Amazon CloudWatch Logs now supports two subscription filters per log group, enabling you to deliver a real-time feed of log events from CloudWatch Logs to an Amazon Kinesis Data Stream, Amazon Kinesis Data Firehose, or AWS Lambda for custom processing, analysis, or delivery to other systems.
Amazon S3 Object Ownership is available to enable bucket owners to automatically assume ownership of objects uploaded to their buckets
Amazon S3 Object Ownership is a new S3 feature that enables bucket owners to automatically assume ownership of objects that are uploaded to their buckets by other AWS Accounts. This helps you to standardize ownership of new objects in your bucket, and to share and manage access to these objects at scale via resource-based policies such as a bucket policy or an access point policy. Whether your S3 bucket receives data from other AWS accounts, or stores output from AWS services like AWS CloudTrail, S3 Object Ownership simplifies the work of creating and maintaining shared data sets on Amazon S3.
AWS Security Hub achieves FedRAMP Moderate authorization
AWS Security Hub is now authorized as FedRAMP Moderate in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (N. California), and US West (Oregon). The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that delivers a standard approach to the security assessment, authorization, and continuous monitoring for cloud products and services. FedRAMP uses the National Institute of Standards and Technology (NIST) Special Publication 800 series and requires cloud service providers to receive an independent security assessment conducted by a third-party assessment organization (3PAO) to ensure that authorizations are compliant with the Federal Information Security Management Act (FISMA). We are also now approved as Department of Defense Cloud Computing Security Requirements Guide Impact Level 2 (DoD SRG IL-2 ) in those regions.
Simplify data management in Amazon Personalize with new APIs
Amazon Personalize enables you to personalize your website, app, ads, emails, and more, using the same machine learning technology as used by Amazon.com, without requiring any prior machine learning experience. Using Amazon Personalize, you can generate personalized recommendations for your users through a simple API interface. Amazon Personalize now makes it easier to manage your growing item and user catalogs with new APIs for incrementally adding items and users in the datasets that you use in Personalize to create personalized recommendations.
AWS Config adds 15 new sample conformance pack templates and introduces simplified setup experience for conformance packs
AWS Config now offers 15 additional sample conformance pack templates that can help you verify your cloud infrastructure’s compliance with one or more frameworks for configuration best practices. With conformance packs, you can package a collection of AWS Config rules and remediation actions that can be deployed together as a single entity across an entire organization. This is particularly useful if you need to quickly establish a common baseline for resource configuration policies and best practices across multiple accounts in your organization in a scalable and efficient way.
Amazon MSK launches new education classes and labs
Amazon Managed Streaming for Apache Kafka (MSK) launches a new master class and AWS Labs to get you started using the service and hone your skills with best practices. The new Amazon MSK Master Class, created by Stephane Maarek, AWS Hero, gives you six hours of hands-on learning in the most comprehensive content available for Amazon MSK. New AWS Labs take you through getting started, a use case example of ingesting and analyzing real-time clickstream data, and best practices for migrating your self-managed Apache Kafka cluster to Amazon MSK. By completing the class and labs, you will learn how to apply your knowledge to your own use cases.
AWS Lake Formation now supports Active Directory and SAML providers for Amazon Athena
AWS Lake Formation now supports Active Directory and Security Assertion Markup Language (SAML) identity providers such as OKTA and Auth0 for Amazon Athena . You can now easily manage data access for Amazon Athena users with fine grained privileges using existing identity management tools.
Increased availability for AWS Certification exam online proctoring
You can now take all AWS Certification exams from home or any private space with online proctoring when you schedule with either test delivery provider, Pearson VUE or PSI. Online proctoring is available anywhere AWS Certification offers testing. For candidates in mainland China and South Korea, online proctored exams are available only via PSI.
Now author AWS Systems Manager Automation runbooks using Visual Studio Code
AWS Systems Manager now enables developers to view, author, and publish Automation runbooks directly from Visual Studio Code, a free code editor built on open source. You can now use the editor to author runbooks faster and be more productive by starting with pre-built templates, auto-completing the code with snippets, and validating the runbook for syntax errors in real time. Once built, you can publish the runbooks from the editor to the cloud with a single click.
AWS Snowball is now available in the AWS Europe (Milan) Region
The AWS Snowball service is now available in the AWS Europe (Milan) Region. AWS Snowball, a part of the AWS Snow Family, is an edge computing, data migration, and edge storage device that comes in two options. Snowball Edge Storage Optimized devices provide 80 TB of Amazon S3 object storage and optional compute with 40 vCPUs. They are well suited for local storage and large-scale data transfer. Snowball Edge Compute Optimized devices provide 52 vCPUs, 7.68 TB of NVMe SSD storage, 42 TB of HDD storage, 256 GB of RAM, and an optional GPU for use cases like advanced machine learning and full motion video analysis in disconnected environments. You can use these devices for data collection, machine learning and processing, and storage in environments with intermittent connectivity (like manufacturing, industrial, and transportation) or in extremely remote locations (like military or maritime operations) before shipping the devices back to AWS. These devices may also be rack mounted and clustered together to build larger temporary installations.