Skip to content

Lesson 04 — Amazon CloudWatch Logs, Metrics, Dashboards & Enterprise Monitoring Architecture

Learning Path

☁️ Phase 02 – AWS Cloud Security

📘 Module 13 – Enterprise Security Operations, Logging, Monitoring & Threat Detection

By the end of this lesson, you will be able to:

  • Explain Amazon CloudWatch architecture.
  • Understand CloudWatch Logs.
  • Understand Metrics.
  • Understand Dashboards.
  • Configure Alarms.
  • Configure Composite Alarms.
  • Configure Metric Filters.
  • Query logs using CloudWatch Logs Insights.
  • Understand CloudWatch Events.
  • Integrate CloudWatch with EventBridge.
  • Monitor enterprise workloads.
  • Build SOC dashboards.
  • Design enterprise monitoring architecture.
  • Monitor cloud security controls.
  • Detect operational anomalies.
  • Integrate CloudWatch with Security Operations.
  • Build enterprise alerting strategies.
  • Design enterprise monitoring governance.
  • Secure CloudWatch.
  • Apply CloudWatch best practices.

Area Details
Estimated Time 8–10 Hours
Difficulty Advanced
Prerequisites Lesson 03 – AWS CloudTrail Enterprise Logging
Hands-on Labs Yes
AWS Services CloudWatch, CloudTrail, EventBridge, SNS, Lambda, Systems Manager

CloudNova Technologies has successfully centralised CloudTrail logging across all AWS accounts.

However, security teams still struggle to detect incidents quickly.

Current challenges include:

  • No central monitoring dashboards.
  • Critical EC2 instances not monitored.
  • Failed logins go unnoticed.
  • CPU spikes are detected hours later.
  • Security logs are collected but not analysed.
  • No CloudWatch Alarms for security events.
  • Metric Filters are not configured.
  • Logs are difficult to search during investigations.
  • Different business units create inconsistent dashboards.
  • Alert fatigue due to poor alarm configuration.
  • No standard naming convention.
  • Limited visibility into production workloads.

During a ransomware simulation, CloudNova discovers that although all API calls were recorded in CloudTrail, nobody noticed suspicious behaviour until several hours later.

The CISO asks:

“How can we transform raw logs into actionable alerts and real-time operational visibility across our AWS environment?”


Cover:

  • What is CloudWatch?
  • Why CloudWatch matters.
  • Monitoring vs Logging.
  • Operational monitoring.
  • Security monitoring.
  • Business monitoring.

Explain:

  • Metrics
  • Logs
  • Dashboards
  • Alarms
  • Composite Alarms
  • Metric Filters
  • Logs Insights
  • Events
  • Agent
  • Contributor Insights
  • Application Insights
  • Anomaly Detection

Architecture Diagram

AWS Resources
CloudWatch Agent
CloudWatch Logs
Metrics
Metric Filters
CloudWatch Alarms
SNS / EventBridge
SOC
Incident Response

Explain:

  • Metrics
  • Namespaces
  • Dimensions
  • Logs
  • Log Groups
  • Log Streams
  • Dashboards
  • Alarms
  • Insights
  • Events
  • Contributor Insights

Topics:

  • Log Groups
  • Log Streams
  • Retention
  • Encryption
  • Subscription Filters
  • Cross-account logging
  • Enterprise logging strategy

Explain:

  • Standard Metrics
  • Custom Metrics
  • Dimensions
  • Statistics
  • Aggregation
  • Resolution
  • High-resolution metrics

Enterprise dashboards for:

  • SOC
  • Operations
  • Executive Management
  • Security Team
  • DevOps Team
  • Cloud Engineering

Cover:

  • Static Thresholds
  • Dynamic Thresholds
  • Alarm States
  • SNS Notifications
  • Lambda Actions
  • Auto Scaling
  • Systems Manager Automation

Explain:

  • Alarm correlation
  • Noise reduction
  • Enterprise alerting
  • Operational examples

Create metrics from:

  • CloudTrail
  • Application Logs
  • Authentication Logs
  • Security Events
  • API Activity

Enterprise examples:

  • Console login failures
  • Root account usage
  • IAM policy changes
  • Security group modifications
  • CloudTrail stopped

Topics:

  • Query language
  • Search
  • Filter
  • Parse
  • Stats
  • Time-series analysis
  • Investigation examples

Explain:

  • Top users
  • Top IP addresses
  • Most active services
  • Security use cases
  • Performance use cases

Cover:

  • Machine-learning baseline
  • Dynamic thresholds
  • False positives
  • Enterprise monitoring

Monitor:

  • Identity
  • Compute
  • Network
  • Storage
  • Databases
  • Containers
  • Serverless
  • Applications
  • Security Services

Monitor:

  • Failed console logins
  • Root usage
  • IAM changes
  • Security group modifications
  • KMS events
  • CloudTrail health
  • Config failures
  • GuardDuty findings

Create dashboards for:

  • SOC Operations
  • Cloud Operations
  • Security Management
  • Executive KPIs
  • Compliance
  • Incident Response

Govern:

  • Naming
  • Retention
  • Encryption
  • Access
  • Dashboards
  • Alarm ownership
  • Documentation
  • Cost optimisation

Threats include:

  • Deleted log groups
  • Disabled alarms
  • Missing metrics
  • Alarm suppression
  • Unauthorised dashboard changes
  • Excessive permissions
  • Log tampering

AWS Accounts
CloudWatch Agent
CloudWatch Logs
Metrics
Metric Filters
CloudWatch Dashboards
CloudWatch Alarms
SNS
EventBridge
Security Operations Centre

CloudWatch integrates with:

  • CloudTrail
  • GuardDuty
  • Security Hub
  • AWS Config
  • Lambda
  • SNS
  • EventBridge
  • Systems Manager
  • Security Lake

Example workflow:

CloudTrail Event
Metric Filter
CloudWatch Alarm
SNS
EventBridge
Lambda
SOC Notification
Investigation

Configure Enterprise CloudWatch Architecture


Create Enterprise Log Groups


Configure Metric Filters


Create Security Alarms


Build Enterprise Dashboards


Configure Composite Alarms


Use CloudWatch Logs Insights


Investigate IAM Activity Using CloudWatch


Monitor CloudTrail Events


Enterprise CloudWatch Assessment


Students configure:

  • Log Groups
  • Log Streams
  • Dashboards
  • Metrics
  • Metric Filters
  • Alarms
  • Composite Alarms
  • Logs Insights
  • Contributor Insights
  • Anomaly Detection

Terminal window
# List CloudWatch log groups
aws logs describe-log-groups
# List log streams
aws logs describe-log-streams \
--log-group-name CloudTrail
# Retrieve log events
aws logs get-log-events \
--log-group-name CloudTrail \
--log-stream-name STREAM_NAME
# Create a metric filter
aws logs put-metric-filter
# List CloudWatch metrics
aws cloudwatch list-metrics
# View metric statistics
aws cloudwatch get-metric-statistics
# Create a CloudWatch alarm
aws cloudwatch put-metric-alarm
# List alarms
aws cloudwatch describe-alarms
# Describe dashboards
aws cloudwatch list-dashboards

Students should be able to:

  • Explain CloudWatch architecture.
  • Create Log Groups.
  • Configure Log Streams.
  • Configure Metrics.
  • Create Metric Filters.
  • Configure Alarms.
  • Configure Composite Alarms.
  • Build Dashboards.
  • Query Logs Insights.
  • Integrate CloudWatch with CloudTrail.
  • Monitor enterprise workloads.
  • Design enterprise monitoring strategies.
  • Implement CloudWatch governance.

CloudNova standards:

  • Standardise Log Group naming conventions.
  • Encrypt CloudWatch Logs using customer-managed KMS keys.
  • Configure log-retention policies for every Log Group.
  • Use Metric Filters for high-value security events.
  • Build role-specific dashboards for SOC, Operations and Management.
  • Reduce alert fatigue with Composite Alarms.
  • Regularly review alarm thresholds.
  • Integrate CloudWatch with EventBridge and Security Operations.
  • Monitor CloudWatch service health and alarm delivery.

  • Using default log-retention settings.
  • Creating too many alarms.
  • Ignoring alarm ownership.
  • Never testing alarms.
  • Not encrypting Log Groups.
  • Treating dashboards as static reports.
  • Forgetting to tune Metric Filters.
  • Allowing alert fatigue to grow.
  • Ignoring CloudWatch costs.
  • Failing to monitor alarm failures.

Design CloudNova’s enterprise CloudWatch monitoring platform supporting:

  • 500 AWS accounts
  • Multi-Region monitoring
  • SOC dashboards
  • Executive dashboards
  • Security dashboards
  • Composite Alarms
  • EventBridge integration
  • Lambda automation
  • CloudTrail integration
  • Security Lake integration

Prepare:

  1. Monitoring architecture
  2. Dashboard strategy
  3. Alarm catalogue
  4. Metric Filter catalogue
  5. Governance framework
  6. Cost-optimisation strategy
  7. Operational runbook
  8. Monitoring maturity roadmap

Create and answer 50 enterprise-level questions covering:

  • CloudWatch architecture
  • Log Groups
  • Log Streams
  • Metrics
  • Dashboards
  • Alarms
  • Composite Alarms
  • Metric Filters
  • Logs Insights
  • Contributor Insights
  • Anomaly Detection
  • CloudWatch governance
  • Enterprise monitoring
  • Security monitoring

After completing this lesson, you should be able to:

  • Design enterprise monitoring architectures using Amazon CloudWatch.
  • Build secure Log Groups, Metrics, Dashboards and Alarms.
  • Convert raw logs into actionable security alerts using Metric Filters.
  • Use CloudWatch Logs Insights to investigate operational and security events.
  • Integrate CloudWatch with CloudTrail, EventBridge, Lambda and Security Operations workflows.
  • Establish governance, monitoring standards and dashboards that support 24×7 enterprise cloud operations.

➡️ Lesson 05 — AWS Config, Configuration Compliance, Conformance Packs & Enterprise Governance