AWS Instance action in Audit Log
I have a new feature request. Currently, Sophos Central can have AWS tied into it to grab information relating to instances that are registered within the Dashboard. It brings in Instance ID, start date, etc. and its able to track that information through the life of the server being registered within Sophos Central.
The Audit log contains the actions taken in Sophos Central with users and systems. We noticed that there is one action that is not currently being tracked, and that is when an AWS instance is terminated. There is no record, in the Audit Log, of the system being terminated. So the server goes from being online and registered, to deleted without any recording in the Audit Log.
We'd like to have it so that there is a delete or terminate record, in the Audit Log, when an instance is removed from AWS. This would better understand how AWS and Sophos Central are interacting, but also leave a trail of what is happening to a specific instance within the Dashboard.