Bedrock Provisioned Throughput in a Region where model invocation logging is off
What does ZopNight detect here?
ZopNight reads the Amazon Bedrock model invocation logging configuration once per Region with `bedrock:GetModelInvocationLoggingConfiguration` and flags every Provisioned Throughput in a Region where logging is disabled. Logging is off by default in Bedrock, so without it no prompt, response or metadata record exists for audit or abuse review. The finding carries no dollar saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1609 |
| Category | governance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | invocation logging disabled |
| Source | ZopNight |
| Permissions used | bedrock:GetModelInvocationLoggingConfiguration · bedrock:ListProvisionedModelThroughputs |
Without invocation logging there is no record of what the model was asked
Model invocation logging
collects the full request data, response data and metadata for Bedrock calls in your account in a
Region. AWS states it is disabled by default. Until someone turns it on, InvokeModel,
InvokeModelWithResponseStream, Converse and ConverseStream calls leave no record of their
content.
That gap matters most where traffic is heaviest, which is why ZopNight anchors the finding on Provisioned Throughput: a model you pay to keep provisioned is almost always serving a production application. Security teams cannot investigate prompt injection or misuse after the fact, and engineering teams cannot study which prompts drive cost.
Checking the setting in each Region
aws bedrock get-model-invocation-logging-configuration --region us-east-1
aws bedrock list-provisioned-model-throughputs --region us-east-1 \ --query 'provisionedModelSummaries[].[provisionedModelName,status]'An empty response, or a loggingConfig with neither cloudWatchConfig nor s3Config, means
logging is off for that Region. Repeat for every Region where you hold Provisioned Throughput.
The one condition behind the finding
The logging configuration is an account-and-Region setting, not a per-model one. ZopNight makes a single configuration call per Region and applies the answer to every Provisioned Throughput it discovers there. If logging is disabled, each of those Provisioned Throughputs gets a finding naming it, so the Region’s most important model endpoints are where the gap shows up.
When no finding is raised
If ZopNight cannot read the logging configuration for a Region, for example because the role lacks the permission or the call fails, it assumes nothing and stays silent. A Region with logging enabled to either destination produces no finding. Regions with only on-demand model use and no Provisioned Throughput are not covered by this check.
A governance gap, not a saving
The finding has no savings figure. Enabling logging adds cost rather than removing it: CloudWatch Logs or S3 storage for the records, which can be large for long prompts. The value is the audit trail. AWS stores logs until the logging configuration is deleted, so set retention on the destination.
Turning logging on
- Create the destination in the same account and Region: a CloudWatch Logs log group plus an IAM role Bedrock can assume, or an S3 bucket with the bucket policy AWS documents.
- Enable it:
aws bedrock put-model-invocation-logging-configuration --logging-config '{"cloudWatchConfig":{"logGroupName":"/bedrock/invocations","roleArn":"arn:aws:iam::111122223333:role/BedrockLogging"},"textDataDeliveryEnabled":true}' - Set a retention period on the log group or a lifecycle rule on the bucket.
- Send a test request and confirm a record arrives.