Ensure that you have an alert monitoring rule and an alert configured to trigger a notification alarm whenever an RDS database instance configuration change is made. Your alert monitoring rule should query ActionTrail logs for events related to RDS modifications, such as "ModifyDBInstanceSpec", "ModifyDBInstanceSSL", and "DeleteBackup".
Using Simple Log Service (SLS) alerts to detect RDS instance configuration changes helps prevent accidental or intentional modifications that could lead to unauthorized access or other security breaches. Misconfiguration can have negative effects on business operations, disaster recovery, and High Availability (HA), while also raising vulnerability to untrusted networks. Therefore, it is highly advised to monitor your Alibaba Cloud account for RDS configuration changes.
Audit
To dentify if an SLS alert exists and is configured correctly to monitor RDS instance configuration changes in your Alibaba Cloud account, perform the following operations:
Checking for Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.Remediation / Resolution
To ensure that a Simple Log Service (SLS) alert exists for RDS instance configuration changes, perform the following operations:
Creating and managing Simple Log Service (SLS) alerts via Alibaba Cloud CLI (aliyun) is not currently supported.