All Products
Search
Document Center

Cloud Config:Use CloudMonitor to trigger alert notifications for non-compliance events

Last Updated:Jul 17, 2026

After you enable non-compliance event delivery in Cloud Config, non-compliance events are automatically sent to CloudMonitor when resources violate rules. You can view these events and set up event-based alert notifications.

Scenarios

In this example, a high-risk rule based on the ecs-instance-deletion-protection-enabled managed rule is created in the Cloud Config console. Cloud Config then audits all Elastic Compute Service (ECS) instances in the current account or across multiple accounts to check whether release protection is enabled. If release protection is disabled on any ECS instance, Cloud Config delivers the non-compliance events to CloudMonitor, where event-based alerting triggers notifications.

Delivery and alerting for the non-compliance events of the current account

Step 1: Enable the non-compliance event delivery feature for the current account

  1. Log on to the Cloud Config console.

  2. In the left-side navigation pane, click Deliveries, and then click the Integrate Service tab.

  3. Turn on the Deliver Non-compliance Events for Current Account switch.

    This switch is in the Non-compliance Events section of the CloudMonitor card on the Integrate Service tab.

Step 2: Create a rule

  1. Log on to the Cloud Config console.

  2. In the left-side navigation pane, choose Compliance Evaluation > Rules.

  3. On the Rules page, click Create Rule.

  4. On the Select Create Method page, select Based on managed rule, search for the ecs-instance-deletion-protection-enabled managed rule, and then click Next.

  5. On the Set Basic Properties page, keep the default settings for the rule name, parameters, risk level, trigger, and description, and then click Next.

  6. On the Set Effective Scope page, keep the default resource type and click Next.

  7. On the Set Correction page, click Submit.

  8. View the compliance check results of the non-compliance events.

    • View the compliance check results of the non-compliance events in the Cloud Config console

      In the left-side navigation pane, choose Compliance & Audit > Rules, and click the name of the target rule to open its details page. On the Evaluation Results tab, you can view a data summary, including the Number of Non-compliant Resources, the total number of audited resources, and the number of compliant resources, as well as a list of the latest evaluation data filtered by compliance status. To modify the rule, click Edit or Re-evaluate in the upper-right corner.

    • View the compliance check results of the non-compliance events in the CloudMonitor console

      In the left-side navigation pane, choose Event Center > System Events. In the filter criteria, select Cloud Config for Product and Non-compliance Event for Event Type. In the search box, enter the rule name, such as ecs-instance-deletion-protection-enabled, click Search. In the Actions column of the event list, click Details to view the non-compliance event details.

Step 3: Configure an alert rule

Create an alert contact to receive notifications by email.

  1. Create an alert contact.

    1. Log on to the Cloud Monitor console.

    2. In the left-side navigation pane, choose Alerts > Alert Contacts.

    3. On the Alert Contacts tab, click Create Alert Contact.

    4. In the Set Alert Contact panel, enter the name and email address of the alert contact.

      Note

      For more information about sending alert notifications through DingTalk, Lark, WeCom, and Slack, see the Create an alert contact section of the "Create an alert contact or alert contact group" topic.

    5. After you confirm the information, complete the slider verification and click OK.

    6. Activate the email address of the alert contact.

      By default, the status of the email address of an alert contact is Pending Activation. The alert contact must click the activation link in the email within 24 hours. Otherwise, the contact cannot receive alert notifications. After activation, you can view the email address of the alert contact in the alert contact list.

  2. Create an alert contact group.

    1. On the Alert Contacts page, click the Alert Contact Group tab.

    2. On the Alert Contact Group tab, click Create Alert Contact Group.

    3. In the Create Alert Contact Group panel, enter a name for the group and select the desired alert contacts.

    4. Click OK.

  3. Create an event subscription policy.

    After Cloud Config delivers non-compliance events to CloudMonitor, create a system event subscription policy to receive alert notifications by email.

    1. In the left-side navigation pane, choose Event Center > Event Subscription.

    2. On the Subscription Policy tab, click Create Subscription Policy.

    3. On the Create Subscription Policy page, configure the parameters for the subscription policy.

      • Basic Information: Enter a name for the subscription policy.

      • Alert Subscription: Set Subscription Type to System Events. Under Subscription Scope, set Products to Cloud Config, Event Type to Notifications, Event Name to Non-compliance Event, and Event Level to Notification (Info). You can enter keywords in the Event Content field to filter events or leave the field empty. Leave Application grouping and Event Resources unconfigured.

        Note
        • For more information about the system events supported by Cloud Config, see the events listed on the CloudConfig page.

        • The Event Content field filters events by keyword. For example, if you enter Critical, the policy matches only Cloud Config rules whose Risk Level is High. You can leave this parameter unconfigured or specify other keywords.

      • Combined Noise Reduction: Keep the default settings.

      • Notifications: When you create the notification configuration, select the alert contact group that you created in Step 2, and use the default value for Custom Notification Method.

        Note
        • For more information about creating a notification configuration, see the Create a notification policy section of the "Manage notification configurations" topic.

        • CloudMonitor automatically sends alert notifications based on the notification methods of the alert contacts in the Alert Contact Group and the alert levels specified in the Custom Notification Method section.

      • Push and Integration: No configuration is required.

    4. Click Submit.

Delivery and alerting for the non-compliance events of multiple accounts

The management account can enable non-compliance event delivery for multiple accounts. Non-compliance events from members in an account group are then delivered to CloudMonitor for event-based alerting.

Prerequisites

Step 1: Enable the non-compliance event delivery feature for multiple accounts

  1. Log on to the Cloud Config console.

  2. In the left-side navigation pane, click Deliveries, and then click the Integrate Service tab.

  3. Turn on the Deliver Non-compliance Events for Multiple Accounts switch.

  4. This switch is in the CloudMonitor section.

Step 2: Create a rule

  1. Log on to the Cloud Config console.

  2. In the upper-left corner, select the target account group, such as Test-fofo, from the account group drop-down list.

  3. In the left-side navigation pane, choose Compliance Evaluation > Rules.

  4. On the Rules page, click Create Rule.

  5. On the Select Create Method page, select Based on managed rule, search for the ecs-instance-deletion-protection-enabled managed rule, and then click Next.

  6. On the Set Basic Properties page, keep the default settings for the rule name, parameters, risk level, trigger, and description, and then click Next.

  7. On the Set Effective Scope page, keep the default resource type and click Next.

  8. On the Set Correction page, click Submit.

  9. View the compliance check results of the non-compliance events.

    • View the compliance check results of the non-compliance events in the Cloud Config console

      In the left-side navigation pane of the Cloud Config console, choose Compliance & Audit > Rules. From the account group drop-down list, select Test-fofo. Click the target rule ecs-instance-deletion-protection-enabled to open its details page. On the Evaluation Results tab, view the data summary. If the Number of Non-compliant Resources is 4 and the total number of audited resources is also 4, this indicates that release protection is disabled for all four ECS instances, and they are therefore evaluated as non-compliant.

    • View the compliance check results of the non-compliance events in the CloudMonitor console

      In the left-side navigation pane, choose Event Center > System Events. In the filter criteria, select Cloud Config for Product and Non-compliance Event for Event Type. In the search box, enter the rule name, such as ecs-instance-deletion-protection-enabled, and click Search. In the Actions column of the event list, click Details to view the non-compliance event details.

Step 3: Configure an alert rule

Create an alert contact to receive notifications by email.

  1. Create an alert contact.

    1. Log on to the Cloud Monitor console.

    2. In the left-side navigation pane, choose Alerts > Alert Contacts.

    3. On the Alert Contacts tab, click Create Alert Contact.

    4. In the Set Alert Contact panel, enter the name and email address of the alert contact.

      Note

      For more information about sending alert notifications through DingTalk, Lark, WeCom, and Slack, see the Create an alert contact section of the "Create an alert contact or alert contact group" topic.

    5. After you confirm the information, complete the slider verification and click OK.

    6. Activate the email address of the alert contact.

      By default, the status of the email address of an alert contact is Pending Activation. The alert contact must click the activation link in the email within 24 hours. Otherwise, the contact cannot receive alert notifications. After activation, you can view the email address of the alert contact in the alert contact list.

  2. Create an alert contact group.

    1. On the Alert Contacts page, click the Alert Contact Group tab.

    2. On the Alert Contact Group tab, click Create Alert Contact Group.

    3. In the Create Alert Contact Group panel, enter a name for the group and select the desired alert contacts.

    4. Click OK.

  3. Create an event subscription policy.

    After Cloud Config delivers non-compliance events to CloudMonitor, create a system event subscription policy to receive alert notifications by email.

    1. In the left-side navigation pane, choose Event Center > Event Subscription.

    2. On the Subscription Policy tab, click Create Subscription Policy.

    3. On the Create Subscription Policy page, configure the parameters for the subscription policy.

      • Basic Information: Enter a name for the subscription policy.

      • Alert Subscription: Set Subscription Type to System Events. Under Subscription Scope, set Products to Cloud Config, Event Type to Notifications, Event Name to Non-compliance Event, and Event Level to Notification (Info). You can enter keywords in the Event Content field to filter events or leave the field empty. Leave Application grouping and Event Resources unconfigured.

        Note
        • For more information about the system events supported by Cloud Config, see the events listed on the CloudConfig page.

        • The Event Content field filters events by keyword. For example, if you enter Critical, the policy matches only Cloud Config rules whose Risk Level is High. You can leave this parameter unconfigured or specify other keywords.

      • Combined Noise Reduction: Keep the default settings.

      • Notifications: When you create the notification configuration, select the alert contact group that you created in Step 2, and use the default settings for Custom Notification Method.

        Note
        • For more information about creating a notification configuration, see the Create a notification policy section of the "Manage notification configurations" topic.

        • CloudMonitor automatically sends alert notifications based on the notification methods of the alert contacts in the Alert Contact Group and the alert levels specified in the Custom Notification Method section.

      • Push and Integration: No configuration is required.

    4. Click Submit.

References