Amazon MSK adds authorizer log delivery for provisioned clusters
Amazon Managed Streaming for Apache Kafka (MSK) now offers authorizer log delivery for provisioned clusters at no extra cost. This feature provides detailed visibility into client access and authorization issues, enhancing security and troubleshooting capabilities. The logs can be sent to CloudWatch Logs, S3, or Data Firehose and are available for both new and existing clusters across most AWS regions.
- →Enable authorizer log delivery for provisioned MSK clusters
- →Availability and setup for authorizer log delivery
Features (1) ›
- Enable authorizer log delivery for provisioned MSK clusters
Amazon MSK now supports authorizer log delivery for provisioned clusters (Standard and Express) at no additional charge. This provides visibility into user/application access, helps address authorization issues, and captures denied requests with client IP and API details. Logs can be delivered to CloudWatch Logs, S3, or Data Firehose.
Notes (1) ›
- Availability and setup for authorizer log delivery
Authorizer Log Delivery is available for new and existing provisioned MSK clusters and can be enabled via the MSK console or AWS CLI. The feature is supported in all AWS Regions where MSK provisioned clusters are available, excluding the AWS European Sovereign Cloud (eusc-de-east-1) region.
https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-msk-kafka-authorizer-logs/
Related releases
- Amazon S3 enhances access denied errors with specific policy ARNs AWS What's New ·
- AWS Clean Rooms now supports exporting privacy-enhanced analysis logs for SQL queries AWS What's New ·
- AWS Security Blog Details How to Secure S3 Buckets AWS Security Blog ·
- AWS Glue integrates with SageMaker Unified Studio for one-click data access AWS What's New ·
- AWS Backup for S3 adds direct read-only access to backup data AWS What's New ·
- Amazon RDS shows storage volume initialization status AWS What's New ·