Transforming Bedrock Guardrails events into OCSF with CloudWatch
Summary
AWS Bedrock Guardrails can detect and block harmful content, sensitive data leaks, and prompt injection attempts (tricking an AI by hiding instructions in its input), but these security events were previously isolated in separate logs. AWS now allows security teams to transform these guardrail intervention events into OCSF (Open Cybersecurity Schema Framework, a standardized format for security data) and consolidate them in CloudWatch's unified data store, making it possible to correlate AI security incidents with other security telemetry like login failures and network traffic.
Solution / Mitigation
Transform AWS Bedrock Guardrails intervention events into structured OCSF Detection Finding records and land them in the CloudWatch unified data store. The guardrail traces arrive as JSON in AWS Bedrock model invocation logs; the pipeline transforms them to OCSF and ingests them into the unified data store so security teams can query guardrail events alongside identity, network, and endpoint data using AWS Athena or CloudWatch Logs Insights.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/blogs/security/transforming-bedrock-guardrails-events-into-ocsf-with-cloudwatch/
First tracked: September 21, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%