Properties
Optional access-analyzer
access-analyzer: boolean
Optional add-sns-topics
add-sns-topics: boolean
Optional config-aggr
config-aggr: boolean
Optional config-aggr-excl-regions
config-aggr-excl-regions: string[]
Optional config-excl-regions
config-excl-regions: string[]
Optional cwl
cwl: boolean
Optional cwl-access-level
cwl-access-level: string
Optional cwl-glbl-exclusions
cwl-glbl-exclusions: string[]
Optional dynamic-s3-log-partitioning
Optional fw-mgr-alert-level
fw-mgr-alert-level: "None" | "Low" | "Medium" | "High"
Optional guardduty
guardduty: boolean
Optional guardduty-excl-regions
guardduty-excl-regions: string[]
Optional guardduty-s3
guardduty-s3: boolean
Optional guardduty-s3-excl-regions
guardduty-s3-excl-regions: string[]
Optional kinesis-stream-shard-count
kinesis-stream-shard-count: number
Optional macie
macie: boolean
Optional macie-excl-regions
macie-excl-regions: string[]
Optional macie-frequency
macie-frequency: string
Optional macie-sensitive-sh
macie-sensitive-sh: boolean
Optional s3-retention
s3-retention: number
Optional security-hub
security-hub: boolean
Optional security-hub-excl-regions
security-hub-excl-regions: string[]
Optional security-hub-findings-sns
security-hub-findings-sns: "None" | "Low" | "Medium" | "High" | "Critical"
Optional sns-excl-regions
sns-excl-regions: string[]
Optional sns-subscription-emails
sns-subscription-emails: {}
Optional ssm-to-cwl
ssm-to-cwl: boolean
Optional ssm-to-s3
ssm-to-s3: boolean
The Accelerator has the concept of grouping certain sets of functionality (security, logs, ITOps, Management) together and centralizing their respective capabilities into a single account. This section identifies the respective central account and provides the ability to enable/disable services associated with it which are applicable across the organization. The central account will be defined in the
mandatory-account-configs
section of the config file. The respective Organization wide central Services will be defined in this section, eitheraws-org-managment
,central-log-services
,central-operations-services
, orcentral-security-services
. Not all options are available in each of these four sections of the config file.