View a markdown version of this page

Overview - Amazon GuardDuty

Overview

The unified Protection Plans page replaces the need to navigate to individual protection plan pages for configuration. The console navigation shows a single Protection Plans link.

The page displays protection plans in the following order:

  1. Foundational GuardDuty – Enable or disable GuardDuty and configure auto-enable for AWS Organizations accounts.

  2. S3 Protection – Monitor Amazon S3 data events for potential threats to your data.

  3. Runtime Monitoring – Monitor operating system-level events for EKS, ECS, and EC2 workloads.

  4. EKS Audit Logs – Monitor Amazon EKS audit logs for potential threats to your clusters.

  5. RDS Protection – Monitor RDS login activity for potential threats to your databases.

  6. Lambda Protection – Monitor Lambda function network activity for potential threats.

Each protection plan displays the following information:

  • Feature status (Enabled or Not enabled)

  • Auto-enable status for AWS Organizations accounts

  • AWS Organizations accounts member statistics