{"data":{"id":"67594746-c797-4770-b727-9e1bf9997edc","title":"Transforming Bedrock Guardrails events into OCSF with CloudWatch","summary":"AWS Bedrock Guardrails can detect and block harmful content, sensitive data leaks, and prompt injection attempts (tricking an AI by hiding instructions in its input), but these security events were previously isolated in separate logs. AWS now allows security teams to transform these guardrail intervention events into OCSF (Open Cybersecurity Schema Framework, a standardized format for security data) and consolidate them in CloudWatch's unified data store, making it possible to correlate AI security incidents with other security telemetry like login failures and network traffic.","solution":"Transform AWS Bedrock Guardrails intervention events into structured OCSF Detection Finding records and land them in the CloudWatch unified data store. The guardrail traces arrive as JSON in AWS Bedrock model invocation logs; the pipeline transforms them to OCSF and ingests them into the unified data store so security teams can query guardrail events alongside identity, network, and endpoint data using AWS Athena or CloudWatch Logs Insights.","labels":["security"],"sourceUrl":"https://aws.amazon.com/blogs/security/transforming-bedrock-guardrails-events-into-ocsf-with-cloudwatch/","publishedAt":"2026-09-21T15:33:25.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["AWS","AWS Bedrock","AWS Bedrock Guardrails","CloudWatch","AWS CloudTrail","AWS GuardDuty"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-21T15:33:25.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}