Ensure that audit logging is enabled for DocumentDB clusters.
Audit logging in Amazon DocumentDB provides visibility into authentication events, queries, and data changes. It helps detect unauthorized access, supports troubleshooting, and meets compliance requirements. Logs should be sent to CloudWatch or a SIEM for centralized monitoring and alerting.
Modify DocumentDB cluster and enable audit logging feature.