Elasticsearch domain error logging to CloudWatch Logs should be enabled
Severity: Medium
Resource Types: AWS::ElasticsearchService::Domain
Description
This control checks whether Elasticsearch domains are configured to send error logs to CloudWatch Logs.
You should enable error logs for Elasticsearch domains and send those logs to CloudWatch Logs for retention and response. Domain error logs can assist with security and access audits, and can help to diagnose availability issues.
Remediation
For information on how to enable log publishing, see Enabling log publishing (console) in the Amazon OpenSearch Service Developer Guide.