Configure health-based detection for your protections - Amazon WAF, Amazon Firewall Manager, and Amazon Shield Advanced
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Configure health-based detection for your protections

Configure Shield Advanced to use health-based detection to improve responsiveness and accuracy in attack detection and mitigation. Well-configured health checks are essential for accurate detection of events. You can configure health-based detection for any resource type except for Route 53 hosted zones.

To use health-based detection, define a health check for your resource in Route 53, and then associate the health check with your Shield Advanced protection. It's important that the health check that you configure accurately reflect the health of the resource. For information and examples for configuring health checks to use with Shield Advanced, see Health-based detection using health checks.

Health checks are required for Shield Response Team (SRT) proactive engagement support. For information about proactive engagement, see Configuring proactive engagement.


Health checks must be reporting healthy when you associate them with your Shield Advanced protections.

To configure health-based detection
  1. Under Associated Health Check, choose the ID of the health check that you want to associate with the protection.


    If you do not see the health check you need, go to the Route 53 console and verify the health check and its ID. For information, see Creating and Updating Health Checks.

  2. Choose Next. The console wizard advances to the alarms and notifications page.