AWS clean-rooms: Clean Rooms: expand query/job log field docs and add review guidance
Summary
Clarifies analysis log fields and their recipients (e.g., the ARN of the additional analyses resource and who receives machineLearningInputChannelArn), notes that members with intermediate tables do not receive analysis logs, and adds a new 'Recommended actions for query and job logs' section advising members to periodically review queries, jobs, and configured table columns against the agreed collaboration use cases.
Security assessment
The change improves audit/monitoring transparency for Clean Rooms analysis logs (who receives which log fields) and adds a recommendation to periodically review queries, jobs, and configured columns for compliance with collaboration agreements, which is logging/audit hardening guidance rather than remediation of a specific incident or CVE.
Evidence
+## Recommended actions for query and job logs
Diff
diff --git a/clean-rooms/latest/userguide/query-logs.md b/clean-rooms/latest/userguide/query-logs.md index d4383e202..7e303819e 100644 --- a//clean-rooms/latest/userguide/query-logs.md +++ b//clean-rooms/latest/userguide/query-logs.md @@ -7 +7 @@ -Delivery, recipients, and log groups +Delivery, recipients, and log groupsRecommended actions for query and job logs @@ -19 +19,3 @@ When **Analysis logging** is turned on, AWS Clean Rooms generates logs at two st -Analysis log fields Field | Delivered when | Description +The following table describes the fields included in analysis logs. + +Field | Delivered when | Description @@ -21 +23 @@ Analysis log fields Field | Delivered when | Description -`eventId` | Always delivered | The unique identifier for the analysis run. For queries, this is the same as the protectedQueryID. For jobs, this is the same as the protectedJobID. +`eventId` | Always delivered | The unique identifier for the analysis run. For queries, this is the same as the `protectedQueryID`. For jobs, this is the same as the `protectedJobID`. @@ -48 +50 @@ Analysis log fields Field | Delivered when | Description -`additionalAnalyses` | Synthetic data is created | Additional analyses configured for the collaboration. +`additionalAnalyses` | Synthetic data is created | The ARN of the additional analyses resource permitted for the synthetic-data analysis. Delivered to members whose configured table is referenced in the query, not to the member who created the ML input channel. @@ -52 +54 @@ Analysis log fields Field | Delivered when | Description -`machineLearningInputChannelArn` | Synthetic data is created | The ARN of the machine learning input channel. +`machineLearningInputChannelArn` | Synthetic data is created | The ARN of the machine learning input channel used to generate the synthetic data. Delivered to the member who created the ML input channel and to members whose configured tables are referenced. @@ -71 +73,3 @@ If a member has multiple configured table associations referenced in the analysi -Logs are created for queries that contain unsupported and supported SQL in AWS Clean Rooms. For more details, see the [AWS Clean Rooms SQL Reference](https://docs.aws.amazon.com/clean-rooms/latest/sql-reference/sql-reference.html). +Members with tables used to create an intermediate table don't receive analysis logs when analyses are run on the intermediate table. + +AWS Clean Rooms creates logs for queries that contain unsupported and supported SQL. For more details, see the [AWS Clean Rooms SQL Reference](https://docs.aws.amazon.com/clean-rooms/latest/sql-reference/sql-reference.html). @@ -73 +77 @@ Logs are created for queries that contain unsupported and supported SQL in AWS C -Logs are also created when queries or jobs reference configured tables that are not associated with the collaboration. +AWS Clean Rooms also creates logs when queries or jobs reference configured tables that are not associated with the collaboration. @@ -81 +85 @@ Query and job logs indicate the status of a query but don't report whether query -A log isn't produced if the query was canceled after AWS Clean Rooms validated its compliance with analysis rules and during query processing. +AWS Clean Rooms doesn't produce a log if the query was canceled after AWS Clean Rooms validated its compliance with analysis rules and during query processing. @@ -88,0 +93,17 @@ For more information about Amazon CloudWatch Logs, see the [Amazon CloudWatch Lo +## Recommended actions for query and job logs + +We recommend that members periodically take the following actions: + + * To verify that the queries and jobs match the use cases or queries that were agreed upon for the collaboration, review the queries and jobs that are run in the collaboration. + +For more information about how to view recent queries, see [Viewing recent queries](https://docs.aws.amazon.com/clean-rooms/latest/userguide/query-data.html#view-queries-console). + +For more information about how to view recent jobs, see [Viewing recent jobs](./view-recent-jobs.html). + + * To verify that the configured table columns match what was agreed upon for the collaboration, review the configured table columns that are used in collaboration members' analysis rules and in queries. + +For more information about how to view the configured columns, see [Viewing tables and analysis rules](https://docs.aws.amazon.com/clean-rooms/latest/userguide/manage-configured-tables.html#view-tables). + + + +