Ensure a log metric filter and alarm exist for usage of root account
Description
Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. It is recommended that a metric filter and alarm be established for root login attempts.
Remediation
Perform the following to ensure a log metric filter and alarm exist for usage of root account
Note: Filter pattern for for usage of root” account