Conclusion

Cleanup

  1. Return to the CloudFormation console

  2. [OPTIONAL] If you deployed the optional stack, click the check box next to it.

  3. [OPTIONAL] From the Actions menu, select Delete stack.

  4. [OPTIONAL] This will clean up the bucket and all of the objects in it. You can return to Kibana to see the DeleteObject events.

  5. Click the check box next to your stack.

  6. From the Actions menu, select Delete Stack.

  7. [Depending on how long you’ve run the stack, the DeleteRawBucketObjects Lambda invocation might fail. If that happens, wait for the stack status to become DELETE_FAILED. Then delete the stack again.]

Conclusion

Congratulations! You now know how to:

  • Send CloudTrail logs to CloudWatch Logs

  • Create a subscription filter to send logs from a CloudWatch Logs log group to Amazon ES

  • Build Kibana visualizations and dashboards to monitor your AWS usage

Additional Resources