AWS AWSEC2: EventBridge notifications and managed resource visibility behavior
Summary
Adds a new "EventBridge notifications" subsection explaining that when managed resource visibility is set to Hidden (default), Amazon EC2 does not emit EC2 Instance State-change Notification events to EventBridge for managed instances, and that visibility must be set to Visible to receive them, with a pointer to the Configure managed resource visibility documentation.
Security assessment
The new text documents that the default Hidden visibility silently suppresses instance state-change events to EventBridge, which directly affects monitoring, audit trails, and automated security response that depend on those events. It is monitoring/audit-relevant guidance rather than a fix for a specific vulnerability, so it is security-adjacent documentation (medium) without evidence of a CVE or incident.
Evidence
+Managed resource visibility settings affect the events that Amazon EC2 emits to Amazon EventBridge. When visibility is **Hidden (default)** , Amazon EC2 does not emit `EC2 Instance State-change Notification` events to EventBridge for managed instances.
Diff
diff --git a/AWSEC2/latest/UserGuide/amazon-ec2-managed-instances.md b/AWSEC2/latest/UserGuide/amazon-ec2-managed-instances.md index debffe6e1..2ed25f40c 100644 --- a//AWSEC2/latest/UserGuide/amazon-ec2-managed-instances.md +++ b//AWSEC2/latest/UserGuide/amazon-ec2-managed-instances.md @@ -246,0 +247,8 @@ The same direct-query-by-ID behavior applies to all affected resource types. You +### EventBridge notifications + +Managed resource visibility settings affect the events that Amazon EC2 emits to Amazon EventBridge. When visibility is **Hidden (default)** , Amazon EC2 does not emit `EC2 Instance State-change Notification` events to EventBridge for managed instances. + +To receive these events for managed instances in EventBridge, set visibility to **Visible**. + +For more information about changing this setting, see Configure managed resource visibility. +