View a markdown version of this page

Monitoring Route 53 Global Resolver with Amazon CloudWatch - Amazon Route 53
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Monitoring Route 53 Global Resolver with Amazon CloudWatch

Route 53 Global Resolver DNS publishes query log data directly to Amazon CloudWatch Logs. With CloudWatch Logs, you can search and analyze your log data, create metric filters that define patterns to look for in the data, and set alarms that send notifications based on those metric filters. For more information about Amazon CloudWatch Logs, see What is Amazon CloudWatch Logs?

You can process Route 53 Global Resolver DNS query log records as you would with any other log events that CloudWatch Logs collects. For more information about monitoring log data and metric filters, see Creating metrics from log events using filters in the Amazon CloudWatch Logs User Guide.

Example: Create a Amazon CloudWatch metric filter and alarm for blocked DNS queries

The following example shows you how to create a metric filter that counts blocked DNS queries in your Route 53 Global Resolver logs. It also shows you how to create an alarm that notifies you when 10 or more blocked queries occur within a 1-hour period.

Step 1: Create the metric filter
  1. Open the CloudWatch console at https://console.aws.amazon.com/cloudwatch/.

  2. In the navigation pane, choose Logs, then Log groups.

  3. Select your Route 53 Global Resolver log group, which is located in the observability Region that you set for Route 53 Global Resolver, and then choose Actions, Create metric filter.

  4. For Filter pattern, enter the following. This matches any log entry in which a firewall rule blocked the DNS query: { $.disposition = "Blocked" }

  5. To verify the pattern works, select a log stream under Select log data to test and choose Test pattern.

  6. Choose Next.

  7. Provide a filter name, set the metric namespace to Route53GlobalResolver, and provide a metric name.

  8. Set the metric value to 1 so that each blocked query increments the count.

  9. Choose Dimensions and add a custom dimension. The dimension name and value can be one of the following.

    Metric filter dimensions for Route 53 Global Resolver logs
    Dimension name Value
    DNSViewId $.enrichments[0].data.dns_view_id
    AccessTokenId $.enrichments[0].data.token_id
    AccessSourceCidr $.enrichments[0].data.access_source_cidr
    GlobalResolverId $.enrichments[0].value
  10. Choose Next, then Create metric filter.

Step 2: Create the alarm
  1. In the navigation pane, choose Alarms, All alarms.

  2. Choose Create alarm.

  3. Find and select the metric you created, then choose Select metric.

  4. Configure the alarm as follows, then choose Next:

    • For Statistic, choose Sum to count all blocked queries in the window.

    • For Period, choose 1 hour.

    • For Whenever, choose Greater/Equal and enter 10 for the threshold.

    • For Additional configuration, Datapoints to alarm, leave the default of 1.

  5. Choose or create an Amazon SNS topic to receive the notification. Choose Next.

  6. Enter a name and description for the alarm and choose Next.

  7. Review the configuration and choose Create alarm.