Incident response, logging, and monitoring in Amazon Quick
| Intended audience: System administrators and Amazon Quick administrators |
Amazon Quick provides multiple monitoring and audit signals that address different aspects of security, operations, and compliance. Each signal has distinct coverage, latency, retention, and access-control characteristics.
-
CloudTrail – Records supported Amazon Quick and Amazon Quick Sight API operations and a documented set of non-API events, such as dashboard views and user-management actions. For chat conversations and feedback, use CloudWatch vended logs.
-
CloudWatch vended logs – Deliver chat conversations, user feedback, agent and research hours usage, index storage usage, and knowledge base file sync results to destinations that you control. Configure vended log delivery shortly after enabling Amazon Quick.
-
CloudWatch metrics – Provide near-real-time operational metrics and support CloudWatch alarms.
-
Amazon Quick analytics – Provide usage, adoption, feedback, and selected security-related insights to IAM administrators.
-
Feature-specific reports – Provide operational detail for the feature that produces them, such as knowledge base sync reports.
Use these sources together when you design monitoring and incident-response procedures. Before you rely on a signal for compliance, detection, or investigation, confirm that it covers the event you intend to track.
The following table helps you choose the right signal for your monitoring need.
| To answer | Use | More information |
|---|---|---|
| Who performed an administrative or API action, from where, and when | CloudTrail | Incident response, logging, and monitoring in Amazon Quick Sight using CloudTrail |
| Who viewed a dashboard, or which non-API events occurred | CloudTrail non-API events | Tracking non-API events by using CloudTrail logs |
| What users asked and what Quick answered | CloudWatch vended logs (CHAT_LOGS) |
Monitoring Amazon Quick usage using CloudWatch Logs |
| How users rated responses and why | Vended logs (FEEDBACK_LOGS) or
analytics |
Monitoring Amazon Quick usage using CloudWatch Logs; Using the Amazon Quick analytics dashboard |
| Whether a document synced into a knowledge base, and why it failed or was skipped | Vended logs (KB_FILE_SYNC_LOGS) or console sync
reports |
Monitoring Amazon Quick usage using CloudWatch Logs; Sync reports and observability |
| Whether a specific user can access a specific synced document | Sync report ACL verification | Sync reports and observability |
| Index storage per knowledge base or Space | Vended logs (INDEX_USAGE_LOGS) or CloudWatch
metrics |
Monitoring Amazon Quick usage using CloudWatch Logs; Monitoring data in Amazon Quick Sight using CloudWatch |
| Operational health: load times, ingestion failures, connector errors, SPICE capacity | CloudWatch metrics and alarms | Monitoring data in Amazon Quick Sight using CloudWatch |
| Adoption, engagement, feedback trends, agent-hours consumption | Analytics dashboard | Using the Amazon Quick analytics dashboard |
Use the following checklist to configure monitoring for your environment:
-
Create a CloudTrail trail for the AWS accounts and AWS Regions that require audit logging.
-
Configure CloudWatch vended log delivery shortly after enabling Amazon Quick AI features.
-
When vended-log destinations use a customer managed AWS KMS key, allow
delivery---logs.amazonaws.com.rproxy.govskope.cain the key policy. -
Chat logs can contain sensitive or personally identifiable data. Filter this information at subscription setup, or apply CloudWatch Logs data-protection masking policies.
-
Configure CloudWatch alarms on operational metrics and map them to your incident-response procedures.
-
Grant
quicksight:QuickSuiteUsageMetrics(analytics access) only to authorized administrators. -
Revalidate your monitoring design when you enable a new Amazon Quick capability.