Logging and monitoring in Amazon Directory Service
As a best practice, monitor your organization to ensure that changes are logged. This helps you to ensure that any unexpected change can be investigated and unwanted changes can be rolled back. Amazon Directory Service currently supports the following two Amazon services, so you can monitor your organization and the activity that happens within it.
-
Amazon CloudWatch - You can use CloudWatch Events with the Amazon Managed Microsoft AD directory type. For more information, see Enabling Amazon CloudWatch Logs log forwarding for Amazon Managed Microsoft AD. Additionally, you can use CloudWatch Metrics to monitor domain controller performance. For more information, see Determining when to add domain controllers with CloudWatch metrics.
-
Amazon CloudTrail
-
You can use CloudTrail with all Amazon Directory Service directory types. For more information, see Logging Amazon Directory Service API calls using Amazon CloudTrail.
-
You can use CloudTrail with Amazon Managed Microsoft AD in the Directory Service Data API. For more information, see Logging Amazon Directory Service Data API calls using Amazon CloudTrail.
-