Monitoring Route 53 Global Resolver with Amazon CloudWatch
Route 53 Global Resolver DNS publishes query log data directly to Amazon CloudWatch Logs. With CloudWatch Logs, you can search
and analyze your log data, create metric filters that define patterns to look for in the data,
and set alarms that send notifications based on those metric filters. For more
information about Amazon CloudWatch Logs, see What
is Amazon CloudWatch Logs?
You can process Route 53 Global Resolver DNS query log records as you would with any other log events
that CloudWatch Logs collects. For more information about monitoring log data and metric filters, see
Creating metrics from log events using filters
Topics
Example: Create a Amazon CloudWatch metric filter and alarm for blocked DNS queries
IAM role for publishing CloudWatch metrics from DNS query logs
Using Amazon CloudWatch Contributor Insights with Route 53 Global Resolver data
Analyzing Route 53 Global Resolver logs with Amazon CloudWatch Logs Insights
Example: Create a Amazon CloudWatch metric filter and alarm for blocked DNS queries
The following example shows you how to create a metric filter that counts blocked DNS queries in your Route 53 Global Resolver logs. It also shows you how to create an alarm that notifies you when 10 or more blocked queries occur within a 1-hour period.
Step 1: Create the metric filter
-
Open the CloudWatch console at https://console.aws.amazon.com/cloudwatch/
. -
In the navigation pane, choose Logs, then Log groups.
-
Select your Route 53 Global Resolver log group, which is located in the observability Region that you set for Route 53 Global Resolver, and then choose Actions, Create metric filter.
-
For Filter pattern, enter the following. This matches any log entry in which a firewall rule blocked the DNS query:
{ $.disposition = "Blocked" } -
To verify the pattern works, select a log stream under Select log data to test and choose Test pattern.
-
Choose Next.
-
Provide a filter name, set the metric namespace to
Route53GlobalResolver, and provide a metric name. -
Set the metric value to 1 so that each blocked query increments the count.
-
Choose Dimensions and add a custom dimension. The dimension name and value can be one of the following.
Metric filter dimensions for Route 53 Global Resolver logs Dimension name Value DNSViewId$.enrichments[0].data.dns_view_idAccessTokenId$.enrichments[0].data.token_idAccessSourceCidr$.enrichments[0].data.access_source_cidrGlobalResolverId$.enrichments[0].value -
Choose Next, then Create metric filter.
Step 2: Create the alarm
-
In the navigation pane, choose Alarms, All alarms.
-
Choose Create alarm.
-
Find and select the metric you created, then choose Select metric.
-
Configure the alarm as follows, then choose Next:
-
For Statistic, choose Sum to count all blocked queries in the window.
-
For Period, choose 1 hour.
-
For Whenever, choose Greater/Equal and enter 10 for the threshold.
-
For Additional configuration, Datapoints to alarm, leave the default of 1.
-
-
Choose or create an Amazon SNS topic to receive the notification. Choose Next.
-
Enter a name and description for the alarm and choose Next.
-
Review the configuration and choose Create alarm.