Mask sensitive Amazon DocumentDB log data with Amazon CloudWatch Logs data protection
Database Blog
This article discusses how to mask sensitive data in Amazon DocumentDB profiler logs using Amazon CloudWatch Logs data protection policies.
Specifically, the article covers:
- Solution overview for masking sensitive data in Amazon DocumentDB logs
- Prerequisites for following the examples
- Identifying sensitive information and mapping it to CloudWatch Logs data identifiers
- Creating a data protection policy for the Amazon DocumentDB log group
- Validating the masking of sensitive data in CloudWatch Logs
- Monitoring masked data with CloudWatch metrics and audit logs
- Cleaning up resources created for the solution
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 6
2024
2024
How Amazon CloudWatch Logs Data Protection can help detect and protect sensitive log data
Oct 30
2025
2025
Handling sensitive log data using Amazon CloudWatch
Jul 23
2024
2024
Detect and protect sensitive data with Amazon Lex and Amazon CloudWatch Logs
Nov 26
2025
2025
Amazon CloudWatch now supports deletion protection for logs
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.