AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard

A security engineer has deployed a new web application on Amazon EKS. The application consists of multiple microservices running in pods across several nodes. The engineer needs to collect detailed logs from these pods, including application-specific logs and container runtime logs, and centralize them for monitoring and troubleshooting. The solution must be scalable, resilient, and allow for easy searching and analysis. Which logging approach should the engineer implement?

  1. AConfigure each pod to write logs directly to Amazon S3 buckets.
  2. BImplement a sidecar container in each pod to tail logs and send them to Amazon Kinesis Data Firehose, which delivers to Amazon OpenSearch Service.
  3. CInstall the CloudWatch agent on each EKS node to collect logs and send them to CloudWatch Logs.
  4. DUse `kubectl logs` command to manually retrieve logs from each pod and store them locally.
Show answer & explanation

Correct answer: B. Implement a sidecar container in each pod to tail logs and send them to Amazon Kinesis Data Firehose, which delivers to Amazon OpenSearch Service.

Implementing a sidecar container for log collection is a common pattern in EKS for isolating logging concerns. Kinesis Data Firehose provides scalable, real-time ingestion, and OpenSearch Service offers powerful, centralized search and analysis capabilities for the collected logs, addressing scalability, resilience, and searchability.

Why the other options are wrong

  • A. Writing directly to S3 from pods is inefficient for real-time analysis and complicates searching across multiple log streams.
  • C. While the CloudWatch agent on nodes can work for node-level logs, a sidecar pattern within pods is often preferred for application-specific logs in EKS, giving more control and isolation, and OpenSearch offers more powerful search than CloudWatch Logs for complex EKS environments.
  • D. Manually retrieving logs is not scalable, resilient, or suitable for continuous monitoring in a production EKS environment.

EKS Container Logging

Collecting and centralizing application and container runtime logs from Amazon EKS pods for monitoring and analysis.

  • Requires a robust, scalable collection mechanism
  • Centralized storage and analysis are critical
  • Common patterns include sidecars or DaemonSets

Memory trick: Sidecar grabs logs, Firehose streams, OpenSearch finds the gleam.

More Domain 2: Logging and Monitoring questions