Control: AWS WAF rules should have CloudWatch metrics enabled
Description
This control checks whether an AWS WAF rule or rule group has Amazon CloudWatch metrics enabled. The control fails if the rule or rule group doesn't have CloudWatch metrics enabled.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.wafv2_rule_group_logging_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.wafv2_rule_group_logging_enabled --share
SQL
This control uses a named query:
wafv2_rule_group_logging_enabled