SageMaker real-time endpoints that capture no inference requests or responses
What does ZopNight detect here?
ZopNight flags an Amazon SageMaker endpoint whose `DataCaptureConfig` is explicitly disabled, so none of its inference inputs or outputs are written to S3. Without captured traffic there is nothing to audit a prediction against and nothing for drift monitoring to compare. The check stays silent when the setting is unknown, and the finding has a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1622 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | EnableCapture = false |
| Source | ZopNight |
| Permissions used | sagemaker:ListEndpoints · sagemaker:DescribeEndpoint |
Where it applies
What a model endpoint forgets without data capture
A SageMaker real-time endpoint returns a prediction and moves on. Unless data capture is turned on in the endpoint configuration, the request payload and the model’s answer are not kept anywhere you control. That matters in three situations: when a customer disputes a decision the model made, when a regulator asks how a model behaved on a given day, and when accuracy degrades slowly because live traffic no longer looks like the training data.
Captured records land in an S3 prefix you choose. SageMaker Model Monitor can read them to compare live traffic with a baseline, although AWS states Model Monitor is no longer open to new customers and will get no new features; the captured data is useful to any analysis tool either way.
Checking an endpoint’s capture setting
aws sagemaker list-endpoints --query 'Endpoints[].EndpointName' --output text
aws sagemaker describe-endpoint --endpoint-name my-endpoint \ --query 'DataCaptureConfig'The block reports EnableCapture, a CaptureStatus of Started or Stopped, the current sampling
percentage and the S3 destination. An empty result or "EnableCapture": false means nothing is
recorded.
The evidence behind a finding
ZopNight records the data capture setting for each endpoint it discovers and flags an InService
endpoint only when that setting is confirmed off. This is purely a configuration check; it does not look at traffic
volume or metrics.
Endpoints left out
If the setting could not be read or parsed, the endpoint is not flagged, and endpoints in any status
other than InService are not evaluated. The rule does not judge the
sampling percentage either, so an endpoint capturing 1% of requests passes. AWS also notes that data
capture pauses on its own when disk usage on the instance runs high, which this configuration check
cannot see.
Cost and value of turning capture on
The finding reports $0. Capture itself adds S3 storage and request charges for the objects it writes, which scale with sampling rate and payload size. A modest sampling percentage and an S3 lifecycle rule usually keep that small.
Enabling capture on a live endpoint
Endpoint configurations cannot be edited, so the change is a new configuration plus an update:
- Create a configuration that copies the current production variants and adds capture:
aws sagemaker create-endpoint-config --endpoint-config-name my-endpoint-cfg-v2 \ --production-variants file://variants.json \ --data-capture-config '{"EnableCapture":true,"InitialSamplingPercentage":20,"DestinationS3Uri":"s3://my-capture-bucket/my-endpoint","CaptureOptions":[{"CaptureMode":"Input"},{"CaptureMode":"Output"}]}'- Switch the endpoint to it with
aws sagemaker update-endpoint --endpoint-name my-endpoint --endpoint-config-name my-endpoint-cfg-v2. - Encrypt and restrict the capture bucket, since it now holds real inference payloads.