Description
CloudFront access logs record details such as request paths, response status and processing time. Without suitable request logs, unusual traffic and errors at the CDN layer can be harder to investigate. Logging does not itself block attacks.
Potential impact
- Unusual requests and high-volume access patterns may be discovered late.
- Incident investigations and troubleshooting may lack the necessary request history.
Remediation
- Configure standard or real-time logging for the distribution. For the S3 delivery method below, set
logging.enabled: true, a log bucket and a prefix. - Configure delivery permissions, access restrictions and retention for the chosen logging method, and confirm that logs arrive.
- Standard logs are delivered on a best-effort basis; do not assume they account for every request.
Examples
These excerpts compare logging settings; required cache behavior and other settings are omitted. Both retain enabled: false, so the distribution is not enabled to serve content.
Before
- name: create a CloudFront distribution
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: my test origin-000111
domain_name: www.example.com
enabled: false
This configuration has no log delivery settings. Also check any logging configured separately for the deployed distribution.
After
- name: create a CloudFront distribution
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: my test origin-000111
domain_name: www.example.com
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
enabled: false
This enables S3 log delivery. Substitute the actual bucket and prefix and provide the permissions required by that logging method.