Logging and monitoring in AWS Directory Service
As a best practice, monitor your organization to ensure that changes are logged. This helps you to ensure that any unexpected change can be investigated and unwanted changes can be rolled back. AWS Directory Service currently supports the following two AWS services so that you can monitor your organization and the activity that happens within it.
Amazon CloudWatch - You can use CloudWatch Events with the AWS Managed Microsoft AD directory type. For more information, see Enable Amazon CloudWatch Logs log forwarding for AWS Managed Microsoft AD. Additionally, you can use CloudWatch Metrics to monitor domain controller performance. For more information, see Determine when to add domain controllers with CloudWatch metrics.
AWS CloudTrail - You can use CloudTrail with all AWS Directory Service directory types. For more information, see Logging AWS Directory Service API calls with CloudTrail.