Monitoring und Alarmierung
Monitoring und Alarmierung
Überwachen Sie Zustand, Leistung und Sicherheit Ihres DuoKey AWS XKS Proxy
Gilt für:
AWS CloudWatchXKS Proxy LogsPerformance Monitoring
Überblick
Ein effektives Monitoring für AWS XKS umfasst:
CloudWatch-Metriken
Verfolgen Sie Leistung und Zustand des XKS-Proxy
Proxy-Protokolle
Überwachen Sie detaillierte Proxy-Vorgänge
Schlüsselmanager-Protokolle
Verfolgen Sie Schlüsselvorgänge an der Quelle
Sicherheitsüberwachung
Erkennen Sie Anomalien und unbefugten Zugriff
AWS CloudWatch-Metriken
Wichtige Metriken
| Metrik | Beschreibung | Schwellenwerte |
|---|---|---|
| XksProxyLatency | Zeit, die AWS KMS auf Proxy-Antworten wartet | Normal: <50 ms, Warnung: 50-100 ms, Kritisch: >100 ms |
| XksProxyCredentialAge | Alter der Proxy-Authentifizierungsdaten | Alle 90 Tage rotieren |
| NumberOfRequests | Anzahl der KMS-Anfragen | Auf Anomalien überwachen |
| UserErrorCount | Anzahl fehlgeschlagener Anfragen | Bei erhöhten Raten alarmieren |
Metrik XksProxyLatency anzeigenBASH
# View XksProxyLatency metric
aws cloudwatch get-metric-statistics \
--namespace AWS/KMS \
--metric-name XksProxyLatency \
--dimensions Name=CustomKeyStoreId,Value=cks-1234567890abcdef0 \
--start-time $(date -u -d '1 hour ago' '+%Y-%m-%dT%H:%M:%S') \
--end-time $(date -u '+%Y-%m-%dT%H:%M:%S') \
--period 300 \
--statistics Average,Maximum,Minimum \
--output tableAlter der Anmeldedaten prüfenBASH
# Check credential age
aws cloudwatch get-metric-statistics \
--namespace AWS/KMS \
--metric-name XksProxyCredentialAge \
--dimensions Name=CustomKeyStoreId,Value=cks-1234567890abcdef0 \
--start-time $(date -u -d '24 hours ago' '+%Y-%m-%dT%H:%M:%S') \
--end-time $(date -u '+%Y-%m-%dT%H:%M:%S') \
--period 3600 \
--statistics Maximum \
--output tableCloudWatch-Alarme erstellen
Alarm für hohe Latenz erstellenBASH
aws cloudwatch put-metric-alarm \
--alarm-name xks-high-latency \
--alarm-description "Alert when XKS proxy latency exceeds threshold" \
--metric-name XksProxyLatency \
--namespace AWS/KMS \
--statistic Average \
--period 300 \
--evaluation-periods 2 \
--threshold 100 \
--comparison-operator GreaterThanThreshold \
--dimensions Name=CustomKeyStoreId,Value=cks-1234567890abcdef0 \
--alarm-actions arn:aws:sns:us-east-1:123456789012:xks-alertsCloudWatch-Dashboard
Dashboard-DefinitionJSON
{
"widgets": [
{
"type": "metric",
"properties": {
"metrics": [
["AWS/KMS", "XksProxyLatency", {"stat": "Average"}],
["...", {"stat": "Maximum"}]
],
"period": 300,
"stat": "Average",
"region": "us-east-1",
"title": "XKS Proxy Latency",
"yAxis": {
"left": {
"min": 0,
"max": 200
}
}
}
},
{
"type": "metric",
"properties": {
"metrics": [
["AWS/KMS", "NumberOfRequests", {"stat": "Sum"}]
],
"period": 300,
"stat": "Sum",
"region": "us-east-1",
"title": "Request Volume"
}
},
{
"type": "metric",
"properties": {
"metrics": [
["AWS/KMS", "UserErrorCount", {"stat": "Sum"}],
[".", "SystemErrorCount", {"stat": "Sum"}]
],
"period": 300,
"stat": "Sum",
"region": "us-east-1",
"title": "Error Rates"
}
}
]
}Dashboard anwendenBASH
aws cloudwatch put-dashboard \
--dashboard-name XKS-Monitoring \
--dashboard-body file://xks-dashboard.jsonXKS-Proxy-Protokollierung
Proxy-Protokollierung konfigurieren
Konfiguration der Proxy-ProtokollierungYAML
logging:
level: info # debug, info, warn, error
format: json
output: /var/log/duokey-xks-proxy/proxy.log
rotation:
max_size: 100MB
max_age: 30
max_backups: 10
compress: true
# Log specific components
components:
authentication: debug
encryption: info
routing: info
health: warnProtokollanalyse
Proxy-Protokolle analysierenBASH
# Count requests by operation
cat /var/log/duokey-xks-proxy/proxy.log | \
jq -r '.operation' | sort | uniq -c
# Average latency by backend
cat /var/log/duokey-xks-proxy/proxy.log | \
jq -r 'select(.backend != null) | "\(.backend) \(.duration_ms)"' | \
awk '{sum[$1]+=$2; count[$1]++} END {for (b in sum) print b, sum[b]/count[b]}'
# Failed requests in last hour
cat /var/log/duokey-xks-proxy/proxy.log | \
jq -r 'select(.status == "error" and .timestamp > "'$(date -u -d '1 hour ago' '+%Y-%m-%dT%H:%M:%S')'")'Protokolle an CloudWatch senden
Konfiguration des CloudWatch Logs AgentJSON
{
"logs": {
"logs_collected": {
"files": {
"collect_list": [
{
"file_path": "/var/log/duokey-xks-proxy/proxy.log",
"log_group_name": "/aws/xks/proxy",
"log_stream_name": "{instance_id}",
"timestamp_format": "%Y-%m-%dT%H:%M:%S"
}
]
}
}
}
}Netzwerküberwachung
Netzwerklatenz überwachenBASH
#!/bin/bash
# Monitor round-trip time to XKS proxy
PROXY_HOST="xks-proxy.example.com"
LOG_FILE="/var/log/xks-network-monitor.log"
while true; do
TIMESTAMP=$(date -u '+%Y-%m-%dT%H:%M:%S')
RTT=$(curl -o /dev/null -s -w '%{time_total}' https://$PROXY_HOST/health)
RTT_MS=$(echo "$RTT * 1000" | bc)
echo "$TIMESTAMP,$RTT_MS" >> $LOG_FILE
# Alert if RTT exceeds threshold
if (( $(echo "$RTT_MS > 100" | bc -l) )); then
echo "WARNING: High latency detected: ${RTT_MS}ms" | \
aws sns publish \
--topic-arn arn:aws:sns:us-east-1:123456789012:xks-alerts \
--subject "XKS High Latency Alert"
fi
sleep 60
doneAblauf des TLS-Zertifikats überwachenBASH
#!/bin/bash
# Check XKS proxy TLS certificate expiration
PROXY_HOST="xks-proxy.example.com"
CERT_EXPIRY=$(echo | openssl s_client -servername $PROXY_HOST \
-connect $PROXY_HOST:443 2>/dev/null | openssl x509 -noout -enddate | \
cut -d= -f2)
EXPIRY_EPOCH=$(date -d "$CERT_EXPIRY" +%s)
CURRENT_EPOCH=$(date +%s)
DAYS_UNTIL_EXPIRY=$(( ($EXPIRY_EPOCH - $CURRENT_EPOCH) / 86400 ))
echo "Certificate expires in $DAYS_UNTIL_EXPIRY days"
if [ $DAYS_UNTIL_EXPIRY -lt 30 ]; then
echo "WARNING: Certificate expires soon!" | \
aws sns publish \
--topic-arn arn:aws:sns:us-east-1:123456789012:xks-alerts \
--subject "XKS Certificate Expiration Warning"
fiSicherheitsüberwachung
AWS CloudTrail-Integration
CloudTrail nach XKS-Ereignissen abfragenBASH
# Query CloudTrail for XKS-related events
aws cloudtrail lookup-events \
--lookup-attributes \
AttributeKey=ResourceName,AttributeValue=cks-1234567890abcdef0 \
--start-time $(date -u -d '24 hours ago' '+%Y-%m-%dT%H:%M:%S') \
--query 'Events[*].{
Time:EventTime,
User:Username,
Event:EventName,
Resource:Resources[0].ResourceName
}' \
--output tableUngewöhnliche Aktivitäten erkennen
Anomalien erkennenBASH
#!/bin/bash
# Detect unusual patterns in XKS usage
# Spike in failed requests
FAILED_COUNT=$(cat /var/log/duokey-xks-proxy/proxy.log | \
jq -r 'select(.timestamp > "'$(date -u -d '5 minutes ago' '+%Y-%m-%dT%H:%M:%S')'"
and .status == "error")' | wc -l)
if [ $FAILED_COUNT -gt 50 ]; then
echo "ALERT: Unusual spike in failed requests: $FAILED_COUNT in 5 minutes"
fi
# Requests from unexpected IPs
KNOWN_IPS="52.94.133.0/24,52.95.0.0/16"
UNKNOWN_IPS=$(cat /var/log/duokey-xks-proxy/proxy.log | \
jq -r '.source_ip' | sort -u | \
grep -v -f <(echo $KNOWN_IPS | tr ',' '\n'))
if [ -n "$UNKNOWN_IPS" ]; then
echo "ALERT: Requests from unknown IPs: $UNKNOWN_IPS"
fiAlarmierungsstrategien
Kritische Alarme (sofortige Maßnahme)
| Alarm | Auslöser | Maßnahme |
|---|---|---|
| XKS-Proxy nicht erreichbar | 3 aufeinanderfolgende Health-Check-Fehler | Bereitschaftsingenieur per Pager benachrichtigen |
| Authentifizierungsfehler | >10 Authentifizierungsfehler in 5 Minuten | Benachrichtigung des Sicherheitsteams |
| Extreme Latenz | Durchschnitt >200 ms über 10 Minuten | Benachrichtigung des Betriebsteams |
Warnungsalarme (Untersuchung erforderlich)
| Alarm | Auslöser | Maßnahme |
|---|---|---|
| Erhöhte Latenz | Durchschnitt >100 ms über 15 Minuten | Betriebsteam per E-Mail benachrichtigen |
| Zertifikatsablauf | <30 Tage bis zum Ablauf | Sicherheitsteam per E-Mail benachrichtigen |
| Hohe Fehlerrate | Fehlerrate >5 % über 10 Minuten | Betriebsteam per E-Mail benachrichtigen |
Info-Alarme (Kenntnisnahme)
| Alarm | Auslöser | Maßnahme |
|---|---|---|
| Alter der Anmeldedaten | Anmeldedaten älter als 60 Tage | E-Mail-Erinnerung zur Rotation |
| Nutzungsspitze | Anfragevolumen 2x normale Baseline | Betriebsteam per E-Mail benachrichtigen |
Best Practices für das Monitoring
Monitoring-Checkliste
Baselines festlegenMetriken 1-2 Wochen lang für normale betriebliche Baselines erfassen
Runbooks erstellenReaktionsverfahren für jeden Alarmtyp dokumentieren
Regelmäßige ÜberprüfungWöchentliche Metrikprüfung, monatliche Aktualisierung der Schwellenwerte
Monitoring testenAlarmierung regelmäßig durch Simulation von Ausfällen testen
Compliance-Berichterstattung
Monatlichen Compliance-Bericht erstellenBASH
#!/bin/bash
# Generate monthly XKS compliance report
MONTH=$(date -u -d 'last month' '+%Y-%m')
REPORT_FILE="xks-compliance-report-$MONTH.txt"
echo "DuoKey AWS XKS Compliance Report - $MONTH" > $REPORT_FILE
echo "==========================================" >> $REPORT_FILE
echo "" >> $REPORT_FILE
# Key Operations Summary
echo "Key Operations Summary:" >> $REPORT_FILE
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=ResourceType,AttributeValue=AWS::KMS::Key \
--start-time $(date -u -d "$MONTH-01" '+%Y-%m-%dT%H:%M:%S') \
--end-time $(date -u -d "$MONTH-01 +1 month" '+%Y-%m-%dT%H:%M:%S') \
--query 'Events[*].EventName' | \
jq -r '.[]' | sort | uniq -c >> $REPORT_FILE