Open stmag opened 4 years ago
Does GuardDuty cost if there're no associated logs?
To be also verified if FPI (they have delegations) is considered in the end as Commission (it could be solved by not putting them in EC's OU). CloudFront also is in multiple regions, isn't it? (some of our services do need global outreach)
Does GuardDuty cost if there're no associated logs?
In theory it should be very little if there is not much activity within a given region - if we can get it on all regions then would be happy - i guess then the question changes around data residency and if this is an issue or not - guess that question would have to be solved by the customer doing a risk assessment
The alternative is to “deactivate” not allowed regions entirely, and force GD for all allowed regions, but it’s probably better for now to force GD in all regions
But you can’t deactivate US East as you all know.
On 22 Sep 2020, at 14.53, S McGowan notifications@github.com wrote:
Does GuardDuty cost if there're no associated logs?
In theory it should be very little if there is not much activity within a given region - if we can get it on all regions then would be happy - i guess then the question changes around data residency and if this is an issue or not - guess that question would have to be solved by the customer doing a risk assessment
— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub, or unsubscribe.
Possible Action Plan to implement this change request:
@austindimmer here's the plan for the deployment of this ticket.
New feature request - can we enforce SCPs at the EC OU level to prevent certain regions from being used. This could help alleviate costs of deploying GuardDuty in all regions as we would consider this unnecessary if region restrictions were in place.
eg i would never see us using Africa, Middle East, South America regions for example (unless there are edge cases we are not aware of within EC). Some key services (like IAM/DNS operate globally from US regions, so we could not restrict these)