Transforming Bedrock Guardrails events into OCSF with CloudWatch
Brief
Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparable to a failed sign-in or a network intrusion alert.
AWS Bedrock publishes this telemetry to AWS CloudWatch metrics and model invocation logs for operational monitoring.
In this post, I show you how to transform AWS Bedrock Guardrails intervention events into structured Open Cybersecurity Schema Framework (OCSF) Detection Finding records and land them in the CloudWatch unified data store . Launched in December 2025 , the unified data store consolidates operational, security, and compliance data from AWS services and third-party sources into a single platform.
