CloudFront request logging is not configured

Collect CloudFront request logs and verify delivery.

Description

Without CloudFront request logs, records needed to investigate request paths, response status and traffic patterns for a distribution may be missing.

Potential impact

It can be harder to identify the causes of unusual requests or service errors.

Remediation

Configure request logging suited to operational needs, destination permissions and retention. Verify that logs are actually delivered.

Examples

The examples use legacy standard logging through DistributionConfig.Logging. Configure ACLs and required delivery permissions on the log bucket. Standard logging v2 uses a separate configuration.

Before

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Enabled: true
        Origins:
          - DomainName: mybucket.s3.amazonaws.com
            Id: myS3Origin
            S3OriginConfig:
              OriginAccessIdentity: origin-access-identity/cloudfront/E127EXAMPLE51Z

After

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Enabled: true
        Origins:
          - DomainName: mybucket.s3.amazonaws.com
            Id: myS3Origin
            S3OriginConfig:
              OriginAccessIdentity: origin-access-identity/cloudfront/E127EXAMPLE51Z
        Logging:
          Bucket: mylogs.s3.amazonaws.com
          Prefix: cloudfront/
          IncludeCookies: false

References