

client.create_telemetry_rule(
    RuleName='string',
    Rule={
        'ResourceType': 'AWS::EC2::Instance'|'AWS::EC2::VPC'|'AWS::Lambda::Function'|'AWS::CloudTrail'|'AWS::EKS::Cluster'|'AWS::WAFv2::WebACL'|'AWS::ElasticLoadBalancingV2::LoadBalancer'|'AWS::Route53Resolver::ResolverEndpoint'|'AWS::BedrockAgentCore::Runtime'|'AWS::BedrockAgentCore::Browser'|'AWS::BedrockAgentCore::CodeInterpreter'|'AWS::BedrockAgentCore::Gateway'|'AWS::BedrockAgentCore::Memory'|'AWS::BedrockAgentCore::WorkloadIdentity'|'AWS::SecurityHub::Hub'|'AWS::CloudFront::Distribution'|'AWS::SecurityHub::HubV2'|'AWS::CloudWatch::OTelEnrichment'|'AWS::MSK::Cluster'|'AWS::S3::Bucket'|'AWS::Bedrock::KnowledgeBase',
        'TelemetryType': 'Logs'|'Metrics'|'Traces',
        'TelemetrySourceTypes': [
            'VPC_FLOW_LOGS'|'ROUTE53_RESOLVER_QUERY_LOGS'|'EKS_AUDIT_LOGS'|'EKS_AUTHENTICATOR_LOGS'|'EKS_CONTROLLER_MANAGER_LOGS'|'EKS_SCHEDULER_LOGS'|'EKS_API_LOGS',
        ],
        'DestinationConfiguration': {
            'DestinationType': 'cloud-watch-logs',
            'DestinationPattern': 'string',
            'RetentionInDays': 123,
            'VPCFlowLogParameters': {
                'LogFormat': 'string',
                'TrafficType': 'string',
                'MaxAggregationInterval': 123
            },
            'CloudtrailParameters': {
                'AdvancedEventSelectors': [
                    {
                        'Name': 'string',
                        'FieldSelectors': [
                            {
                                'Field': 'string',
                                'Equals': [
                                    'string',
                                ],
                                'StartsWith': [
                                    'string',
                                ],
                                'EndsWith': [
                                    'string',
                                ],
                                'NotEquals': [
                                    'string',
                                ],
                                'NotStartsWith': [
                                    'string',
                                ],
                                'NotEndsWith': [
                                    'string',
                                ]
                            },
                        ]
                    },
                ]
            },
            'ELBLoadBalancerLoggingParameters': {
                'OutputFormat': 'plain'|'json',
                'FieldDelimiter': 'string'
            },
            'WAFLoggingParameters': {
                'RedactedFields': [
                    {
                        'SingleHeader': {
                            'Name': 'string'
                        },
                        'UriPath': 'string',
                        'QueryString': 'string',
                        'Method': 'string'
                    },
                ],
                'LoggingFilter': {
                    'Filters': [
                        {
                            'Behavior': 'KEEP'|'DROP',
                            'Requirement': 'MEETS_ALL'|'MEETS_ANY',
                            'Conditions': [
                                {
                                    'ActionCondition': {
                                        'Action': 'ALLOW'|'BLOCK'|'COUNT'|'CAPTCHA'|'CHALLENGE'|'EXCLUDED_AS_COUNT'
                                    },
                                    'LabelNameCondition': {
                                        'LabelName': 'string'
                                    }
                                },
                            ]
                        },
                    ],
                    'DefaultBehavior': 'KEEP'|'DROP'
                },
                'LogType': 'WAF_LOGS'
            },
            'LogDeliveryParameters': {
                'LogTypes': [
                    'APPLICATION_LOGS'|'USAGE_LOGS'|'SECURITY_FINDING_LOGS'|'ACCESS_LOGS'|'CONNECTION_LOGS'|'S3_SERVER_ACCESS_LOGS'|'ALB_ACCESS_LOGS'|'ALB_CONNECTION_LOGS'|'ALB_HEALTH_CHECK_LOGS',
                ]
            },
            'MskMonitoringParameters': {
                'EnhancedMonitoring': 'DEFAULT'|'PER_BROKER'|'PER_TOPIC_PER_BROKER'|'PER_TOPIC_PER_PARTITION'
            },
            'KmsKeyArn': 'string'
        },
        'Scope': 'string',
        'SelectionCriteria': 'string',
        'AllowFieldUpdates': True|False,
        'Regions': [
            'string',
        ],
        'AllRegions': True|False
    },
    Tags={
        'string': 'string'
    }
)
type RuleName:

string

param RuleName:

[REQUIRED]

A unique name for the telemetry rule being created.

type Rule:

dict

param Rule:

[REQUIRED]

The configuration details for the telemetry rule, including the resource type, telemetry type, destination configuration, and selection criteria for which resources the rule applies to.

  • ResourceType (string) --

    The type of Amazon Web Services resource to configure telemetry for (for example, AWS::EC2::VPC, AWS::EKS::Cluster, AWS::ElasticLoadBalancingV2::LoadBalancer, or AWS::Bedrock::KnowledgeBase).

  • TelemetryType (string) -- [REQUIRED]

    The type of telemetry to collect (Logs, Metrics, or Traces).

  • TelemetrySourceTypes (list) --

    The specific telemetry source types to configure for the resource, such as VPC_FLOW_LOGS or EKS_AUDIT_LOGS. TelemetrySourceTypes must be correlated with the specific resource type.

    • (string) --

      Specifies the type of telemetry source for a resource, such as EKS cluster logs.

  • DestinationConfiguration (dict) --

    Configuration specifying where and how the telemetry data should be delivered.

    • DestinationType (string) --

      The type of destination for the telemetry data (e.g., "Amazon CloudWatch Logs", "S3").

    • DestinationPattern (string) --

      The pattern used to generate the destination path or name, supporting macros like <resourceId> and <accountId>.

    • RetentionInDays (integer) --

      The number of days to retain the telemetry data in the destination.

    • VPCFlowLogParameters (dict) --

      Configuration parameters specific to VPC Flow Logs when VPC is the resource type.

      • LogFormat (string) --

        The format in which VPC Flow Log entries should be logged.

      • TrafficType (string) --

        The type of traffic to log (ACCEPT, REJECT, or ALL).

      • MaxAggregationInterval (integer) --

        The maximum interval in seconds between the capture of flow log records.

    • CloudtrailParameters (dict) --

      Configuration parameters specific to Amazon Web Services CloudTrail when CloudTrail is the source type.

      • AdvancedEventSelectors (list) -- [REQUIRED]

        The advanced event selectors to use for filtering Amazon Web Services CloudTrail events.

        • (dict) --

          Advanced event selectors let you create fine-grained selectors for management, data, and network activity events.

          • Name (string) --

            An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".

          • FieldSelectors (list) -- [REQUIRED]

            Contains all selector statements in an advanced event selector.

            • (dict) --

              Defines criteria for selecting resources based on field values.

              • Field (string) -- [REQUIRED]

                The name of the field to use for selection.

              • Equals (list) --

                Matches if the field value equals the specified value.

                • (string) --

              • StartsWith (list) --

                Matches if the field value starts with the specified value.

                • (string) --

              • EndsWith (list) --

                Matches if the field value ends with the specified value.

                • (string) --

              • NotEquals (list) --

                Matches if the field value does not equal the specified value.

                • (string) --

              • NotStartsWith (list) --

                Matches if the field value does not start with the specified value.

                • (string) --

              • NotEndsWith (list) --

                Matches if the field value does not end with the specified value.

                • (string) --

    • ELBLoadBalancerLoggingParameters (dict) --

      Configuration parameters specific to ELB load balancer logging when ELB is the resource type.

      • OutputFormat (string) --

        The format for ELB access log entries (plain text or JSON format).

      • FieldDelimiter (string) --

        The delimiter character used to separate fields in ELB access log entries when using plain text format.

    • WAFLoggingParameters (dict) --

      Configuration parameters specific to WAF logging when WAF is the resource type.

      • RedactedFields (list) --

        The fields to redact from WAF logs to protect sensitive information.

        • (dict) --

          Specifies a field in the request to redact from WAF logs, such as headers, query parameters, or body content.

          • SingleHeader (dict) --

            Redacts a specific header field by name from WAF logs.

            • Name (string) --

              The name value, limited to 64 characters.

          • UriPath (string) --

            Redacts the URI path from WAF logs.

          • QueryString (string) --

            Redacts the entire query string from WAF logs.

          • Method (string) --

            Redacts the HTTP method from WAF logs.

      • LoggingFilter (dict) --

        A filter configuration that determines which WAF log records to include or exclude.

        • Filters (list) --

          A list of filter conditions that determine log record handling behavior.

          • (dict) --

            A single filter condition that specifies behavior, requirement, and matching conditions for WAF log records.

            • Behavior (string) --

              The action to take for log records matching this filter (KEEP or DROP).

            • Requirement (string) --

              Whether the log record must meet all conditions (MEETS_ALL) or any condition (MEETS_ANY) to match this filter.

            • Conditions (list) --

              The list of conditions that determine if a log record matches this filter.

              • (dict) --

                A single condition that can match based on WAF rule action or label name.

                • ActionCondition (dict) --

                  Matches log records based on the WAF rule action taken (ALLOW, BLOCK, COUNT, etc.).

                  • Action (string) --

                    The WAF action to match against (ALLOW, BLOCK, COUNT, CAPTCHA, CHALLENGE, EXCLUDED_AS_COUNT).

                • LabelNameCondition (dict) --

                  Matches log records based on WAF rule labels applied to the request.

                  • LabelName (string) --

                    The label name to match, supporting alphanumeric characters, underscores, hyphens, and colons.

        • DefaultBehavior (string) --

          The default action (KEEP or DROP) for log records that don't match any filter conditions.

      • LogType (string) --

        The type of WAF logs to collect (currently supports WAF_LOGS).

    • LogDeliveryParameters (dict) --

      The configuration parameters for log delivery when the resource type supports configurable log types, such as Amazon Bedrock Knowledge Bases or Elastic Load Balancing Application Load Balancers.

      • LogTypes (list) --

        The types of logs to collect from the resource.

        • (string) --

          The following log types are supported for log delivery configuration:

          • APPLICATION_LOGS – Application-level logs.

          • USAGE_LOGS – Resource usage logs.

          • SECURITY_FINDING_LOGS – Security finding logs.

          • ACCESS_LOGS – Access logs (such as Elastic Load Balancing access logs).

          • CONNECTION_LOGS – Connection logs.

          • S3_SERVER_ACCESS_LOGS – Amazon S3 server access logs.

    • MskMonitoringParameters (dict) --

      Configuration parameters specific to MSK monitoring when MSK is the resource type.

      • EnhancedMonitoring (string) --

        The level of enhanced monitoring for the MSK cluster.

    • KmsKeyArn (string) --

      The Amazon Resource Name (ARN) of the customer-managed Amazon Web Services KMS key used to encrypt the log groups created during telemetry rule remediation.

  • Scope (string) --

    The organizational scope to which the rule applies, specified using accounts or organizational units.

  • SelectionCriteria (string) --

    Criteria for selecting which resources the rule applies to, such as resource tags.

  • AllowFieldUpdates (boolean) --

    If set to true, Amazon CloudWatch Observability Admin detects and remediates configuration drift in telemetry resources that it manages. For example, if a VPC flow log's format, traffic type, or aggregation interval no longer matches the rule's destination configuration, the flow log is replaced with one that matches. Only Observability Admin-managed resources are updated; customer-created resources are never modified. Currently supported for AWS::EC2::VPC resources (VPC flow logs).

  • Regions (list) --

    An optional list of Amazon Web Services Regions where this telemetry rule should be replicated. When specified, the rule is created in the home region and automatically replicated to all listed regions. Mutually exclusive with AllRegions.

    • (string) --

  • AllRegions (boolean) --

    If set to true, the telemetry rule is replicated to all Amazon Web Services Regions where Amazon CloudWatch Observability Admin is available in the current partition. When new regions become available, the rule automatically replicates to them. Mutually exclusive with Regions.

type Tags:

dict

param Tags:

The key-value pairs to associate with the telemetry rule resource for categorization and management purposes.

  • (string) --

    • (string) --

rtype:

dict

returns:

Response Syntax

{
    'RuleArn': 'string'
}

Response Structure

  • (dict) --

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the created telemetry rule.

CreateTelemetryRuleForOrganization (updated) Link ¶
Changes (request)
{'Rule': {'DestinationConfiguration': {'KmsKeyArn': 'string'}}}

Creates a telemetry rule that applies across an Amazon Web Services Organization. This operation can only be called by the organization's management account or a delegated administrator account.

See also: AWS API Documentation

Request Syntax

client.create_telemetry_rule_for_organization(
    RuleName='string',
    Rule={
        'ResourceType': 'AWS::EC2::Instance'|'AWS::EC2::VPC'|'AWS::Lambda::Function'|'AWS::CloudTrail'|'AWS::EKS::Cluster'|'AWS::WAFv2::WebACL'|'AWS::ElasticLoadBalancingV2::LoadBalancer'|'AWS::Route53Resolver::ResolverEndpoint'|'AWS::BedrockAgentCore::Runtime'|'AWS::BedrockAgentCore::Browser'|'AWS::BedrockAgentCore::CodeInterpreter'|'AWS::BedrockAgentCore::Gateway'|'AWS::BedrockAgentCore::Memory'|'AWS::BedrockAgentCore::WorkloadIdentity'|'AWS::SecurityHub::Hub'|'AWS::CloudFront::Distribution'|'AWS::SecurityHub::HubV2'|'AWS::CloudWatch::OTelEnrichment'|'AWS::MSK::Cluster'|'AWS::S3::Bucket'|'AWS::Bedrock::KnowledgeBase',
        'TelemetryType': 'Logs'|'Metrics'|'Traces',
        'TelemetrySourceTypes': [
            'VPC_FLOW_LOGS'|'ROUTE53_RESOLVER_QUERY_LOGS'|'EKS_AUDIT_LOGS'|'EKS_AUTHENTICATOR_LOGS'|'EKS_CONTROLLER_MANAGER_LOGS'|'EKS_SCHEDULER_LOGS'|'EKS_API_LOGS',
        ],
        'DestinationConfiguration': {
            'DestinationType': 'cloud-watch-logs',
            'DestinationPattern': 'string',
            'RetentionInDays': 123,
            'VPCFlowLogParameters': {
                'LogFormat': 'string',
                'TrafficType': 'string',
                'MaxAggregationInterval': 123
            },
            'CloudtrailParameters': {
                'AdvancedEventSelectors': [
                    {
                        'Name': 'string',
                        'FieldSelectors': [
                            {
                                'Field': 'string',
                                'Equals': [
                                    'string',
                                ],
                                'StartsWith': [
                                    'string',
                                ],
                                'EndsWith': [
                                    'string',
                                ],
                                'NotEquals': [
                                    'string',
                                ],
                                'NotStartsWith': [
                                    'string',
                                ],
                                'NotEndsWith': [
                                    'string',
                                ]
                            },
                        ]
                    },
                ]
            },
            'ELBLoadBalancerLoggingParameters': {
                'OutputFormat': 'plain'|'json',
                'FieldDelimiter': 'string'
            },
            'WAFLoggingParameters': {
                'RedactedFields': [
                    {
                        'SingleHeader': {
                            'Name': 'string'
                        },
                        'UriPath': 'string',
                        'QueryString': 'string',
                        'Method': 'string'
                    },
                ],
                'LoggingFilter': {
                    'Filters': [
                        {
                            'Behavior': 'KEEP'|'DROP',
                            'Requirement': 'MEETS_ALL'|'MEETS_ANY',
                            'Conditions': [
                                {
                                    'ActionCondition': {
                                        'Action': 'ALLOW'|'BLOCK'|'COUNT'|'CAPTCHA'|'CHALLENGE'|'EXCLUDED_AS_COUNT'
                                    },
                                    'LabelNameCondition': {
                                        'LabelName': 'string'
                                    }
                                },
                            ]
                        },
                    ],
                    'DefaultBehavior': 'KEEP'|'DROP'
                },
                'LogType': 'WAF_LOGS'
            },
            'LogDeliveryParameters': {
                'LogTypes': [
                    'APPLICATION_LOGS'|'USAGE_LOGS'|'SECURITY_FINDING_LOGS'|'ACCESS_LOGS'|'CONNECTION_LOGS'|'S3_SERVER_ACCESS_LOGS'|'ALB_ACCESS_LOGS'|'ALB_CONNECTION_LOGS'|'ALB_HEALTH_CHECK_LOGS',
                ]
            },
            'MskMonitoringParameters': {
                'EnhancedMonitoring': 'DEFAULT'|'PER_BROKER'|'PER_TOPIC_PER_BROKER'|'PER_TOPIC_PER_PARTITION'
            },
            'KmsKeyArn': 'string'
        },
        'Scope': 'string',
        'SelectionCriteria': 'string',
        'AllowFieldUpdates': True|False,
        'Regions': [
            'string',
        ],
        'AllRegions': True|False
    },
    Tags={
        'string': 'string'
    }
)
type RuleName:

string

param RuleName:

[REQUIRED]

A unique name for the organization-wide telemetry rule being created.

type Rule:

dict

param Rule:

[REQUIRED]

The configuration details for the organization-wide telemetry rule, including the resource type, telemetry type, destination configuration, and selection criteria for which resources the rule applies to across the organization.

  • ResourceType (string) --

    The type of Amazon Web Services resource to configure telemetry for (for example, AWS::EC2::VPC, AWS::EKS::Cluster, AWS::ElasticLoadBalancingV2::LoadBalancer, or AWS::Bedrock::KnowledgeBase).

  • TelemetryType (string) -- [REQUIRED]

    The type of telemetry to collect (Logs, Metrics, or Traces).

  • TelemetrySourceTypes (list) --

    The specific telemetry source types to configure for the resource, such as VPC_FLOW_LOGS or EKS_AUDIT_LOGS. TelemetrySourceTypes must be correlated with the specific resource type.

    • (string) --

      Specifies the type of telemetry source for a resource, such as EKS cluster logs.

  • DestinationConfiguration (dict) --

    Configuration specifying where and how the telemetry data should be delivered.

    • DestinationType (string) --

      The type of destination for the telemetry data (e.g., "Amazon CloudWatch Logs", "S3").

    • DestinationPattern (string) --

      The pattern used to generate the destination path or name, supporting macros like <resourceId> and <accountId>.

    • RetentionInDays (integer) --

      The number of days to retain the telemetry data in the destination.

    • VPCFlowLogParameters (dict) --

      Configuration parameters specific to VPC Flow Logs when VPC is the resource type.

      • LogFormat (string) --

        The format in which VPC Flow Log entries should be logged.

      • TrafficType (string) --

        The type of traffic to log (ACCEPT, REJECT, or ALL).

      • MaxAggregationInterval (integer) --

        The maximum interval in seconds between the capture of flow log records.

    • CloudtrailParameters (dict) --

      Configuration parameters specific to Amazon Web Services CloudTrail when CloudTrail is the source type.

      • AdvancedEventSelectors (list) -- [REQUIRED]

        The advanced event selectors to use for filtering Amazon Web Services CloudTrail events.

        • (dict) --

          Advanced event selectors let you create fine-grained selectors for management, data, and network activity events.

          • Name (string) --

            An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".

          • FieldSelectors (list) -- [REQUIRED]

            Contains all selector statements in an advanced event selector.

            • (dict) --

              Defines criteria for selecting resources based on field values.

              • Field (string) -- [REQUIRED]

                The name of the field to use for selection.

              • Equals (list) --

                Matches if the field value equals the specified value.

                • (string) --

              • StartsWith (list) --

                Matches if the field value starts with the specified value.

                • (string) --

              • EndsWith (list) --

                Matches if the field value ends with the specified value.

                • (string) --

              • NotEquals (list) --

                Matches if the field value does not equal the specified value.

                • (string) --

              • NotStartsWith (list) --

                Matches if the field value does not start with the specified value.

                • (string) --

              • NotEndsWith (list) --

                Matches if the field value does not end with the specified value.

                • (string) --

    • ELBLoadBalancerLoggingParameters (dict) --

      Configuration parameters specific to ELB load balancer logging when ELB is the resource type.

      • OutputFormat (string) --

        The format for ELB access log entries (plain text or JSON format).

      • FieldDelimiter (string) --

        The delimiter character used to separate fields in ELB access log entries when using plain text format.

    • WAFLoggingParameters (dict) --

      Configuration parameters specific to WAF logging when WAF is the resource type.

      • RedactedFields (list) --

        The fields to redact from WAF logs to protect sensitive information.

        • (dict) --

          Specifies a field in the request to redact from WAF logs, such as headers, query parameters, or body content.

          • SingleHeader (dict) --

            Redacts a specific header field by name from WAF logs.

            • Name (string) --

              The name value, limited to 64 characters.

          • UriPath (string) --

            Redacts the URI path from WAF logs.

          • QueryString (string) --

            Redacts the entire query string from WAF logs.

          • Method (string) --

            Redacts the HTTP method from WAF logs.

      • LoggingFilter (dict) --

        A filter configuration that determines which WAF log records to include or exclude.

        • Filters (list) --

          A list of filter conditions that determine log record handling behavior.

          • (dict) --

            A single filter condition that specifies behavior, requirement, and matching conditions for WAF log records.

            • Behavior (string) --

              The action to take for log records matching this filter (KEEP or DROP).

            • Requirement (string) --

              Whether the log record must meet all conditions (MEETS_ALL) or any condition (MEETS_ANY) to match this filter.

            • Conditions (list) --

              The list of conditions that determine if a log record matches this filter.

              • (dict) --

                A single condition that can match based on WAF rule action or label name.

                • ActionCondition (dict) --

                  Matches log records based on the WAF rule action taken (ALLOW, BLOCK, COUNT, etc.).

                  • Action (string) --

                    The WAF action to match against (ALLOW, BLOCK, COUNT, CAPTCHA, CHALLENGE, EXCLUDED_AS_COUNT).

                • LabelNameCondition (dict) --

                  Matches log records based on WAF rule labels applied to the request.

                  • LabelName (string) --

                    The label name to match, supporting alphanumeric characters, underscores, hyphens, and colons.

        • DefaultBehavior (string) --

          The default action (KEEP or DROP) for log records that don't match any filter conditions.

      • LogType (string) --

        The type of WAF logs to collect (currently supports WAF_LOGS).

    • LogDeliveryParameters (dict) --

      The configuration parameters for log delivery when the resource type supports configurable log types, such as Amazon Bedrock Knowledge Bases or Elastic Load Balancing Application Load Balancers.

      • LogTypes (list) --

        The types of logs to collect from the resource.

        • (string) --

          The following log types are supported for log delivery configuration:

          • APPLICATION_LOGS – Application-level logs.

          • USAGE_LOGS – Resource usage logs.

          • SECURITY_FINDING_LOGS – Security finding logs.

          • ACCESS_LOGS – Access logs (such as Elastic Load Balancing access logs).

          • CONNECTION_LOGS – Connection logs.

          • S3_SERVER_ACCESS_LOGS – Amazon S3 server access logs.

    • MskMonitoringParameters (dict) --

      Configuration parameters specific to MSK monitoring when MSK is the resource type.

      • EnhancedMonitoring (string) --

        The level of enhanced monitoring for the MSK cluster.

    • KmsKeyArn (string) --

      The Amazon Resource Name (ARN) of the customer-managed Amazon Web Services KMS key used to encrypt the log groups created during telemetry rule remediation.

  • Scope (string) --

    The organizational scope to which the rule applies, specified using accounts or organizational units.

  • SelectionCriteria (string) --

    Criteria for selecting which resources the rule applies to, such as resource tags.

  • AllowFieldUpdates (boolean) --

    If set to true, Amazon CloudWatch Observability Admin detects and remediates configuration drift in telemetry resources that it manages. For example, if a VPC flow log's format, traffic type, or aggregation interval no longer matches the rule's destination configuration, the flow log is replaced with one that matches. Only Observability Admin-managed resources are updated; customer-created resources are never modified. Currently supported for AWS::EC2::VPC resources (VPC flow logs).

  • Regions (list) --

    An optional list of Amazon Web Services Regions where this telemetry rule should be replicated. When specified, the rule is created in the home region and automatically replicated to all listed regions. Mutually exclusive with AllRegions.

    • (string) --

  • AllRegions (boolean) --

    If set to true, the telemetry rule is replicated to all Amazon Web Services Regions where Amazon CloudWatch Observability Admin is available in the current partition. When new regions become available, the rule automatically replicates to them. Mutually exclusive with Regions.

type Tags:

dict

param Tags:

The key-value pairs to associate with the organization telemetry rule resource for categorization and management purposes.

  • (string) --

    • (string) --

rtype:

dict

returns:

Response Syntax

{
    'RuleArn': 'string'
}

Response Structure

  • (dict) --

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the created organization telemetry rule.

GetCentralizationRuleForOrganization (updated) Link ¶
Changes (response)
{'CentralizationRule': {'Destination': {'DestinationLogsConfiguration': {'LogsEncryptionConfiguration': {'EncryptionScope': 'ENCRYPTED_SOURCE_ONLY '
                                                                                                                            '| '
                                                                                                                            'NEW_DESTINATION_LOG_GROUPS'}}}}}

Retrieves the details of a specific organization centralization rule. This operation can only be called by the organization's management account or a delegated administrator account.

See also: AWS API Documentation

Request Syntax

client.get_centralization_rule_for_organization(
    RuleIdentifier='string'
)
type RuleIdentifier:

string

param RuleIdentifier:

[REQUIRED]

The identifier (name or ARN) of the organization centralization rule to retrieve.

rtype:

dict

returns:

Response Syntax

{
    'RuleName': 'string',
    'RuleArn': 'string',
    'CreatorAccountId': 'string',
    'CreatedTimeStamp': 123,
    'CreatedRegion': 'string',
    'LastUpdateTimeStamp': 123,
    'RuleHealth': 'Healthy'|'Unhealthy'|'Provisioning',
    'FailureReason': 'TRUSTED_ACCESS_NOT_ENABLED'|'DESTINATION_ACCOUNT_NOT_IN_ORGANIZATION'|'INTERNAL_SERVER_ERROR',
    'CentralizationRule': {
        'Source': {
            'Regions': [
                'string',
            ],
            'Scope': 'string',
            'SourceLogsConfiguration': {
                'LogGroupSelectionCriteria': 'string',
                'DataSourceSelectionCriteria': 'string',
                'EncryptedLogGroupStrategy': 'ALLOW'|'SKIP'
            },
            'SourceMetricsConfiguration': {
                'MetricsSelectionCriteria': 'string'
            }
        },
        'Destination': {
            'Region': 'string',
            'Account': 'string',
            'DestinationLogsConfiguration': {
                'LogsEncryptionConfiguration': {
                    'EncryptionStrategy': 'CUSTOMER_MANAGED'|'AWS_OWNED',
                    'KmsKeyArn': 'string',
                    'EncryptionConflictResolutionStrategy': 'ALLOW'|'SKIP',
                    'EncryptionScope': 'ENCRYPTED_SOURCE_ONLY'|'NEW_DESTINATION_LOG_GROUPS'
                },
                'BackupConfiguration': {
                    'Region': 'string',
                    'KmsKeyArn': 'string'
                },
                'LogGroupNameConfiguration': {
                    'LogGroupNamePattern': 'string'
                }
            },
            'DestinationMetricsConfiguration': {
                'BackupConfiguration': {
                    'Region': 'string'
                }
            }
        }
    }
}

Response Structure

  • (dict) --

    • RuleName (string) --

      The name of the organization centralization rule.

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the organization centralization rule.

    • CreatorAccountId (string) --

      The Amazon Web Services Account that created the organization centralization rule.

    • CreatedTimeStamp (integer) --

      The timestamp when the organization centralization rule was created.

    • CreatedRegion (string) --

      The Amazon Web Services region where the organization centralization rule was created.

    • LastUpdateTimeStamp (integer) --

      The timestamp when the organization centralization rule was last updated.

    • RuleHealth (string) --

      The health status of the organization centralization rule.

    • FailureReason (string) --

      The reason why an organization centralization rule is marked UNHEALTHY.

    • CentralizationRule (dict) --

      The configuration details for the organization centralization rule.

      • Source (dict) --

        Configuration determining the source of the telemetry data to be centralized.

        • Regions (list) --

          The list of source regions from which telemetry data should be centralized.

          • (string) --

        • Scope (string) --

          The organizational scope from which telemetry data should be centralized, specified using organization id, accounts or organizational unit ids.

        • SourceLogsConfiguration (dict) --

          Log specific configuration for centralization source log groups.

          • LogGroupSelectionCriteria (string) --

            The selection criteria that specifies which source log groups to centralize. The selection criteria uses the same format as OAM link filters.

          • DataSourceSelectionCriteria (string) --

            The selection criteria that specifies which data sources to centralize. The selection criteria uses the same filter expression format as LogGroupSelectionCriteria, but operates on DataSourceName and DataSourceType operands. When both LogGroupSelectionCriteria and DataSourceSelectionCriteria are specified, a log event must match both criteria to be centralized.

          • EncryptedLogGroupStrategy (string) --

            A strategy determining whether to centralize source log groups that are encrypted with customer managed KMS keys (CMK). ALLOW will consider CMK encrypted source log groups for centralization while SKIP will skip CMK encrypted source log groups from centralization.

        • SourceMetricsConfiguration (dict) --

          Metric specific configuration for centralization source metrics.

          • MetricsSelectionCriteria (string) --

            The filter expression that selects which source metrics to centralize. Currently, only * (all metrics) is supported. Other values return a validation error.

      • Destination (dict) --

        Configuration determining where the telemetry data should be centralized, backed up, as well as encryption configuration for the primary and backup destinations.

        • Region (string) --

          The primary destination region to which telemetry data should be centralized.

        • Account (string) --

          The destination account (within the organization) to which the telemetry data should be centralized.

        • DestinationLogsConfiguration (dict) --

          Log specific configuration for centralization destination log groups.

          • LogsEncryptionConfiguration (dict) --

            The encryption configuration for centralization destination log groups.

            • EncryptionStrategy (string) --

              Configuration that determines the encryption strategy of the destination log groups. CUSTOMER_MANAGED uses the configured KmsKeyArn to encrypt newly created destination log groups.

            • KmsKeyArn (string) --

              KMS Key ARN belonging to the primary destination account and region, to encrypt newly created central log groups in the primary destination.

            • EncryptionConflictResolutionStrategy (string) --

              Conflict resolution strategy for centralization if the encryption strategy is set to CUSTOMER_MANAGED and the destination log group is encrypted with an AWS_OWNED KMS Key. ALLOW lets centralization go through while SKIP prevents centralization into the destination log group.

            • EncryptionScope (string) --

              Determines which newly created destination log groups are encrypted with the configured KmsKeyArn when EncryptionStrategy is CUSTOMER_MANAGED.

              If you set this to ENCRYPTED_SOURCE_ONLY (the default), only destination log groups whose source log group is encrypted with a customer managed KMS key use the configured KmsKeyArn. Destination log groups derived from Amazon Web Services owned encrypted source log groups remain Amazon Web Services owned encrypted.

              If you set this to NEW_DESTINATION_LOG_GROUPS, every new destination log group created by this rule uses the configured KmsKeyArn, regardless of the source log group's encryption posture.

              This field is not valid when EncryptionStrategy is AWS_OWNED.

          • BackupConfiguration (dict) --

            Configuration defining the backup region and an optional KMS key for the backup destination.

            • Region (string) --

              Logs specific backup destination region within the primary destination account to which log data should be centralized.

            • KmsKeyArn (string) --

              KMS Key ARN belonging to the primary destination account and backup region, to encrypt newly created central log groups in the backup destination.

          • LogGroupNameConfiguration (dict) --

            Configuration that specifies a naming pattern for destination log groups created during centralization. The pattern supports static text and dynamic variables that are replaced with source attributes when log groups are created.

            • LogGroupNamePattern (string) --

              The pattern used to generate destination log group names during centralization. The pattern can contain static text and dynamic variables that are replaced with source attributes. If a variable cannot be resolved, it inherits the value from its parent variable in the hierarchy. The pattern must be between 1 and 512 characters.

              Supported variables:

              • ${source.logGroup} — The original log group name from the source account.

              • ${source.accountId} — The Amazon Web Services account ID where the log originated.

              • ${source.region} — The Amazon Web Services Region where the log originated.

              • ${source.org.id} — The Amazon Web Services Organization ID of the source account.

              • ${source.org.ouId} — The organizational unit ID of the source account.

              • ${source.org.rootId} — The organization Root ID.

              • ${source.org.path} — The organizational path from account to root.

        • DestinationMetricsConfiguration (dict) --

          Metric specific configuration for centralization destination metrics.

          • BackupConfiguration (dict) --

            Configuration defining the backup region for the metrics backup destination.

            • Region (string) --

              Metrics specific backup destination region within the primary destination account to which metrics data should be centralized.

GetTelemetryRule (updated) Link ¶
Changes (response)
{'TelemetryRule': {'DestinationConfiguration': {'KmsKeyArn': 'string'}}}

Retrieves the details of a specific telemetry rule in your account.

See also: AWS API Documentation

Request Syntax

client.get_telemetry_rule(
    RuleIdentifier='string'
)
type RuleIdentifier:

string

param RuleIdentifier:

[REQUIRED]

The identifier (name or ARN) of the telemetry rule to retrieve.

rtype:

dict

returns:

Response Syntax

{
    'RuleName': 'string',
    'RuleArn': 'string',
    'CreatedTimeStamp': 123,
    'LastUpdateTimeStamp': 123,
    'TelemetryRule': {
        'ResourceType': 'AWS::EC2::Instance'|'AWS::EC2::VPC'|'AWS::Lambda::Function'|'AWS::CloudTrail'|'AWS::EKS::Cluster'|'AWS::WAFv2::WebACL'|'AWS::ElasticLoadBalancingV2::LoadBalancer'|'AWS::Route53Resolver::ResolverEndpoint'|'AWS::BedrockAgentCore::Runtime'|'AWS::BedrockAgentCore::Browser'|'AWS::BedrockAgentCore::CodeInterpreter'|'AWS::BedrockAgentCore::Gateway'|'AWS::BedrockAgentCore::Memory'|'AWS::BedrockAgentCore::WorkloadIdentity'|'AWS::SecurityHub::Hub'|'AWS::CloudFront::Distribution'|'AWS::SecurityHub::HubV2'|'AWS::CloudWatch::OTelEnrichment'|'AWS::MSK::Cluster'|'AWS::S3::Bucket'|'AWS::Bedrock::KnowledgeBase',
        'TelemetryType': 'Logs'|'Metrics'|'Traces',
        'TelemetrySourceTypes': [
            'VPC_FLOW_LOGS'|'ROUTE53_RESOLVER_QUERY_LOGS'|'EKS_AUDIT_LOGS'|'EKS_AUTHENTICATOR_LOGS'|'EKS_CONTROLLER_MANAGER_LOGS'|'EKS_SCHEDULER_LOGS'|'EKS_API_LOGS',
        ],
        'DestinationConfiguration': {
            'DestinationType': 'cloud-watch-logs',
            'DestinationPattern': 'string',
            'RetentionInDays': 123,
            'VPCFlowLogParameters': {
                'LogFormat': 'string',
                'TrafficType': 'string',
                'MaxAggregationInterval': 123
            },
            'CloudtrailParameters': {
                'AdvancedEventSelectors': [
                    {
                        'Name': 'string',
                        'FieldSelectors': [
                            {
                                'Field': 'string',
                                'Equals': [
                                    'string',
                                ],
                                'StartsWith': [
                                    'string',
                                ],
                                'EndsWith': [
                                    'string',
                                ],
                                'NotEquals': [
                                    'string',
                                ],
                                'NotStartsWith': [
                                    'string',
                                ],
                                'NotEndsWith': [
                                    'string',
                                ]
                            },
                        ]
                    },
                ]
            },
            'ELBLoadBalancerLoggingParameters': {
                'OutputFormat': 'plain'|'json',
                'FieldDelimiter': 'string'
            },
            'WAFLoggingParameters': {
                'RedactedFields': [
                    {
                        'SingleHeader': {
                            'Name': 'string'
                        },
                        'UriPath': 'string',
                        'QueryString': 'string',
                        'Method': 'string'
                    },
                ],
                'LoggingFilter': {
                    'Filters': [
                        {
                            'Behavior': 'KEEP'|'DROP',
                            'Requirement': 'MEETS_ALL'|'MEETS_ANY',
                            'Conditions': [
                                {
                                    'ActionCondition': {
                                        'Action': 'ALLOW'|'BLOCK'|'COUNT'|'CAPTCHA'|'CHALLENGE'|'EXCLUDED_AS_COUNT'
                                    },
                                    'LabelNameCondition': {
                                        'LabelName': 'string'
                                    }
                                },
                            ]
                        },
                    ],
                    'DefaultBehavior': 'KEEP'|'DROP'
                },
                'LogType': 'WAF_LOGS'
            },
            'LogDeliveryParameters': {
                'LogTypes': [
                    'APPLICATION_LOGS'|'USAGE_LOGS'|'SECURITY_FINDING_LOGS'|'ACCESS_LOGS'|'CONNECTION_LOGS'|'S3_SERVER_ACCESS_LOGS'|'ALB_ACCESS_LOGS'|'ALB_CONNECTION_LOGS'|'ALB_HEALTH_CHECK_LOGS',
                ]
            },
            'MskMonitoringParameters': {
                'EnhancedMonitoring': 'DEFAULT'|'PER_BROKER'|'PER_TOPIC_PER_BROKER'|'PER_TOPIC_PER_PARTITION'
            },
            'KmsKeyArn': 'string'
        },
        'Scope': 'string',
        'SelectionCriteria': 'string',
        'AllowFieldUpdates': True|False,
        'Regions': [
            'string',
        ],
        'AllRegions': True|False
    },
    'HomeRegion': 'string',
    'IsReplicated': True|False,
    'RegionStatuses': [
        {
            'Region': 'string',
            'Status': 'string',
            'FailureReason': 'string',
            'RuleArn': 'string'
        },
    ]
}

Response Structure

  • (dict) --

    • RuleName (string) --

      The name of the telemetry rule.

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the telemetry rule.

    • CreatedTimeStamp (integer) --

      The timestamp when the telemetry rule was created.

    • LastUpdateTimeStamp (integer) --

      The timestamp when the telemetry rule was last updated.

    • TelemetryRule (dict) --

      The configuration details of the telemetry rule.

      • ResourceType (string) --

        The type of Amazon Web Services resource to configure telemetry for (for example, AWS::EC2::VPC, AWS::EKS::Cluster, AWS::ElasticLoadBalancingV2::LoadBalancer, or AWS::Bedrock::KnowledgeBase).

      • TelemetryType (string) --

        The type of telemetry to collect (Logs, Metrics, or Traces).

      • TelemetrySourceTypes (list) --

        The specific telemetry source types to configure for the resource, such as VPC_FLOW_LOGS or EKS_AUDIT_LOGS. TelemetrySourceTypes must be correlated with the specific resource type.

        • (string) --

          Specifies the type of telemetry source for a resource, such as EKS cluster logs.

      • DestinationConfiguration (dict) --

        Configuration specifying where and how the telemetry data should be delivered.

        • DestinationType (string) --

          The type of destination for the telemetry data (e.g., "Amazon CloudWatch Logs", "S3").

        • DestinationPattern (string) --

          The pattern used to generate the destination path or name, supporting macros like <resourceId> and <accountId>.

        • RetentionInDays (integer) --

          The number of days to retain the telemetry data in the destination.

        • VPCFlowLogParameters (dict) --

          Configuration parameters specific to VPC Flow Logs when VPC is the resource type.

          • LogFormat (string) --

            The format in which VPC Flow Log entries should be logged.

          • TrafficType (string) --

            The type of traffic to log (ACCEPT, REJECT, or ALL).

          • MaxAggregationInterval (integer) --

            The maximum interval in seconds between the capture of flow log records.

        • CloudtrailParameters (dict) --

          Configuration parameters specific to Amazon Web Services CloudTrail when CloudTrail is the source type.

          • AdvancedEventSelectors (list) --

            The advanced event selectors to use for filtering Amazon Web Services CloudTrail events.

            • (dict) --

              Advanced event selectors let you create fine-grained selectors for management, data, and network activity events.

              • Name (string) --

                An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".

              • FieldSelectors (list) --

                Contains all selector statements in an advanced event selector.

                • (dict) --

                  Defines criteria for selecting resources based on field values.

                  • Field (string) --

                    The name of the field to use for selection.

                  • Equals (list) --

                    Matches if the field value equals the specified value.

                    • (string) --

                  • StartsWith (list) --

                    Matches if the field value starts with the specified value.

                    • (string) --

                  • EndsWith (list) --

                    Matches if the field value ends with the specified value.

                    • (string) --

                  • NotEquals (list) --

                    Matches if the field value does not equal the specified value.

                    • (string) --

                  • NotStartsWith (list) --

                    Matches if the field value does not start with the specified value.

                    • (string) --

                  • NotEndsWith (list) --

                    Matches if the field value does not end with the specified value.

                    • (string) --

        • ELBLoadBalancerLoggingParameters (dict) --

          Configuration parameters specific to ELB load balancer logging when ELB is the resource type.

          • OutputFormat (string) --

            The format for ELB access log entries (plain text or JSON format).

          • FieldDelimiter (string) --

            The delimiter character used to separate fields in ELB access log entries when using plain text format.

        • WAFLoggingParameters (dict) --

          Configuration parameters specific to WAF logging when WAF is the resource type.

          • RedactedFields (list) --

            The fields to redact from WAF logs to protect sensitive information.

            • (dict) --

              Specifies a field in the request to redact from WAF logs, such as headers, query parameters, or body content.

              • SingleHeader (dict) --

                Redacts a specific header field by name from WAF logs.

                • Name (string) --

                  The name value, limited to 64 characters.

              • UriPath (string) --

                Redacts the URI path from WAF logs.

              • QueryString (string) --

                Redacts the entire query string from WAF logs.

              • Method (string) --

                Redacts the HTTP method from WAF logs.

          • LoggingFilter (dict) --

            A filter configuration that determines which WAF log records to include or exclude.

            • Filters (list) --

              A list of filter conditions that determine log record handling behavior.

              • (dict) --

                A single filter condition that specifies behavior, requirement, and matching conditions for WAF log records.

                • Behavior (string) --

                  The action to take for log records matching this filter (KEEP or DROP).

                • Requirement (string) --

                  Whether the log record must meet all conditions (MEETS_ALL) or any condition (MEETS_ANY) to match this filter.

                • Conditions (list) --

                  The list of conditions that determine if a log record matches this filter.

                  • (dict) --

                    A single condition that can match based on WAF rule action or label name.

                    • ActionCondition (dict) --

                      Matches log records based on the WAF rule action taken (ALLOW, BLOCK, COUNT, etc.).

                      • Action (string) --

                        The WAF action to match against (ALLOW, BLOCK, COUNT, CAPTCHA, CHALLENGE, EXCLUDED_AS_COUNT).

                    • LabelNameCondition (dict) --

                      Matches log records based on WAF rule labels applied to the request.

                      • LabelName (string) --

                        The label name to match, supporting alphanumeric characters, underscores, hyphens, and colons.

            • DefaultBehavior (string) --

              The default action (KEEP or DROP) for log records that don't match any filter conditions.

          • LogType (string) --

            The type of WAF logs to collect (currently supports WAF_LOGS).

        • LogDeliveryParameters (dict) --

          The configuration parameters for log delivery when the resource type supports configurable log types, such as Amazon Bedrock Knowledge Bases or Elastic Load Balancing Application Load Balancers.

          • LogTypes (list) --

            The types of logs to collect from the resource.

            • (string) --

              The following log types are supported for log delivery configuration:

              • APPLICATION_LOGS – Application-level logs.

              • USAGE_LOGS – Resource usage logs.

              • SECURITY_FINDING_LOGS – Security finding logs.

              • ACCESS_LOGS – Access logs (such as Elastic Load Balancing access logs).

              • CONNECTION_LOGS – Connection logs.

              • S3_SERVER_ACCESS_LOGS – Amazon S3 server access logs.

        • MskMonitoringParameters (dict) --

          Configuration parameters specific to MSK monitoring when MSK is the resource type.

          • EnhancedMonitoring (string) --

            The level of enhanced monitoring for the MSK cluster.

        • KmsKeyArn (string) --

          The Amazon Resource Name (ARN) of the customer-managed Amazon Web Services KMS key used to encrypt the log groups created during telemetry rule remediation.

      • Scope (string) --

        The organizational scope to which the rule applies, specified using accounts or organizational units.

      • SelectionCriteria (string) --

        Criteria for selecting which resources the rule applies to, such as resource tags.

      • AllowFieldUpdates (boolean) --

        If set to true, Amazon CloudWatch Observability Admin detects and remediates configuration drift in telemetry resources that it manages. For example, if a VPC flow log's format, traffic type, or aggregation interval no longer matches the rule's destination configuration, the flow log is replaced with one that matches. Only Observability Admin-managed resources are updated; customer-created resources are never modified. Currently supported for AWS::EC2::VPC resources (VPC flow logs).

      • Regions (list) --

        An optional list of Amazon Web Services Regions where this telemetry rule should be replicated. When specified, the rule is created in the home region and automatically replicated to all listed regions. Mutually exclusive with AllRegions.

        • (string) --

      • AllRegions (boolean) --

        If set to true, the telemetry rule is replicated to all Amazon Web Services Regions where Amazon CloudWatch Observability Admin is available in the current partition. When new regions become available, the rule automatically replicates to them. Mutually exclusive with Regions.

    • HomeRegion (string) --

      The Amazon Web Services Region where the telemetry rule was originally created. For replicated rules in spoke regions, this indicates the region that manages the rule. For rules created without multi-region scope, this field is not present.

    • IsReplicated (boolean) --

      Indicates whether this telemetry rule is a replica that was created in this region through multi-region fan-out from the home region. Replicated rules cannot be directly updated or deleted in the spoke region. To modify a replicated rule, make changes in the home region.

    • RegionStatuses (list) --

      A list of per-region replication statuses for the telemetry rule. Each entry indicates the replication status of the rule in a specific spoke region. This field is only present for rules created with multi-region scope.

      • (dict) --

        Represents the status of a multi-region operation in a specific Amazon Web Services Region. This structure is used to report per-region progress for both telemetry evaluation and telemetry rule replication.

        • Region (string) --

          The Amazon Web Services Region code (for example, eu-west-1 or us-west-2) that this status applies to.

        • Status (string) --

          The status of the operation in this region. For telemetry evaluation, valid values include STARTING, RUNNING, and FAILED_START. For telemetry rules, valid values include PENDING, ACTIVE, and FAILED.

        • FailureReason (string) --

          The reason for a failure status in this region. This field is only populated when Status indicates a failure.

        • RuleArn (string) --

          The Amazon Resource Name (ARN) of the telemetry rule in this spoke region. This field is only present for telemetry rule region statuses and is populated when the rule has been successfully created in the spoke region (status is ACTIVE).

GetTelemetryRuleForOrganization (updated) Link ¶
Changes (response)
{'TelemetryRule': {'DestinationConfiguration': {'KmsKeyArn': 'string'}}}

Retrieves the details of a specific organization telemetry rule. This operation can only be called by the organization's management account or a delegated administrator account.

See also: AWS API Documentation

Request Syntax

client.get_telemetry_rule_for_organization(
    RuleIdentifier='string'
)
type RuleIdentifier:

string

param RuleIdentifier:

[REQUIRED]

The identifier (name or ARN) of the organization telemetry rule to retrieve.

rtype:

dict

returns:

Response Syntax

{
    'RuleName': 'string',
    'RuleArn': 'string',
    'CreatedTimeStamp': 123,
    'LastUpdateTimeStamp': 123,
    'TelemetryRule': {
        'ResourceType': 'AWS::EC2::Instance'|'AWS::EC2::VPC'|'AWS::Lambda::Function'|'AWS::CloudTrail'|'AWS::EKS::Cluster'|'AWS::WAFv2::WebACL'|'AWS::ElasticLoadBalancingV2::LoadBalancer'|'AWS::Route53Resolver::ResolverEndpoint'|'AWS::BedrockAgentCore::Runtime'|'AWS::BedrockAgentCore::Browser'|'AWS::BedrockAgentCore::CodeInterpreter'|'AWS::BedrockAgentCore::Gateway'|'AWS::BedrockAgentCore::Memory'|'AWS::BedrockAgentCore::WorkloadIdentity'|'AWS::SecurityHub::Hub'|'AWS::CloudFront::Distribution'|'AWS::SecurityHub::HubV2'|'AWS::CloudWatch::OTelEnrichment'|'AWS::MSK::Cluster'|'AWS::S3::Bucket'|'AWS::Bedrock::KnowledgeBase',
        'TelemetryType': 'Logs'|'Metrics'|'Traces',
        'TelemetrySourceTypes': [
            'VPC_FLOW_LOGS'|'ROUTE53_RESOLVER_QUERY_LOGS'|'EKS_AUDIT_LOGS'|'EKS_AUTHENTICATOR_LOGS'|'EKS_CONTROLLER_MANAGER_LOGS'|'EKS_SCHEDULER_LOGS'|'EKS_API_LOGS',
        ],
        'DestinationConfiguration': {
            'DestinationType': 'cloud-watch-logs',
            'DestinationPattern': 'string',
            'RetentionInDays': 123,
            'VPCFlowLogParameters': {
                'LogFormat': 'string',
                'TrafficType': 'string',
                'MaxAggregationInterval': 123
            },
            'CloudtrailParameters': {
                'AdvancedEventSelectors': [
                    {
                        'Name': 'string',
                        'FieldSelectors': [
                            {
                                'Field': 'string',
                                'Equals': [
                                    'string',
                                ],
                                'StartsWith': [
                                    'string',
                                ],
                                'EndsWith': [
                                    'string',
                                ],
                                'NotEquals': [
                                    'string',
                                ],
                                'NotStartsWith': [
                                    'string',
                                ],
                                'NotEndsWith': [
                                    'string',
                                ]
                            },
                        ]
                    },
                ]
            },
            'ELBLoadBalancerLoggingParameters': {
                'OutputFormat': 'plain'|'json',
                'FieldDelimiter': 'string'
            },
            'WAFLoggingParameters': {
                'RedactedFields': [
                    {
                        'SingleHeader': {
                            'Name': 'string'
                        },
                        'UriPath': 'string',
                        'QueryString': 'string',
                        'Method': 'string'
                    },
                ],
                'LoggingFilter': {
                    'Filters': [
                        {
                            'Behavior': 'KEEP'|'DROP',
                            'Requirement': 'MEETS_ALL'|'MEETS_ANY',
                            'Conditions': [
                                {
                                    'ActionCondition': {
                                        'Action': 'ALLOW'|'BLOCK'|'COUNT'|'CAPTCHA'|'CHALLENGE'|'EXCLUDED_AS_COUNT'
                                    },
                                    'LabelNameCondition': {
                                        'LabelName': 'string'
                                    }
                                },
                            ]
                        },
                    ],
                    'DefaultBehavior': 'KEEP'|'DROP'
                },
                'LogType': 'WAF_LOGS'
            },
            'LogDeliveryParameters': {
                'LogTypes': [
                    'APPLICATION_LOGS'|'USAGE_LOGS'|'SECURITY_FINDING_LOGS'|'ACCESS_LOGS'|'CONNECTION_LOGS'|'S3_SERVER_ACCESS_LOGS'|'ALB_ACCESS_LOGS'|'ALB_CONNECTION_LOGS'|'ALB_HEALTH_CHECK_LOGS',
                ]
            },
            'MskMonitoringParameters': {
                'EnhancedMonitoring': 'DEFAULT'|'PER_BROKER'|'PER_TOPIC_PER_BROKER'|'PER_TOPIC_PER_PARTITION'
            },
            'KmsKeyArn': 'string'
        },
        'Scope': 'string',
        'SelectionCriteria': 'string',
        'AllowFieldUpdates': True|False,
        'Regions': [
            'string',
        ],
        'AllRegions': True|False
    },
    'HomeRegion': 'string',
    'IsReplicated': True|False,
    'RegionStatuses': [
        {
            'Region': 'string',
            'Status': 'string',
            'FailureReason': 'string',
            'RuleArn': 'string'
        },
    ]
}

Response Structure

  • (dict) --

    • RuleName (string) --

      The name of the organization telemetry rule.

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the organization telemetry rule.

    • CreatedTimeStamp (integer) --

      The timestamp when the organization telemetry rule was created.

    • LastUpdateTimeStamp (integer) --

      The timestamp when the organization telemetry rule was last updated.

    • TelemetryRule (dict) --

      The configuration details of the organization telemetry rule.

      • ResourceType (string) --

        The type of Amazon Web Services resource to configure telemetry for (for example, AWS::EC2::VPC, AWS::EKS::Cluster, AWS::ElasticLoadBalancingV2::LoadBalancer, or AWS::Bedrock::KnowledgeBase).

      • TelemetryType (string) --

        The type of telemetry to collect (Logs, Metrics, or Traces).

      • TelemetrySourceTypes (list) --

        The specific telemetry source types to configure for the resource, such as VPC_FLOW_LOGS or EKS_AUDIT_LOGS. TelemetrySourceTypes must be correlated with the specific resource type.

        • (string) --

          Specifies the type of telemetry source for a resource, such as EKS cluster logs.

      • DestinationConfiguration (dict) --

        Configuration specifying where and how the telemetry data should be delivered.

        • DestinationType (string) --

          The type of destination for the telemetry data (e.g., "Amazon CloudWatch Logs", "S3").

        • DestinationPattern (string) --

          The pattern used to generate the destination path or name, supporting macros like <resourceId> and <accountId>.

        • RetentionInDays (integer) --

          The number of days to retain the telemetry data in the destination.

        • VPCFlowLogParameters (dict) --

          Configuration parameters specific to VPC Flow Logs when VPC is the resource type.

          • LogFormat (string) --

            The format in which VPC Flow Log entries should be logged.

          • TrafficType (string) --

            The type of traffic to log (ACCEPT, REJECT, or ALL).

          • MaxAggregationInterval (integer) --

            The maximum interval in seconds between the capture of flow log records.

        • CloudtrailParameters (dict) --

          Configuration parameters specific to Amazon Web Services CloudTrail when CloudTrail is the source type.

          • AdvancedEventSelectors (list) --

            The advanced event selectors to use for filtering Amazon Web Services CloudTrail events.

            • (dict) --

              Advanced event selectors let you create fine-grained selectors for management, data, and network activity events.

              • Name (string) --

                An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".

              • FieldSelectors (list) --

                Contains all selector statements in an advanced event selector.

                • (dict) --

                  Defines criteria for selecting resources based on field values.

                  • Field (string) --

                    The name of the field to use for selection.

                  • Equals (list) --

                    Matches if the field value equals the specified value.

                    • (string) --

                  • StartsWith (list) --

                    Matches if the field value starts with the specified value.

                    • (string) --

                  • EndsWith (list) --

                    Matches if the field value ends with the specified value.

                    • (string) --

                  • NotEquals (list) --

                    Matches if the field value does not equal the specified value.

                    • (string) --

                  • NotStartsWith (list) --

                    Matches if the field value does not start with the specified value.

                    • (string) --

                  • NotEndsWith (list) --

                    Matches if the field value does not end with the specified value.

                    • (string) --

        • ELBLoadBalancerLoggingParameters (dict) --

          Configuration parameters specific to ELB load balancer logging when ELB is the resource type.

          • OutputFormat (string) --

            The format for ELB access log entries (plain text or JSON format).

          • FieldDelimiter (string) --

            The delimiter character used to separate fields in ELB access log entries when using plain text format.

        • WAFLoggingParameters (dict) --

          Configuration parameters specific to WAF logging when WAF is the resource type.

          • RedactedFields (list) --

            The fields to redact from WAF logs to protect sensitive information.

            • (dict) --

              Specifies a field in the request to redact from WAF logs, such as headers, query parameters, or body content.

              • SingleHeader (dict) --

                Redacts a specific header field by name from WAF logs.

                • Name (string) --

                  The name value, limited to 64 characters.

              • UriPath (string) --

                Redacts the URI path from WAF logs.

              • QueryString (string) --

                Redacts the entire query string from WAF logs.

              • Method (string) --

                Redacts the HTTP method from WAF logs.

          • LoggingFilter (dict) --

            A filter configuration that determines which WAF log records to include or exclude.

            • Filters (list) --

              A list of filter conditions that determine log record handling behavior.

              • (dict) --

                A single filter condition that specifies behavior, requirement, and matching conditions for WAF log records.

                • Behavior (string) --

                  The action to take for log records matching this filter (KEEP or DROP).

                • Requirement (string) --

                  Whether the log record must meet all conditions (MEETS_ALL) or any condition (MEETS_ANY) to match this filter.

                • Conditions (list) --

                  The list of conditions that determine if a log record matches this filter.

                  • (dict) --

                    A single condition that can match based on WAF rule action or label name.

                    • ActionCondition (dict) --

                      Matches log records based on the WAF rule action taken (ALLOW, BLOCK, COUNT, etc.).

                      • Action (string) --

                        The WAF action to match against (ALLOW, BLOCK, COUNT, CAPTCHA, CHALLENGE, EXCLUDED_AS_COUNT).

                    • LabelNameCondition (dict) --

                      Matches log records based on WAF rule labels applied to the request.

                      • LabelName (string) --

                        The label name to match, supporting alphanumeric characters, underscores, hyphens, and colons.

            • DefaultBehavior (string) --

              The default action (KEEP or DROP) for log records that don't match any filter conditions.

          • LogType (string) --

            The type of WAF logs to collect (currently supports WAF_LOGS).

        • LogDeliveryParameters (dict) --

          The configuration parameters for log delivery when the resource type supports configurable log types, such as Amazon Bedrock Knowledge Bases or Elastic Load Balancing Application Load Balancers.

          • LogTypes (list) --

            The types of logs to collect from the resource.

            • (string) --

              The following log types are supported for log delivery configuration:

              • APPLICATION_LOGS – Application-level logs.

              • USAGE_LOGS – Resource usage logs.

              • SECURITY_FINDING_LOGS – Security finding logs.

              • ACCESS_LOGS – Access logs (such as Elastic Load Balancing access logs).

              • CONNECTION_LOGS – Connection logs.

              • S3_SERVER_ACCESS_LOGS – Amazon S3 server access logs.

        • MskMonitoringParameters (dict) --

          Configuration parameters specific to MSK monitoring when MSK is the resource type.

          • EnhancedMonitoring (string) --

            The level of enhanced monitoring for the MSK cluster.

        • KmsKeyArn (string) --

          The Amazon Resource Name (ARN) of the customer-managed Amazon Web Services KMS key used to encrypt the log groups created during telemetry rule remediation.

      • Scope (string) --

        The organizational scope to which the rule applies, specified using accounts or organizational units.

      • SelectionCriteria (string) --

        Criteria for selecting which resources the rule applies to, such as resource tags.

      • AllowFieldUpdates (boolean) --

        If set to true, Amazon CloudWatch Observability Admin detects and remediates configuration drift in telemetry resources that it manages. For example, if a VPC flow log's format, traffic type, or aggregation interval no longer matches the rule's destination configuration, the flow log is replaced with one that matches. Only Observability Admin-managed resources are updated; customer-created resources are never modified. Currently supported for AWS::EC2::VPC resources (VPC flow logs).

      • Regions (list) --

        An optional list of Amazon Web Services Regions where this telemetry rule should be replicated. When specified, the rule is created in the home region and automatically replicated to all listed regions. Mutually exclusive with AllRegions.

        • (string) --

      • AllRegions (boolean) --

        If set to true, the telemetry rule is replicated to all Amazon Web Services Regions where Amazon CloudWatch Observability Admin is available in the current partition. When new regions become available, the rule automatically replicates to them. Mutually exclusive with Regions.

    • HomeRegion (string) --

      The Amazon Web Services Region where the organization telemetry rule was originally created. For replicated rules in spoke regions, this indicates the region that manages the rule. For rules created without multi-region scope, this field is not present.

    • IsReplicated (boolean) --

      Indicates whether this organization telemetry rule is a replica that was created in this region through multi-region fan-out from the home region. Replicated rules cannot be directly updated or deleted in the spoke region. To modify a replicated rule, make changes in the home region.

    • RegionStatuses (list) --

      A list of per-region replication statuses for the organization telemetry rule. Each entry indicates the replication status of the rule in a specific spoke region. This field is only present for rules created with multi-region scope.

      • (dict) --

        Represents the status of a multi-region operation in a specific Amazon Web Services Region. This structure is used to report per-region progress for both telemetry evaluation and telemetry rule replication.

        • Region (string) --

          The Amazon Web Services Region code (for example, eu-west-1 or us-west-2) that this status applies to.

        • Status (string) --

          The status of the operation in this region. For telemetry evaluation, valid values include STARTING, RUNNING, and FAILED_START. For telemetry rules, valid values include PENDING, ACTIVE, and FAILED.

        • FailureReason (string) --

          The reason for a failure status in this region. This field is only populated when Status indicates a failure.

        • RuleArn (string) --

          The Amazon Resource Name (ARN) of the telemetry rule in this spoke region. This field is only present for telemetry rule region statuses and is populated when the rule has been successfully created in the spoke region (status is ACTIVE).

UpdateCentralizationRuleForOrganization (updated) Link ¶
Changes (request)
{'Rule': {'Destination': {'DestinationLogsConfiguration': {'LogsEncryptionConfiguration': {'EncryptionScope': 'ENCRYPTED_SOURCE_ONLY '
                                                                                                              '| '
                                                                                                              'NEW_DESTINATION_LOG_GROUPS'}}}}}

Updates an existing centralization rule that applies across an Amazon Web Services Organization. This operation can only be called by the organization's management account or a delegated administrator account.

See also: AWS API Documentation

Request Syntax

client.update_centralization_rule_for_organization(
    RuleIdentifier='string',
    Rule={
        'Source': {
            'Regions': [
                'string',
            ],
            'Scope': 'string',
            'SourceLogsConfiguration': {
                'LogGroupSelectionCriteria': 'string',
                'DataSourceSelectionCriteria': 'string',
                'EncryptedLogGroupStrategy': 'ALLOW'|'SKIP'
            },
            'SourceMetricsConfiguration': {
                'MetricsSelectionCriteria': 'string'
            }
        },
        'Destination': {
            'Region': 'string',
            'Account': 'string',
            'DestinationLogsConfiguration': {
                'LogsEncryptionConfiguration': {
                    'EncryptionStrategy': 'CUSTOMER_MANAGED'|'AWS_OWNED',
                    'KmsKeyArn': 'string',
                    'EncryptionConflictResolutionStrategy': 'ALLOW'|'SKIP',
                    'EncryptionScope': 'ENCRYPTED_SOURCE_ONLY'|'NEW_DESTINATION_LOG_GROUPS'
                },
                'BackupConfiguration': {
                    'Region': 'string',
                    'KmsKeyArn': 'string'
                },
                'LogGroupNameConfiguration': {
                    'LogGroupNamePattern': 'string'
                }
            },
            'DestinationMetricsConfiguration': {
                'BackupConfiguration': {
                    'Region': 'string'
                }
            }
        }
    }
)
type RuleIdentifier:

string

param RuleIdentifier:

[REQUIRED]

The identifier (name or ARN) of the organization centralization rule to update.

type Rule:

dict

param Rule:

[REQUIRED]

The configuration details for the organization-wide centralization rule, including the source configuration and the destination configuration to centralize telemetry data across the organization.

  • Source (dict) -- [REQUIRED]

    Configuration determining the source of the telemetry data to be centralized.

    • Regions (list) -- [REQUIRED]

      The list of source regions from which telemetry data should be centralized.

      • (string) --

    • Scope (string) --

      The organizational scope from which telemetry data should be centralized, specified using organization id, accounts or organizational unit ids.

    • SourceLogsConfiguration (dict) --

      Log specific configuration for centralization source log groups.

      • LogGroupSelectionCriteria (string) --

        The selection criteria that specifies which source log groups to centralize. The selection criteria uses the same format as OAM link filters.

      • DataSourceSelectionCriteria (string) --

        The selection criteria that specifies which data sources to centralize. The selection criteria uses the same filter expression format as LogGroupSelectionCriteria, but operates on DataSourceName and DataSourceType operands. When both LogGroupSelectionCriteria and DataSourceSelectionCriteria are specified, a log event must match both criteria to be centralized.

      • EncryptedLogGroupStrategy (string) -- [REQUIRED]

        A strategy determining whether to centralize source log groups that are encrypted with customer managed KMS keys (CMK). ALLOW will consider CMK encrypted source log groups for centralization while SKIP will skip CMK encrypted source log groups from centralization.

    • SourceMetricsConfiguration (dict) --

      Metric specific configuration for centralization source metrics.

      • MetricsSelectionCriteria (string) --

        The filter expression that selects which source metrics to centralize. Currently, only * (all metrics) is supported. Other values return a validation error.

  • Destination (dict) -- [REQUIRED]

    Configuration determining where the telemetry data should be centralized, backed up, as well as encryption configuration for the primary and backup destinations.

    • Region (string) -- [REQUIRED]

      The primary destination region to which telemetry data should be centralized.

    • Account (string) --

      The destination account (within the organization) to which the telemetry data should be centralized.

    • DestinationLogsConfiguration (dict) --

      Log specific configuration for centralization destination log groups.

      • LogsEncryptionConfiguration (dict) --

        The encryption configuration for centralization destination log groups.

        • EncryptionStrategy (string) -- [REQUIRED]

          Configuration that determines the encryption strategy of the destination log groups. CUSTOMER_MANAGED uses the configured KmsKeyArn to encrypt newly created destination log groups.

        • KmsKeyArn (string) --

          KMS Key ARN belonging to the primary destination account and region, to encrypt newly created central log groups in the primary destination.

        • EncryptionConflictResolutionStrategy (string) --

          Conflict resolution strategy for centralization if the encryption strategy is set to CUSTOMER_MANAGED and the destination log group is encrypted with an AWS_OWNED KMS Key. ALLOW lets centralization go through while SKIP prevents centralization into the destination log group.

        • EncryptionScope (string) --

          Determines which newly created destination log groups are encrypted with the configured KmsKeyArn when EncryptionStrategy is CUSTOMER_MANAGED.

          If you set this to ENCRYPTED_SOURCE_ONLY (the default), only destination log groups whose source log group is encrypted with a customer managed KMS key use the configured KmsKeyArn. Destination log groups derived from Amazon Web Services owned encrypted source log groups remain Amazon Web Services owned encrypted.

          If you set this to NEW_DESTINATION_LOG_GROUPS, every new destination log group created by this rule uses the configured KmsKeyArn, regardless of the source log group's encryption posture.

          This field is not valid when EncryptionStrategy is AWS_OWNED.

      • BackupConfiguration (dict) --

        Configuration defining the backup region and an optional KMS key for the backup destination.

        • Region (string) -- [REQUIRED]

          Logs specific backup destination region within the primary destination account to which log data should be centralized.

        • KmsKeyArn (string) --

          KMS Key ARN belonging to the primary destination account and backup region, to encrypt newly created central log groups in the backup destination.

      • LogGroupNameConfiguration (dict) --

        Configuration that specifies a naming pattern for destination log groups created during centralization. The pattern supports static text and dynamic variables that are replaced with source attributes when log groups are created.

        • LogGroupNamePattern (string) -- [REQUIRED]

          The pattern used to generate destination log group names during centralization. The pattern can contain static text and dynamic variables that are replaced with source attributes. If a variable cannot be resolved, it inherits the value from its parent variable in the hierarchy. The pattern must be between 1 and 512 characters.

          Supported variables:

          • ${source.logGroup} — The original log group name from the source account.

          • ${source.accountId} — The Amazon Web Services account ID where the log originated.

          • ${source.region} — The Amazon Web Services Region where the log originated.

          • ${source.org.id} — The Amazon Web Services Organization ID of the source account.

          • ${source.org.ouId} — The organizational unit ID of the source account.

          • ${source.org.rootId} — The organization Root ID.

          • ${source.org.path} — The organizational path from account to root.

    • DestinationMetricsConfiguration (dict) --

      Metric specific configuration for centralization destination metrics.

      • BackupConfiguration (dict) --

        Configuration defining the backup region for the metrics backup destination.

        • Region (string) -- [REQUIRED]

          Metrics specific backup destination region within the primary destination account to which metrics data should be centralized.

rtype:

dict

returns:

Response Syntax

{
    'RuleArn': 'string'
}

Response Structure

  • (dict) --

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the updated organization centralization rule.

UpdateTelemetryRule (updated) Link ¶
Changes (request)
{'Rule': {'DestinationConfiguration': {'KmsKeyArn': 'string'}}}

Updates an existing telemetry rule in your account. If multiple users attempt to modify the same telemetry rule simultaneously, a ConflictException is returned to provide specific error information for concurrent modification scenarios.

See also: AWS API Documentation

Request Syntax

client.update_telemetry_rule(
    RuleIdentifier='string',
    Rule={
        'ResourceType': 'AWS::EC2::Instance'|'AWS::EC2::VPC'|'AWS::Lambda::Function'|'AWS::CloudTrail'|'AWS::EKS::Cluster'|'AWS::WAFv2::WebACL'|'AWS::ElasticLoadBalancingV2::LoadBalancer'|'AWS::Route53Resolver::ResolverEndpoint'|'AWS::BedrockAgentCore::Runtime'|'AWS::BedrockAgentCore::Browser'|'AWS::BedrockAgentCore::CodeInterpreter'|'AWS::BedrockAgentCore::Gateway'|'AWS::BedrockAgentCore::Memory'|'AWS::BedrockAgentCore::WorkloadIdentity'|'AWS::SecurityHub::Hub'|'AWS::CloudFront::Distribution'|'AWS::SecurityHub::HubV2'|'AWS::CloudWatch::OTelEnrichment'|'AWS::MSK::Cluster'|'AWS::S3::Bucket'|'AWS::Bedrock::KnowledgeBase',
        'TelemetryType': 'Logs'|'Metrics'|'Traces',
        'TelemetrySourceTypes': [
            'VPC_FLOW_LOGS'|'ROUTE53_RESOLVER_QUERY_LOGS'|'EKS_AUDIT_LOGS'|'EKS_AUTHENTICATOR_LOGS'|'EKS_CONTROLLER_MANAGER_LOGS'|'EKS_SCHEDULER_LOGS'|'EKS_API_LOGS',
        ],
        'DestinationConfiguration': {
            'DestinationType': 'cloud-watch-logs',
            'DestinationPattern': 'string',
            'RetentionInDays': 123,
            'VPCFlowLogParameters': {
                'LogFormat': 'string',
                'TrafficType': 'string',
                'MaxAggregationInterval': 123
            },
            'CloudtrailParameters': {
                'AdvancedEventSelectors': [
                    {
                        'Name': 'string',
                        'FieldSelectors': [
                            {
                                'Field': 'string',
                                'Equals': [
                                    'string',
                                ],
                                'StartsWith': [
                                    'string',
                                ],
                                'EndsWith': [
                                    'string',
                                ],
                                'NotEquals': [
                                    'string',
                                ],
                                'NotStartsWith': [
                                    'string',
                                ],
                                'NotEndsWith': [
                                    'string',
                                ]
                            },
                        ]
                    },
                ]
            },
            'ELBLoadBalancerLoggingParameters': {
                'OutputFormat': 'plain'|'json',
                'FieldDelimiter': 'string'
            },
            'WAFLoggingParameters': {
                'RedactedFields': [
                    {
                        'SingleHeader': {
                            'Name': 'string'
                        },
                        'UriPath': 'string',
                        'QueryString': 'string',
                        'Method': 'string'
                    },
                ],
                'LoggingFilter': {
                    'Filters': [
                        {
                            'Behavior': 'KEEP'|'DROP',
                            'Requirement': 'MEETS_ALL'|'MEETS_ANY',
                            'Conditions': [
                                {
                                    'ActionCondition': {
                                        'Action': 'ALLOW'|'BLOCK'|'COUNT'|'CAPTCHA'|'CHALLENGE'|'EXCLUDED_AS_COUNT'
                                    },
                                    'LabelNameCondition': {
                                        'LabelName': 'string'
                                    }
                                },
                            ]
                        },
                    ],
                    'DefaultBehavior': 'KEEP'|'DROP'
                },
                'LogType': 'WAF_LOGS'
            },
            'LogDeliveryParameters': {
                'LogTypes': [
                    'APPLICATION_LOGS'|'USAGE_LOGS'|'SECURITY_FINDING_LOGS'|'ACCESS_LOGS'|'CONNECTION_LOGS'|'S3_SERVER_ACCESS_LOGS'|'ALB_ACCESS_LOGS'|'ALB_CONNECTION_LOGS'|'ALB_HEALTH_CHECK_LOGS',
                ]
            },
            'MskMonitoringParameters': {
                'EnhancedMonitoring': 'DEFAULT'|'PER_BROKER'|'PER_TOPIC_PER_BROKER'|'PER_TOPIC_PER_PARTITION'
            },
            'KmsKeyArn': 'string'
        },
        'Scope': 'string',
        'SelectionCriteria': 'string',
        'AllowFieldUpdates': True|False,
        'Regions': [
            'string',
        ],
        'AllRegions': True|False
    }
)
type RuleIdentifier:

string

param RuleIdentifier:

[REQUIRED]

The identifier (name or ARN) of the telemetry rule to update.

type Rule:

dict

param Rule:

[REQUIRED]

The new configuration details for the telemetry rule.

  • ResourceType (string) --

    The type of Amazon Web Services resource to configure telemetry for (for example, AWS::EC2::VPC, AWS::EKS::Cluster, AWS::ElasticLoadBalancingV2::LoadBalancer, or AWS::Bedrock::KnowledgeBase).

  • TelemetryType (string) -- [REQUIRED]

    The type of telemetry to collect (Logs, Metrics, or Traces).

  • TelemetrySourceTypes (list) --

    The specific telemetry source types to configure for the resource, such as VPC_FLOW_LOGS or EKS_AUDIT_LOGS. TelemetrySourceTypes must be correlated with the specific resource type.

    • (string) --

      Specifies the type of telemetry source for a resource, such as EKS cluster logs.

  • DestinationConfiguration (dict) --

    Configuration specifying where and how the telemetry data should be delivered.

    • DestinationType (string) --

      The type of destination for the telemetry data (e.g., "Amazon CloudWatch Logs", "S3").

    • DestinationPattern (string) --

      The pattern used to generate the destination path or name, supporting macros like <resourceId> and <accountId>.

    • RetentionInDays (integer) --

      The number of days to retain the telemetry data in the destination.

    • VPCFlowLogParameters (dict) --

      Configuration parameters specific to VPC Flow Logs when VPC is the resource type.

      • LogFormat (string) --

        The format in which VPC Flow Log entries should be logged.

      • TrafficType (string) --

        The type of traffic to log (ACCEPT, REJECT, or ALL).

      • MaxAggregationInterval (integer) --

        The maximum interval in seconds between the capture of flow log records.

    • CloudtrailParameters (dict) --

      Configuration parameters specific to Amazon Web Services CloudTrail when CloudTrail is the source type.

      • AdvancedEventSelectors (list) -- [REQUIRED]

        The advanced event selectors to use for filtering Amazon Web Services CloudTrail events.

        • (dict) --

          Advanced event selectors let you create fine-grained selectors for management, data, and network activity events.

          • Name (string) --

            An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".

          • FieldSelectors (list) -- [REQUIRED]

            Contains all selector statements in an advanced event selector.

            • (dict) --

              Defines criteria for selecting resources based on field values.

              • Field (string) -- [REQUIRED]

                The name of the field to use for selection.

              • Equals (list) --

                Matches if the field value equals the specified value.

                • (string) --

              • StartsWith (list) --

                Matches if the field value starts with the specified value.

                • (string) --

              • EndsWith (list) --

                Matches if the field value ends with the specified value.

                • (string) --

              • NotEquals (list) --

                Matches if the field value does not equal the specified value.

                • (string) --

              • NotStartsWith (list) --

                Matches if the field value does not start with the specified value.

                • (string) --

              • NotEndsWith (list) --

                Matches if the field value does not end with the specified value.

                • (string) --

    • ELBLoadBalancerLoggingParameters (dict) --

      Configuration parameters specific to ELB load balancer logging when ELB is the resource type.

      • OutputFormat (string) --

        The format for ELB access log entries (plain text or JSON format).

      • FieldDelimiter (string) --

        The delimiter character used to separate fields in ELB access log entries when using plain text format.

    • WAFLoggingParameters (dict) --

      Configuration parameters specific to WAF logging when WAF is the resource type.

      • RedactedFields (list) --

        The fields to redact from WAF logs to protect sensitive information.

        • (dict) --

          Specifies a field in the request to redact from WAF logs, such as headers, query parameters, or body content.

          • SingleHeader (dict) --

            Redacts a specific header field by name from WAF logs.

            • Name (string) --

              The name value, limited to 64 characters.

          • UriPath (string) --

            Redacts the URI path from WAF logs.

          • QueryString (string) --

            Redacts the entire query string from WAF logs.

          • Method (string) --

            Redacts the HTTP method from WAF logs.

      • LoggingFilter (dict) --

        A filter configuration that determines which WAF log records to include or exclude.

        • Filters (list) --

          A list of filter conditions that determine log record handling behavior.

          • (dict) --

            A single filter condition that specifies behavior, requirement, and matching conditions for WAF log records.

            • Behavior (string) --

              The action to take for log records matching this filter (KEEP or DROP).

            • Requirement (string) --

              Whether the log record must meet all conditions (MEETS_ALL) or any condition (MEETS_ANY) to match this filter.

            • Conditions (list) --

              The list of conditions that determine if a log record matches this filter.

              • (dict) --

                A single condition that can match based on WAF rule action or label name.

                • ActionCondition (dict) --

                  Matches log records based on the WAF rule action taken (ALLOW, BLOCK, COUNT, etc.).

                  • Action (string) --

                    The WAF action to match against (ALLOW, BLOCK, COUNT, CAPTCHA, CHALLENGE, EXCLUDED_AS_COUNT).

                • LabelNameCondition (dict) --

                  Matches log records based on WAF rule labels applied to the request.

                  • LabelName (string) --

                    The label name to match, supporting alphanumeric characters, underscores, hyphens, and colons.

        • DefaultBehavior (string) --

          The default action (KEEP or DROP) for log records that don't match any filter conditions.

      • LogType (string) --

        The type of WAF logs to collect (currently supports WAF_LOGS).

    • LogDeliveryParameters (dict) --

      The configuration parameters for log delivery when the resource type supports configurable log types, such as Amazon Bedrock Knowledge Bases or Elastic Load Balancing Application Load Balancers.

      • LogTypes (list) --

        The types of logs to collect from the resource.

        • (string) --

          The following log types are supported for log delivery configuration:

          • APPLICATION_LOGS – Application-level logs.

          • USAGE_LOGS – Resource usage logs.

          • SECURITY_FINDING_LOGS – Security finding logs.

          • ACCESS_LOGS – Access logs (such as Elastic Load Balancing access logs).

          • CONNECTION_LOGS – Connection logs.

          • S3_SERVER_ACCESS_LOGS – Amazon S3 server access logs.

    • MskMonitoringParameters (dict) --

      Configuration parameters specific to MSK monitoring when MSK is the resource type.

      • EnhancedMonitoring (string) --

        The level of enhanced monitoring for the MSK cluster.

    • KmsKeyArn (string) --

      The Amazon Resource Name (ARN) of the customer-managed Amazon Web Services KMS key used to encrypt the log groups created during telemetry rule remediation.

  • Scope (string) --

    The organizational scope to which the rule applies, specified using accounts or organizational units.

  • SelectionCriteria (string) --

    Criteria for selecting which resources the rule applies to, such as resource tags.

  • AllowFieldUpdates (boolean) --

    If set to true, Amazon CloudWatch Observability Admin detects and remediates configuration drift in telemetry resources that it manages. For example, if a VPC flow log's format, traffic type, or aggregation interval no longer matches the rule's destination configuration, the flow log is replaced with one that matches. Only Observability Admin-managed resources are updated; customer-created resources are never modified. Currently supported for AWS::EC2::VPC resources (VPC flow logs).

  • Regions (list) --

    An optional list of Amazon Web Services Regions where this telemetry rule should be replicated. When specified, the rule is created in the home region and automatically replicated to all listed regions. Mutually exclusive with AllRegions.

    • (string) --

  • AllRegions (boolean) --

    If set to true, the telemetry rule is replicated to all Amazon Web Services Regions where Amazon CloudWatch Observability Admin is available in the current partition. When new regions become available, the rule automatically replicates to them. Mutually exclusive with Regions.

rtype:

dict

returns:

Response Syntax

{
    'RuleArn': 'string'
}

Response Structure

  • (dict) --

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the updated telemetry rule.

UpdateTelemetryRuleForOrganization (updated) Link ¶
Changes (request)
{'Rule': {'DestinationConfiguration': {'KmsKeyArn': 'string'}}}

Updates an existing telemetry rule that applies across an Amazon Web Services Organization. This operation can only be called by the organization's management account or a delegated administrator account.

See also: AWS API Documentation

Request Syntax

client.update_telemetry_rule_for_organization(
    RuleIdentifier='string',
    Rule={
        'ResourceType': 'AWS::EC2::Instance'|'AWS::EC2::VPC'|'AWS::Lambda::Function'|'AWS::CloudTrail'|'AWS::EKS::Cluster'|'AWS::WAFv2::WebACL'|'AWS::ElasticLoadBalancingV2::LoadBalancer'|'AWS::Route53Resolver::ResolverEndpoint'|'AWS::BedrockAgentCore::Runtime'|'AWS::BedrockAgentCore::Browser'|'AWS::BedrockAgentCore::CodeInterpreter'|'AWS::BedrockAgentCore::Gateway'|'AWS::BedrockAgentCore::Memory'|'AWS::BedrockAgentCore::WorkloadIdentity'|'AWS::SecurityHub::Hub'|'AWS::CloudFront::Distribution'|'AWS::SecurityHub::HubV2'|'AWS::CloudWatch::OTelEnrichment'|'AWS::MSK::Cluster'|'AWS::S3::Bucket'|'AWS::Bedrock::KnowledgeBase',
        'TelemetryType': 'Logs'|'Metrics'|'Traces',
        'TelemetrySourceTypes': [
            'VPC_FLOW_LOGS'|'ROUTE53_RESOLVER_QUERY_LOGS'|'EKS_AUDIT_LOGS'|'EKS_AUTHENTICATOR_LOGS'|'EKS_CONTROLLER_MANAGER_LOGS'|'EKS_SCHEDULER_LOGS'|'EKS_API_LOGS',
        ],
        'DestinationConfiguration': {
            'DestinationType': 'cloud-watch-logs',
            'DestinationPattern': 'string',
            'RetentionInDays': 123,
            'VPCFlowLogParameters': {
                'LogFormat': 'string',
                'TrafficType': 'string',
                'MaxAggregationInterval': 123
            },
            'CloudtrailParameters': {
                'AdvancedEventSelectors': [
                    {
                        'Name': 'string',
                        'FieldSelectors': [
                            {
                                'Field': 'string',
                                'Equals': [
                                    'string',
                                ],
                                'StartsWith': [
                                    'string',
                                ],
                                'EndsWith': [
                                    'string',
                                ],
                                'NotEquals': [
                                    'string',
                                ],
                                'NotStartsWith': [
                                    'string',
                                ],
                                'NotEndsWith': [
                                    'string',
                                ]
                            },
                        ]
                    },
                ]
            },
            'ELBLoadBalancerLoggingParameters': {
                'OutputFormat': 'plain'|'json',
                'FieldDelimiter': 'string'
            },
            'WAFLoggingParameters': {
                'RedactedFields': [
                    {
                        'SingleHeader': {
                            'Name': 'string'
                        },
                        'UriPath': 'string',
                        'QueryString': 'string',
                        'Method': 'string'
                    },
                ],
                'LoggingFilter': {
                    'Filters': [
                        {
                            'Behavior': 'KEEP'|'DROP',
                            'Requirement': 'MEETS_ALL'|'MEETS_ANY',
                            'Conditions': [
                                {
                                    'ActionCondition': {
                                        'Action': 'ALLOW'|'BLOCK'|'COUNT'|'CAPTCHA'|'CHALLENGE'|'EXCLUDED_AS_COUNT'
                                    },
                                    'LabelNameCondition': {
                                        'LabelName': 'string'
                                    }
                                },
                            ]
                        },
                    ],
                    'DefaultBehavior': 'KEEP'|'DROP'
                },
                'LogType': 'WAF_LOGS'
            },
            'LogDeliveryParameters': {
                'LogTypes': [
                    'APPLICATION_LOGS'|'USAGE_LOGS'|'SECURITY_FINDING_LOGS'|'ACCESS_LOGS'|'CONNECTION_LOGS'|'S3_SERVER_ACCESS_LOGS'|'ALB_ACCESS_LOGS'|'ALB_CONNECTION_LOGS'|'ALB_HEALTH_CHECK_LOGS',
                ]
            },
            'MskMonitoringParameters': {
                'EnhancedMonitoring': 'DEFAULT'|'PER_BROKER'|'PER_TOPIC_PER_BROKER'|'PER_TOPIC_PER_PARTITION'
            },
            'KmsKeyArn': 'string'
        },
        'Scope': 'string',
        'SelectionCriteria': 'string',
        'AllowFieldUpdates': True|False,
        'Regions': [
            'string',
        ],
        'AllRegions': True|False
    }
)
type RuleIdentifier:

string

param RuleIdentifier:

[REQUIRED]

The identifier (name or ARN) of the organization telemetry rule to update.

type Rule:

dict

param Rule:

[REQUIRED]

The new configuration details for the organization telemetry rule, including resource type, telemetry type, and destination configuration.

  • ResourceType (string) --

    The type of Amazon Web Services resource to configure telemetry for (for example, AWS::EC2::VPC, AWS::EKS::Cluster, AWS::ElasticLoadBalancingV2::LoadBalancer, or AWS::Bedrock::KnowledgeBase).

  • TelemetryType (string) -- [REQUIRED]

    The type of telemetry to collect (Logs, Metrics, or Traces).

  • TelemetrySourceTypes (list) --

    The specific telemetry source types to configure for the resource, such as VPC_FLOW_LOGS or EKS_AUDIT_LOGS. TelemetrySourceTypes must be correlated with the specific resource type.

    • (string) --

      Specifies the type of telemetry source for a resource, such as EKS cluster logs.

  • DestinationConfiguration (dict) --

    Configuration specifying where and how the telemetry data should be delivered.

    • DestinationType (string) --

      The type of destination for the telemetry data (e.g., "Amazon CloudWatch Logs", "S3").

    • DestinationPattern (string) --

      The pattern used to generate the destination path or name, supporting macros like <resourceId> and <accountId>.

    • RetentionInDays (integer) --

      The number of days to retain the telemetry data in the destination.

    • VPCFlowLogParameters (dict) --

      Configuration parameters specific to VPC Flow Logs when VPC is the resource type.

      • LogFormat (string) --

        The format in which VPC Flow Log entries should be logged.

      • TrafficType (string) --

        The type of traffic to log (ACCEPT, REJECT, or ALL).

      • MaxAggregationInterval (integer) --

        The maximum interval in seconds between the capture of flow log records.

    • CloudtrailParameters (dict) --

      Configuration parameters specific to Amazon Web Services CloudTrail when CloudTrail is the source type.

      • AdvancedEventSelectors (list) -- [REQUIRED]

        The advanced event selectors to use for filtering Amazon Web Services CloudTrail events.

        • (dict) --

          Advanced event selectors let you create fine-grained selectors for management, data, and network activity events.

          • Name (string) --

            An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".

          • FieldSelectors (list) -- [REQUIRED]

            Contains all selector statements in an advanced event selector.

            • (dict) --

              Defines criteria for selecting resources based on field values.

              • Field (string) -- [REQUIRED]

                The name of the field to use for selection.

              • Equals (list) --

                Matches if the field value equals the specified value.

                • (string) --

              • StartsWith (list) --

                Matches if the field value starts with the specified value.

                • (string) --

              • EndsWith (list) --

                Matches if the field value ends with the specified value.

                • (string) --

              • NotEquals (list) --

                Matches if the field value does not equal the specified value.

                • (string) --

              • NotStartsWith (list) --

                Matches if the field value does not start with the specified value.

                • (string) --

              • NotEndsWith (list) --

                Matches if the field value does not end with the specified value.

                • (string) --

    • ELBLoadBalancerLoggingParameters (dict) --

      Configuration parameters specific to ELB load balancer logging when ELB is the resource type.

      • OutputFormat (string) --

        The format for ELB access log entries (plain text or JSON format).

      • FieldDelimiter (string) --

        The delimiter character used to separate fields in ELB access log entries when using plain text format.

    • WAFLoggingParameters (dict) --

      Configuration parameters specific to WAF logging when WAF is the resource type.

      • RedactedFields (list) --

        The fields to redact from WAF logs to protect sensitive information.

        • (dict) --

          Specifies a field in the request to redact from WAF logs, such as headers, query parameters, or body content.

          • SingleHeader (dict) --

            Redacts a specific header field by name from WAF logs.

            • Name (string) --

              The name value, limited to 64 characters.

          • UriPath (string) --

            Redacts the URI path from WAF logs.

          • QueryString (string) --

            Redacts the entire query string from WAF logs.

          • Method (string) --

            Redacts the HTTP method from WAF logs.

      • LoggingFilter (dict) --

        A filter configuration that determines which WAF log records to include or exclude.

        • Filters (list) --

          A list of filter conditions that determine log record handling behavior.

          • (dict) --

            A single filter condition that specifies behavior, requirement, and matching conditions for WAF log records.

            • Behavior (string) --

              The action to take for log records matching this filter (KEEP or DROP).

            • Requirement (string) --

              Whether the log record must meet all conditions (MEETS_ALL) or any condition (MEETS_ANY) to match this filter.

            • Conditions (list) --

              The list of conditions that determine if a log record matches this filter.

              • (dict) --

                A single condition that can match based on WAF rule action or label name.

                • ActionCondition (dict) --

                  Matches log records based on the WAF rule action taken (ALLOW, BLOCK, COUNT, etc.).

                  • Action (string) --

                    The WAF action to match against (ALLOW, BLOCK, COUNT, CAPTCHA, CHALLENGE, EXCLUDED_AS_COUNT).

                • LabelNameCondition (dict) --

                  Matches log records based on WAF rule labels applied to the request.

                  • LabelName (string) --

                    The label name to match, supporting alphanumeric characters, underscores, hyphens, and colons.

        • DefaultBehavior (string) --

          The default action (KEEP or DROP) for log records that don't match any filter conditions.

      • LogType (string) --

        The type of WAF logs to collect (currently supports WAF_LOGS).

    • LogDeliveryParameters (dict) --

      The configuration parameters for log delivery when the resource type supports configurable log types, such as Amazon Bedrock Knowledge Bases or Elastic Load Balancing Application Load Balancers.

      • LogTypes (list) --

        The types of logs to collect from the resource.

        • (string) --

          The following log types are supported for log delivery configuration:

          • APPLICATION_LOGS – Application-level logs.

          • USAGE_LOGS – Resource usage logs.

          • SECURITY_FINDING_LOGS – Security finding logs.

          • ACCESS_LOGS – Access logs (such as Elastic Load Balancing access logs).

          • CONNECTION_LOGS – Connection logs.

          • S3_SERVER_ACCESS_LOGS – Amazon S3 server access logs.

    • MskMonitoringParameters (dict) --

      Configuration parameters specific to MSK monitoring when MSK is the resource type.

      • EnhancedMonitoring (string) --

        The level of enhanced monitoring for the MSK cluster.

    • KmsKeyArn (string) --

      The Amazon Resource Name (ARN) of the customer-managed Amazon Web Services KMS key used to encrypt the log groups created during telemetry rule remediation.

  • Scope (string) --

    The organizational scope to which the rule applies, specified using accounts or organizational units.

  • SelectionCriteria (string) --

    Criteria for selecting which resources the rule applies to, such as resource tags.

  • AllowFieldUpdates (boolean) --

    If set to true, Amazon CloudWatch Observability Admin detects and remediates configuration drift in telemetry resources that it manages. For example, if a VPC flow log's format, traffic type, or aggregation interval no longer matches the rule's destination configuration, the flow log is replaced with one that matches. Only Observability Admin-managed resources are updated; customer-created resources are never modified. Currently supported for AWS::EC2::VPC resources (VPC flow logs).

  • Regions (list) --

    An optional list of Amazon Web Services Regions where this telemetry rule should be replicated. When specified, the rule is created in the home region and automatically replicated to all listed regions. Mutually exclusive with AllRegions.

    • (string) --

  • AllRegions (boolean) --

    If set to true, the telemetry rule is replicated to all Amazon Web Services Regions where Amazon CloudWatch Observability Admin is available in the current partition. When new regions become available, the rule automatically replicates to them. Mutually exclusive with Regions.

rtype:

dict

returns:

Response Syntax

{
    'RuleArn': 'string'
}

Response Structure

  • (dict) --

    • RuleArn (string) --

      The Amazon Resource Name (ARN) of the updated organization telemetry rule.