Loading controls...
Benchmark: Opensearch
Overview
This section contains recommendations for configuring OpenSearch resources and options.
Usage
Browse dashboards and select Opensearch:
steampipe dashboard
Or run the benchmarks in your terminal:
steampipe check aws_compliance.benchmark.foundational_security_opensearch
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share aws_compliance.benchmark.foundational_security_opensearch
Controls
- 1 OpenSearch domains should have encryption at rest enabled
- 2 OpenSearch domains should be in a VPC
- 3 OpenSearch domains should encrypt data sent between nodes
- 4 OpenSearch domain error logging to CloudWatch Logs should be enabled
- 5 OpenSearch domains should have audit logging enabled
- 6 OpenSearch domains should have at least three data nodes
- 7 OpenSearch domains should have fine-grained access control enabled
- 8 Connections to OpenSearch domains should be encrypted using TLS 1.2