Skip to main content
governance · aws

Bedrock Provisioned Throughput in a Region where model invocation logging is off

rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight reads the Amazon Bedrock model invocation logging configuration once per Region with `bedrock:GetModelInvocationLoggingConfiguration` and flags every Provisioned Throughput in a Region where logging is disabled. Logging is off by default in Bedrock, so without it no prompt, response or metadata record exists for audit or abuse review. The finding carries no dollar saving.

Signal and threshold

How ZopNight evaluates Bedrock Provisioned Throughput in a Region where model invocation logging is off.
Field Value
Rule IDsRC-1609
Categorygovernance
Severitylow
Metricnone — pure configuration read
Thresholdinvocation logging disabled
SourceZopNight
Permissions usedbedrock:GetModelInvocationLoggingConfiguration · bedrock:ListProvisionedModelThroughputs

Without invocation logging there is no record of what the model was asked

Model invocation logging collects the full request data, response data and metadata for Bedrock calls in your account in a Region. AWS states it is disabled by default. Until someone turns it on, InvokeModel, InvokeModelWithResponseStream, Converse and ConverseStream calls leave no record of their content.

That gap matters most where traffic is heaviest, which is why ZopNight anchors the finding on Provisioned Throughput: a model you pay to keep provisioned is almost always serving a production application. Security teams cannot investigate prompt injection or misuse after the fact, and engineering teams cannot study which prompts drive cost.

Checking the setting in each Region

Terminal window
aws bedrock get-model-invocation-logging-configuration --region us-east-1
aws bedrock list-provisioned-model-throughputs --region us-east-1 \
--query 'provisionedModelSummaries[].[provisionedModelName,status]'

An empty response, or a loggingConfig with neither cloudWatchConfig nor s3Config, means logging is off for that Region. Repeat for every Region where you hold Provisioned Throughput.

The one condition behind the finding

The logging configuration is an account-and-Region setting, not a per-model one. ZopNight makes a single configuration call per Region and applies the answer to every Provisioned Throughput it discovers there. If logging is disabled, each of those Provisioned Throughputs gets a finding naming it, so the Region’s most important model endpoints are where the gap shows up.

When no finding is raised

If ZopNight cannot read the logging configuration for a Region, for example because the role lacks the permission or the call fails, it assumes nothing and stays silent. A Region with logging enabled to either destination produces no finding. Regions with only on-demand model use and no Provisioned Throughput are not covered by this check.

A governance gap, not a saving

The finding has no savings figure. Enabling logging adds cost rather than removing it: CloudWatch Logs or S3 storage for the records, which can be large for long prompts. The value is the audit trail. AWS stores logs until the logging configuration is deleted, so set retention on the destination.

Turning logging on

  1. Create the destination in the same account and Region: a CloudWatch Logs log group plus an IAM role Bedrock can assume, or an S3 bucket with the bucket policy AWS documents.
  2. Enable it: aws bedrock put-model-invocation-logging-configuration --logging-config '{"cloudWatchConfig":{"logGroupName":"/bedrock/invocations","roleArn":"arn:aws:iam::111122223333:role/BedrockLogging"},"textDataDeliveryEnabled":true}'
  3. Set a retention period on the log group or a lifecycle rule on the bucket.
  4. Send a test request and confirm a record arrives.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·