Publicado el Deja un comentario

Amazon OpenSearch Service introduces agentic AI for log analytics

Amazon OpenSearch Service now offers agentic AI capabilities that enable engineering and support teams to analyze log data through an agentic conversational interface. These agentic AI features help simplify log querying and accelerate incident investigations by allowing teams to interact with data using natural language, plan and initiate autonomous root cause analysis, and persist conversation as they navigate through their Observability workspace in OpenSearch UI.

This launch introduces three key capabilities available at no additional cost (token-based usage limits apply). Agentic chat enables you to ask questions in natural language to analyze data, generate and iterate Piped Processing Language (PPL) queries in Discover, and analyze visualizations for insights. When deeper root cause analysis is needed, you can trigger the investigation agent to autonomously and iteratively plan for the investigation, execute queries, reflect on results, and then deliver structured root cause hypotheses ranked by likelihood with full transparency into its reasoning. With agent memory, you can seamlessly continue your conversation across different feature pages or in a new web session.

You can use the agentic AI features in the following AWS Regions: Asia Pacific (Tokyo), Asia Pacific (Sydney), Europe (Frankfurt), Europe (Stockholm), Europe (Spain), Europe (Ireland), US East (N. Virginia), US East (Ohio), and US West (Oregon).

To learn more, see Agentic AI in Amazon OpenSearch Service. For more information about Amazon OpenSearch Service, see the Amazon OpenSearch Service product page.

 

​Amazon OpenSearch Service now offers agentic AI capabilities that enable engineering and support teams to analyze log data through an agentic conversational interface. These agentic AI features help simplify log querying and accelerate incident investigations by allowing teams to interact with data using natural language, plan and initiate autonomous root cause analysis, and persist conversation as they navigate through their Observability workspace in OpenSearch UI. This launch introduces three key capabilities available at no additional cost (token-based usage limits apply). Agentic chat enables you to ask questions in natural language to analyze data, generate and iterate Piped Processing Language (PPL) queries in Discover, and analyze visualizations for insights. When deeper root cause analysis is needed, you can trigger the investigation agent to autonomously and iteratively plan for the investigation, execute queries, reflect on results, and then deliver structured root cause hypotheses ranked by likelihood with full transparency into its reasoning. With agent memory, you can seamlessly continue your conversation across different feature pages or in a new web session. You can use the agentic AI features in the following AWS Regions: Asia Pacific (Tokyo), Asia Pacific (Sydney), Europe (Frankfurt), Europe (Stockholm), Europe (Spain), Europe (Ireland), US East (N. Virginia), US East (Ohio), and US West (Oregon). To learn more, see Agentic AI in Amazon OpenSearch Service. For more information about Amazon OpenSearch Service, see the Amazon OpenSearch Service product page.  

Publicado el Deja un comentario

Amazon CloudWatch now supports ingesting Security Hub CSPM findings with organization-wide enablement

Amazon CloudWatch now supports ingesting AWS Security Hub CSPM findings, enabling customers to centrally analyze and monitor security findings directly in CloudWatch Logs. Security Hub CSPM findings are supported in AWS Security Finding Format (ASFF) and Open Cybersecurity Schema Framework (OCSF) format using CloudWatch Pipelines, providing standardized security data ingestion. Customers can now use CloudWatch Logs Insights to query findings, create metric filters for monitoring, and leverage Amazon S3 Tables integration for advanced analytics, helping security teams identify and respond to threats faster across their AWS environment.

With today’s launch, customers can automatically enable Security Hub findings delivery to CloudWatch Logs using CloudWatch enablement rules that apply to the entire organization or specific accounts, to standardize security monitoring coverage. For example, a security team can create an enablement rule to automatically send Security Hub findings to CloudWatch Logs for all production accounts, ensuring consistent visibility into security posture.

Security Hub findings to CloudWatch logs are available in all AWS commercial regions.

Security Hub findings are charged as tiered pricing when delivered to CloudWatch Logs. For pricing information, see the CloudWatch pricing page. To learn more about Security Hub findings in CloudWatch Logs and organization-level enablement, visit the Amazon CloudWatch documentation..

 

​Amazon CloudWatch now supports ingesting AWS Security Hub CSPM findings, enabling customers to centrally analyze and monitor security findings directly in CloudWatch Logs. Security Hub CSPM findings are supported in AWS Security Finding Format (ASFF) and Open Cybersecurity Schema Framework (OCSF) format using CloudWatch Pipelines, providing standardized security data ingestion. Customers can now use CloudWatch Logs Insights to query findings, create metric filters for monitoring, and leverage Amazon S3 Tables integration for advanced analytics, helping security teams identify and respond to threats faster across their AWS environment.
With today’s launch, customers can automatically enable Security Hub findings delivery to CloudWatch Logs using CloudWatch enablement rules that apply to the entire organization or specific accounts, to standardize security monitoring coverage. For example, a security team can create an enablement rule to automatically send Security Hub findings to CloudWatch Logs for all production accounts, ensuring consistent visibility into security posture.
Security Hub findings to CloudWatch logs are available in all AWS commercial regions.
Security Hub findings are charged as tiered pricing when delivered to CloudWatch Logs. For pricing information, see the CloudWatch pricing page. To learn more about Security Hub findings in CloudWatch Logs and organization-level enablement, visit the Amazon CloudWatch documentation..  

Publicado el Deja un comentario

AWS IAM Identity Center is now available in AWS European Sovereign Cloud (Germany) Region

You can now deploy AWS IAM Identity Center in the AWS European Sovereign Cloud (Germany) Region. The AWS European Sovereign Cloud is a new independent cloud for Europe entirely located within the European Union (EU), designed to help customers meet their evolving sovereignty requirements.

IAM Identity Center is the recommended service for managing workforce access to AWS applications. It enables you to connect your existing source of workforce identities once and to offer your users a single sign-on experience across the AWS European Sovereign Cloud. It powers the personalized experiences provided by AWS applications, and the ability to define and audit user-aware access to data in AWS services. It can also help you manage access to multiple AWS accounts from a central place. IAM Identity Center is available at no additional cost.

To learn more about IAM Identity Center, visit the product detail page. To get started, see the IAM Identity Center user guide.

 

​You can now deploy AWS IAM Identity Center in the AWS European Sovereign Cloud (Germany) Region. The AWS European Sovereign Cloud is a new independent cloud for Europe entirely located within the European Union (EU), designed to help customers meet their evolving sovereignty requirements.
IAM Identity Center is the recommended service for managing workforce access to AWS applications. It enables you to connect your existing source of workforce identities once and to offer your users a single sign-on experience across the AWS European Sovereign Cloud. It powers the personalized experiences provided by AWS applications, and the ability to define and audit user-aware access to data in AWS services. It can also help you manage access to multiple AWS accounts from a central place. IAM Identity Center is available at no additional cost.
To learn more about IAM Identity Center, visit the product detail page. To get started, see the IAM Identity Center user guide.  

Publicado el Deja un comentario

Amazon SageMaker Unified Studio adds Observability for AWS Glue jobs via CloudWatch metrics

Amazon SageMaker Unified Studio adds Observability for jobs, it now displays Amazon CloudWatch metrics for AWS Glue jobs directly alongside job logs in a single, unified interface. This enhancement adds observability to SageMaker Unified Studio, enabling data engineers and ETL developers to streamline their troubleshooting processes.

With this feature, teams can diagnose performance issues faster by correlating resource utilization patterns—including DPU utilization, memory consumption, CPU load, and data movement size—directly with job log output. Specific use cases include identifying compute bottlenecks, detecting memory pressure or out-of-memory conditions, optimizing resource allocation, and monitoring data pipeline performance at scale. By consolidating metrics and logs into one workspace, organizations can significantly reduce mean time to resolution (MTTR) for ETL pipeline issues and improve overall operational efficiency.

This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is generally available. To access CloudWatch metrics, navigate to any Glue job in SageMaker Unified Studio, open a previous job run, and select the Metrics tab to view comprehensive performance data.

To learn more about Amazon SageMaker Unified Studio and this new capability, visit the SageMaker Unified Studio page and see the documentation.

 

​Amazon SageMaker Unified Studio adds Observability for jobs, it now displays Amazon CloudWatch metrics for AWS Glue jobs directly alongside job logs in a single, unified interface. This enhancement adds observability to SageMaker Unified Studio, enabling data engineers and ETL developers to streamline their troubleshooting processes.
With this feature, teams can diagnose performance issues faster by correlating resource utilization patterns—including DPU utilization, memory consumption, CPU load, and data movement size—directly with job log output. Specific use cases include identifying compute bottlenecks, detecting memory pressure or out-of-memory conditions, optimizing resource allocation, and monitoring data pipeline performance at scale. By consolidating metrics and logs into one workspace, organizations can significantly reduce mean time to resolution (MTTR) for ETL pipeline issues and improve overall operational efficiency.
This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is generally available. To access CloudWatch metrics, navigate to any Glue job in SageMaker Unified Studio, open a previous job run, and select the Metrics tab to view comprehensive performance data.
To learn more about Amazon SageMaker Unified Studio and this new capability, visit the SageMaker Unified Studio page and see the documentation.  

Publicado el Deja un comentario

AWS Organizations now provides organization paths in API responses

AWS Organizations now returns the complete organizational path for accounts and organizational units (OUs) directly in API responses, eliminating the need for multiple API calls to traverse organizational hierarchies. Previously, understanding where accounts and organizational units (OUs) are positioned within your organization structure required multiple API calls. This enhancement is particularly valuable for enterprise customers managing large, complex AWS Organizations with deeply nested OU structures.

With this launch, APIs including DescribeAccount, ListAccounts, DescribeOrganizationalUnit, and others now include the full path from organization to root to the target entity (e.g., o-{orgId}/r-{rootId}/ou-{ouId}/{accountId}) in a single call. This eliminates time-consuming multiple API calls for org path determination and reduces operational overhead when analyzing service control policy impacts, assessing permissions boundaries, or evaluating account movements across complex organizational hierarchies. Cloud architects, security teams, and operations teams can now troubleshoot faster and build more effective automation, including large language model (LLM) powered tools that require complete organizational context for accurate guidance.

The organization path is now available in all commercial AWS Regions and the AWS GovCloud (US) Regions.

To learn more, visit the To learn more, visit the AWS Organizations API documentation.

 

​AWS Organizations now returns the complete organizational path for accounts and organizational units (OUs) directly in API responses, eliminating the need for multiple API calls to traverse organizational hierarchies. Previously, understanding where accounts and organizational units (OUs) are positioned within your organization structure required multiple API calls. This enhancement is particularly valuable for enterprise customers managing large, complex AWS Organizations with deeply nested OU structures.
With this launch, APIs including DescribeAccount, ListAccounts, DescribeOrganizationalUnit, and others now include the full path from organization to root to the target entity (e.g., o-{orgId}/r-{rootId}/ou-{ouId}/{accountId}) in a single call. This eliminates time-consuming multiple API calls for org path determination and reduces operational overhead when analyzing service control policy impacts, assessing permissions boundaries, or evaluating account movements across complex organizational hierarchies. Cloud architects, security teams, and operations teams can now troubleshoot faster and build more effective automation, including large language model (LLM) powered tools that require complete organizational context for accurate guidance.
The organization path is now available in all commercial AWS Regions and the AWS GovCloud (US) Regions.
To learn more, visit the To learn more, visit the AWS Organizations API documentation.  

Publicado el Deja un comentario

AWS launches Sustainability console for carbon emissions tracking

AWS launches the AWS Sustainability console, a free, standalone service that shows customers their environmental impact associated with their AWS usage. Expanding on the features from the Customer Carbon Footprint Tool (CCFT) in the AWS Billing console, this new service addresses a critical access barrier by enabling sustainability professionals to view carbon emissions data without requiring billing permissions. Organizations can now ensure the right teams have access to the environmental data.

Like the CCFT, the AWS Sustainability console provides customers their estimated carbon emissions from using AWS, calculated using both market-based (MBM) and location-based (LBM) methods and available by AWS Region, service, and emissions scope (1, 2, 3). The console also delivers additional capabilities including improved customizable visualizations, the ability to set which month your fiscal year starts, customizable CSV reports, and API/SDK access for seamless integration of emissions data into existing reporting workflows.

The AWS Sustainability service is now available in the US East (N. Virginia) region and provides carbon emissions data for all AWS commercial regions. Access the service globally through the AWS Management Console.

 

​AWS launches the AWS Sustainability console, a free, standalone service that shows customers their environmental impact associated with their AWS usage. Expanding on the features from the Customer Carbon Footprint Tool (CCFT) in the AWS Billing console, this new service addresses a critical access barrier by enabling sustainability professionals to view carbon emissions data without requiring billing permissions. Organizations can now ensure the right teams have access to the environmental data. Like the CCFT, the AWS Sustainability console provides customers their estimated carbon emissions from using AWS, calculated using both market-based (MBM) and location-based (LBM) methods and available by AWS Region, service, and emissions scope (1, 2, 3). The console also delivers additional capabilities including improved customizable visualizations, the ability to set which month your fiscal year starts, customizable CSV reports, and API/SDK access for seamless integration of emissions data into existing reporting workflows.
The AWS Sustainability service is now available in the US East (N. Virginia) region and provides carbon emissions data for all AWS commercial regions. Access the service globally through the AWS Management Console.  

Publicado el Deja un comentario

Amazon Managed Service for Apache Flink now supports Apache Flink 2.2

Amazon Managed Service for Apache Flink now supports Apache Flink version 2.2. This is a major upgrade that brings runtime improvements such as Java 17 support, RocksDB 8.10.0 for better I/O performance, and serialization enhancements. Additionally, Dataset API and Scala APIs are now deprecated. You can create a new application on Apache Flink 2.2 or use in-place version upgrades to adopt the Flink 2.2 runtime for a simpler and faster upgrade to compatible applications.

Amazon Managed Service for Apache Flink makes it easier to transform and analyze streaming data in real time across various use cases, including real-time analytics, anomaly detection, and complex event processing. Amazon Managed Service for Apache Flink simplifies the setup, operation, and scaling of Apache Flink applications, allowing developers and data engineers to focus on building and running their streaming applications without managing the underlying infrastructure.

Apache Flink 2.2 is available across AWS regions where Amazon Managed Service for Apache Flink is offered. You can learn more about Apache Flink 2.2 in Amazon Managed Service for Apache Flink in our documentation

 

​Amazon Managed Service for Apache Flink now supports Apache Flink version 2.2. This is a major upgrade that brings runtime improvements such as Java 17 support, RocksDB 8.10.0 for better I/O performance, and serialization enhancements. Additionally, Dataset API and Scala APIs are now deprecated. You can create a new application on Apache Flink 2.2 or use in-place version upgrades to adopt the Flink 2.2 runtime for a simpler and faster upgrade to compatible applications. Amazon Managed Service for Apache Flink makes it easier to transform and analyze streaming data in real time across various use cases, including real-time analytics, anomaly detection, and complex event processing. Amazon Managed Service for Apache Flink simplifies the setup, operation, and scaling of Apache Flink applications, allowing developers and data engineers to focus on building and running their streaming applications without managing the underlying infrastructure. Apache Flink 2.2 is available across AWS regions where Amazon Managed Service for Apache Flink is offered. You can learn more about Apache Flink 2.2 in Amazon Managed Service for Apache Flink in our documentation.   

Publicado el Deja un comentario

AWS Marketplace sellers can now self-serve refunds and agreement cancellations

AWS Marketplace now offers sellers a streamlined self-service process for refunds and agreement cancellations, reducing the time and effort required to process these requests. This new capability eliminates the need to file support tickets, and gives both sellers and buyers full visibility into the latest status of each request. Buyers can now review and approve cancellation requests directly from the AWS Marketplace console, and see refunds reflected on their charge summary for easier reconciliation. Additionally, Know Your Customer (KYC) verification is now only triggered for invoices that require compliance validation, so sellers can process refunds for KYC-exempt invoices without unnecessary verification delays.

With this launch, sellers can request refunds or cancellations from the Agreements page in the seller portal or programmatically through the AWS Marketplace Agreement APIs. These requests are pre-populated with agreement and invoice data and processed automatically. Sellers can then track every request from submission through completion. Billing adjustments are processed automatically without requiring buyer approval, allowing sellers to refund charges on paid invoices or reduce outstanding balances on unpaid invoices. For agreement cancellations, sellers submit a request and share an approval link directly with the buyer, who has seven days to respond before the cancellation proceeds automatically. All parties receive email and Amazon EventBridge notifications for every status change, enabling integration with their operational workflows. For Channel Partner Private Offer agreements, the channel partner initiates the refund or cancellation request, and the Independent Software Vendor (ISV) receives notifications for visibility.

Seller self-service refunds and agreement cancellations are available in all commercial AWS Regions where AWS Marketplace is supported.

To learn more, see Refunds and cancellations in the AWS Marketplace Seller Guide. For information about responding to seller-initiated cancellation requests and tracking refunds, see Refunds and cancellations in the AWS Marketplace Buyer Guide.

 

​AWS Marketplace now offers sellers a streamlined self-service process for refunds and agreement cancellations, reducing the time and effort required to process these requests. This new capability eliminates the need to file support tickets, and gives both sellers and buyers full visibility into the latest status of each request. Buyers can now review and approve cancellation requests directly from the AWS Marketplace console, and see refunds reflected on their charge summary for easier reconciliation. Additionally, Know Your Customer (KYC) verification is now only triggered for invoices that require compliance validation, so sellers can process refunds for KYC-exempt invoices without unnecessary verification delays. With this launch, sellers can request refunds or cancellations from the Agreements page in the seller portal or programmatically through the AWS Marketplace Agreement APIs. These requests are pre-populated with agreement and invoice data and processed automatically. Sellers can then track every request from submission through completion. Billing adjustments are processed automatically without requiring buyer approval, allowing sellers to refund charges on paid invoices or reduce outstanding balances on unpaid invoices. For agreement cancellations, sellers submit a request and share an approval link directly with the buyer, who has seven days to respond before the cancellation proceeds automatically. All parties receive email and Amazon EventBridge notifications for every status change, enabling integration with their operational workflows. For Channel Partner Private Offer agreements, the channel partner initiates the refund or cancellation request, and the Independent Software Vendor (ISV) receives notifications for visibility. Seller self-service refunds and agreement cancellations are available in all commercial AWS Regions where AWS Marketplace is supported. To learn more, see Refunds and cancellations in the AWS Marketplace Seller Guide. For information about responding to seller-initiated cancellation requests and tracking refunds, see Refunds and cancellations in the AWS Marketplace Buyer Guide.  

Publicado el Deja un comentario

Amazon S3 Vectors expands to 17 additional AWS Regions

Amazon S3 Vectors is now available in 17 additional AWS Regions: Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (New Zealand), Asia Pacific (Osaka), Asia Pacific (Taipei), Asia Pacific (Thailand), Canada West (Calgary), Europe (Milan), Europe (Spain), Europe (Zurich), Mexico (Central), South America (Sao Paulo), and US West (N. California).

Amazon S3 Vectors is the first cloud object storage with native support for storing and querying vectors. It delivers purpose-built, cost-optimized vector storage for AI agents, inference, Retrieval Augmented Generation (RAG), and semantic search at billion-vector scale. S3 Vectors is designed to provide the same elasticity, durability, and availability as Amazon S3. With a dedicated set of APIs, you can store and query up to two billion vectors per vector index and elastically scale to 10,000 vector indexes per vector bucket without provisioning any infrastructure. Infrequent queries return results in under one second, with frequent queries resulting in latencies as low as 100 milliseconds. S3 Vectors is natively integrated with Amazon Bedrock Knowledge Bases so you can reduce the cost of using large vector datasets for RAG.

With this expansion, S3 Vectors is now available in 31 AWS Regions. For pricing details, visit the S3 pricing page. To learn more, visit the product page and documentation.

 

​Amazon S3 Vectors is now available in 17 additional AWS Regions: Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (New Zealand), Asia Pacific (Osaka), Asia Pacific (Taipei), Asia Pacific (Thailand), Canada West (Calgary), Europe (Milan), Europe (Spain), Europe (Zurich), Mexico (Central), South America (Sao Paulo), and US West (N. California).
Amazon S3 Vectors is the first cloud object storage with native support for storing and querying vectors. It delivers purpose-built, cost-optimized vector storage for AI agents, inference, Retrieval Augmented Generation (RAG), and semantic search at billion-vector scale. S3 Vectors is designed to provide the same elasticity, durability, and availability as Amazon S3. With a dedicated set of APIs, you can store and query up to two billion vectors per vector index and elastically scale to 10,000 vector indexes per vector bucket without provisioning any infrastructure. Infrequent queries return results in under one second, with frequent queries resulting in latencies as low as 100 milliseconds. S3 Vectors is natively integrated with Amazon Bedrock Knowledge Bases so you can reduce the cost of using large vector datasets for RAG.
With this expansion, S3 Vectors is now available in 31 AWS Regions. For pricing details, visit the S3 pricing page. To learn more, visit the product page and documentation.  

Publicado el Deja un comentario

AWS announces End User Messaging Notify

Businesses want to send one-time passcodes (OTPs) because they are often the easiest and fastest way for customers to verify who they are. However, businesses are often surprised when it takes weeks or months to get phone numbers, complete carrier registrations, and set up sender IDs. Today, AWS announces AWS End User Messaging Notify to change all of this. Within minutes, a developer can use phone numbers and sender IDs owned by AWS to power their OTP use case and start sending right away.

With Notify, you set up a configuration with your brand name, turn on SMS, voice, or both, and begin sending OTP messages to over 200 countries using ready-to-use templates. You can customize your brand name, code format, and how long a code stays valid. Every API call includes built-in SMS fraud protection through AWS End User Messaging SMS Protect at no extra cost, catching and blocking suspicious traffic before messages incur costs. Spend limits give you another layer of protection by pausing delivery if your account hits its set threshold.

AWS End User Messaging Notify is available in all AWS Regions where AWS End User Messaging is available.

To get started, visit the AWS End User Notify user guide.

 

 

​Businesses want to send one-time passcodes (OTPs) because they are often the easiest and fastest way for customers to verify who they are. However, businesses are often surprised when it takes weeks or months to get phone numbers, complete carrier registrations, and set up sender IDs. Today, AWS announces AWS End User Messaging Notify to change all of this. Within minutes, a developer can use phone numbers and sender IDs owned by AWS to power their OTP use case and start sending right away.
With Notify, you set up a configuration with your brand name, turn on SMS, voice, or both, and begin sending OTP messages to over 200 countries using ready-to-use templates. You can customize your brand name, code format, and how long a code stays valid. Every API call includes built-in SMS fraud protection through AWS End User Messaging SMS Protect at no extra cost, catching and blocking suspicious traffic before messages incur costs. Spend limits give you another layer of protection by pausing delivery if your account hits its set threshold.
AWS End User Messaging Notify is available in all AWS Regions where AWS End User Messaging is available.
To get started, visit the AWS End User Notify user guide.