Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever a Cloud Firewall control policy change is made. Your alert monitoring rule should query ActionTrail logs for events related to Cloud Firewall control policy modifications, such as "CreateVpcFirewallControlPolicy", "ModifyVpcFirewallControlPolicy", and "DeleteVpcFirewallControlPolicy".
Using Simple Log Service (SLS) alerts to detect Cloud Firewall control policy changes helps prevent accidental or intentional modifications that could lead to unauthorized access or other security breaches. Monitoring Cloud Firewall control policy changes helps identify network access modifications and shortens the time to detect suspicious activity.
Audit
To dentify if an SLS alert exists and is configured correctly to monitor Cloud Firewall control policy changes in your Alibaba Cloud account, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for Cloud Firewall control policy changes, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.