Zum Hauptinhalt springen

Monitoring und Alarmierung

Gilt für:
AWS CloudWatchXKS Proxy LogsPerformance Monitoring

Überblick​

Ein effektives Monitoring für AWS XKS umfasst:

CloudWatch-Metriken

Verfolgen Sie Leistung und Zustand des XKS-Proxy

Proxy-Protokolle

Überwachen Sie detaillierte Proxy-Vorgänge

Schlüsselmanager-Protokolle

Verfolgen Sie Schlüsselvorgänge an der Quelle

Sicherheitsüberwachung

Erkennen Sie Anomalien und unbefugten Zugriff

AWS CloudWatch-Metriken​

Wichtige Metriken​

MetrikBeschreibungSchwellenwerte
XksProxyLatencyZeit, die AWS KMS auf Proxy-Antworten wartetNormal: <50 ms, Warnung: 50-100 ms, Kritisch: >100 ms
XksProxyCredentialAgeAlter der Proxy-AuthentifizierungsdatenAlle 90 Tage rotieren
NumberOfRequestsAnzahl der KMS-AnfragenAuf Anomalien überwachen
UserErrorCountAnzahl fehlgeschlagener AnfragenBei erhöhten Raten alarmieren
Metrik XksProxyLatency anzeigenBASH
# View XksProxyLatency metric
aws cloudwatch get-metric-statistics \
  --namespace AWS/KMS \
  --metric-name XksProxyLatency \
  --dimensions Name=CustomKeyStoreId,Value=cks-1234567890abcdef0 \
  --start-time $(date -u -d '1 hour ago' '+%Y-%m-%dT%H:%M:%S') \
  --end-time $(date -u '+%Y-%m-%dT%H:%M:%S') \
  --period 300 \
  --statistics Average,Maximum,Minimum \
  --output table
Alter der Anmeldedaten prüfenBASH
# Check credential age
aws cloudwatch get-metric-statistics \
  --namespace AWS/KMS \
  --metric-name XksProxyCredentialAge \
  --dimensions Name=CustomKeyStoreId,Value=cks-1234567890abcdef0 \
  --start-time $(date -u -d '24 hours ago' '+%Y-%m-%dT%H:%M:%S') \
  --end-time $(date -u '+%Y-%m-%dT%H:%M:%S') \
  --period 3600 \
  --statistics Maximum \
  --output table

CloudWatch-Alarme erstellen​

Alarm für hohe Latenz erstellenBASH
aws cloudwatch put-metric-alarm \
  --alarm-name xks-high-latency \
  --alarm-description "Alert when XKS proxy latency exceeds threshold" \
  --metric-name XksProxyLatency \
  --namespace AWS/KMS \
  --statistic Average \
  --period 300 \
  --evaluation-periods 2 \
  --threshold 100 \
  --comparison-operator GreaterThanThreshold \
  --dimensions Name=CustomKeyStoreId,Value=cks-1234567890abcdef0 \
  --alarm-actions arn:aws:sns:us-east-1:123456789012:xks-alerts

CloudWatch-Dashboard​

Dashboard-DefinitionJSON
{
"widgets": [
  {
    "type": "metric",
    "properties": {
      "metrics": [
        ["AWS/KMS", "XksProxyLatency", {"stat": "Average"}],
        ["...", {"stat": "Maximum"}]
      ],
      "period": 300,
      "stat": "Average",
      "region": "us-east-1",
      "title": "XKS Proxy Latency",
      "yAxis": {
        "left": {
          "min": 0,
          "max": 200
        }
      }
    }
  },
  {
    "type": "metric",
    "properties": {
      "metrics": [
        ["AWS/KMS", "NumberOfRequests", {"stat": "Sum"}]
      ],
      "period": 300,
      "stat": "Sum",
      "region": "us-east-1",
      "title": "Request Volume"
    }
  },
  {
    "type": "metric",
    "properties": {
      "metrics": [
        ["AWS/KMS", "UserErrorCount", {"stat": "Sum"}],
        [".", "SystemErrorCount", {"stat": "Sum"}]
      ],
      "period": 300,
      "stat": "Sum",
      "region": "us-east-1",
      "title": "Error Rates"
    }
  }
]
}
Dashboard anwendenBASH
aws cloudwatch put-dashboard \
  --dashboard-name XKS-Monitoring \
  --dashboard-body file://xks-dashboard.json

XKS-Proxy-Protokollierung​

Proxy-Protokollierung konfigurieren​

Konfiguration der Proxy-ProtokollierungYAML
logging:
level: info # debug, info, warn, error
format: json
output: /var/log/duokey-xks-proxy/proxy.log
rotation:
  max_size: 100MB
  max_age: 30
  max_backups: 10
  compress: true

# Log specific components
components:
  authentication: debug
  encryption: info
  routing: info
  health: warn

Protokollanalyse​

Proxy-Protokolle analysierenBASH
# Count requests by operation
cat /var/log/duokey-xks-proxy/proxy.log | \
  jq -r '.operation' | sort | uniq -c

# Average latency by backend
cat /var/log/duokey-xks-proxy/proxy.log | \
  jq -r 'select(.backend != null) | "\(.backend) \(.duration_ms)"' | \
  awk '{sum[$1]+=$2; count[$1]++} END {for (b in sum) print b, sum[b]/count[b]}'

# Failed requests in last hour
cat /var/log/duokey-xks-proxy/proxy.log | \
  jq -r 'select(.status == "error" and .timestamp > "'$(date -u -d '1 hour ago' '+%Y-%m-%dT%H:%M:%S')'")'

Protokolle an CloudWatch senden​

Konfiguration des CloudWatch Logs AgentJSON
{
"logs": {
  "logs_collected": {
    "files": {
      "collect_list": [
        {
          "file_path": "/var/log/duokey-xks-proxy/proxy.log",
          "log_group_name": "/aws/xks/proxy",
          "log_stream_name": "{instance_id}",
          "timestamp_format": "%Y-%m-%dT%H:%M:%S"
        }
      ]
    }
  }
}
}

Netzwerküberwachung​

Netzwerklatenz überwachenBASH
#!/bin/bash
# Monitor round-trip time to XKS proxy

PROXY_HOST="xks-proxy.example.com"
LOG_FILE="/var/log/xks-network-monitor.log"

while true; do
  TIMESTAMP=$(date -u '+%Y-%m-%dT%H:%M:%S')
  RTT=$(curl -o /dev/null -s -w '%{time_total}' https://$PROXY_HOST/health)
  RTT_MS=$(echo "$RTT * 1000" | bc)

  echo "$TIMESTAMP,$RTT_MS" >> $LOG_FILE

  # Alert if RTT exceeds threshold
  if (( $(echo "$RTT_MS > 100" | bc -l) )); then
      echo "WARNING: High latency detected: ${RTT_MS}ms" | \
          aws sns publish \
              --topic-arn arn:aws:sns:us-east-1:123456789012:xks-alerts \
              --subject "XKS High Latency Alert"
  fi

  sleep 60
done
Ablauf des TLS-Zertifikats überwachenBASH
#!/bin/bash
# Check XKS proxy TLS certificate expiration

PROXY_HOST="xks-proxy.example.com"
CERT_EXPIRY=$(echo | openssl s_client -servername $PROXY_HOST \
  -connect $PROXY_HOST:443 2>/dev/null | openssl x509 -noout -enddate | \
  cut -d= -f2)

EXPIRY_EPOCH=$(date -d "$CERT_EXPIRY" +%s)
CURRENT_EPOCH=$(date +%s)
DAYS_UNTIL_EXPIRY=$(( ($EXPIRY_EPOCH - $CURRENT_EPOCH) / 86400 ))

echo "Certificate expires in $DAYS_UNTIL_EXPIRY days"

if [ $DAYS_UNTIL_EXPIRY -lt 30 ]; then
  echo "WARNING: Certificate expires soon!" | \
      aws sns publish \
          --topic-arn arn:aws:sns:us-east-1:123456789012:xks-alerts \
          --subject "XKS Certificate Expiration Warning"
fi

Sicherheitsüberwachung​

AWS CloudTrail-Integration​

CloudTrail nach XKS-Ereignissen abfragenBASH
# Query CloudTrail for XKS-related events
aws cloudtrail lookup-events \
  --lookup-attributes \
      AttributeKey=ResourceName,AttributeValue=cks-1234567890abcdef0 \
  --start-time $(date -u -d '24 hours ago' '+%Y-%m-%dT%H:%M:%S') \
  --query 'Events[*].{
      Time:EventTime,
      User:Username,
      Event:EventName,
      Resource:Resources[0].ResourceName
  }' \
  --output table

Ungewöhnliche Aktivitäten erkennen​

Anomalien erkennenBASH
#!/bin/bash
# Detect unusual patterns in XKS usage

# Spike in failed requests
FAILED_COUNT=$(cat /var/log/duokey-xks-proxy/proxy.log | \
  jq -r 'select(.timestamp > "'$(date -u -d '5 minutes ago' '+%Y-%m-%dT%H:%M:%S')'"
      and .status == "error")' | wc -l)

if [ $FAILED_COUNT -gt 50 ]; then
  echo "ALERT: Unusual spike in failed requests: $FAILED_COUNT in 5 minutes"
fi

# Requests from unexpected IPs
KNOWN_IPS="52.94.133.0/24,52.95.0.0/16"
UNKNOWN_IPS=$(cat /var/log/duokey-xks-proxy/proxy.log | \
  jq -r '.source_ip' | sort -u | \
  grep -v -f <(echo $KNOWN_IPS | tr ',' '\n'))

if [ -n "$UNKNOWN_IPS" ]; then
  echo "ALERT: Requests from unknown IPs: $UNKNOWN_IPS"
fi

Alarmierungsstrategien​

Kritische Alarme (sofortige Maßnahme)​

AlarmAuslöserMaßnahme
XKS-Proxy nicht erreichbar3 aufeinanderfolgende Health-Check-FehlerBereitschaftsingenieur per Pager benachrichtigen
Authentifizierungsfehler>10 Authentifizierungsfehler in 5 MinutenBenachrichtigung des Sicherheitsteams
Extreme LatenzDurchschnitt >200 ms über 10 MinutenBenachrichtigung des Betriebsteams

Warnungsalarme (Untersuchung erforderlich)​

AlarmAuslöserMaßnahme
Erhöhte LatenzDurchschnitt >100 ms über 15 MinutenBetriebsteam per E-Mail benachrichtigen
Zertifikatsablauf<30 Tage bis zum AblaufSicherheitsteam per E-Mail benachrichtigen
Hohe FehlerrateFehlerrate >5 % über 10 MinutenBetriebsteam per E-Mail benachrichtigen

Info-Alarme (Kenntnisnahme)​

AlarmAuslöserMaßnahme
Alter der AnmeldedatenAnmeldedaten älter als 60 TageE-Mail-Erinnerung zur Rotation
NutzungsspitzeAnfragevolumen 2x normale BaselineBetriebsteam per E-Mail benachrichtigen

Best Practices für das Monitoring​

Monitoring-Checkliste

Baselines festlegenMetriken 1-2 Wochen lang für normale betriebliche Baselines erfassen
Runbooks erstellenReaktionsverfahren für jeden Alarmtyp dokumentieren
Regelmäßige ÜberprüfungWöchentliche Metrikprüfung, monatliche Aktualisierung der Schwellenwerte
Monitoring testenAlarmierung regelmäßig durch Simulation von Ausfällen testen

Compliance-Berichterstattung​

Monatlichen Compliance-Bericht erstellenBASH
#!/bin/bash
# Generate monthly XKS compliance report

MONTH=$(date -u -d 'last month' '+%Y-%m')
REPORT_FILE="xks-compliance-report-$MONTH.txt"

echo "DuoKey AWS XKS Compliance Report - $MONTH" > $REPORT_FILE
echo "==========================================" >> $REPORT_FILE
echo "" >> $REPORT_FILE

# Key Operations Summary
echo "Key Operations Summary:" >> $REPORT_FILE
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=ResourceType,AttributeValue=AWS::KMS::Key \
  --start-time $(date -u -d "$MONTH-01" '+%Y-%m-%dT%H:%M:%S') \
  --end-time $(date -u -d "$MONTH-01 +1 month" '+%Y-%m-%dT%H:%M:%S') \
  --query 'Events[*].EventName' | \
  jq -r '.[]' | sort | uniq -c >> $REPORT_FILE

Nächste Schritte​