Description
Without CloudFront request logs, records needed to investigate request paths, response status and traffic patterns for a distribution may be missing.
Potential impact
It can be harder to identify the causes of unusual requests or service errors.
Remediation
Configure request logging suited to operational needs, destination permissions and retention. Verify that logs are actually delivered.
Examples
The examples use legacy standard logging through DistributionConfig.Logging. Configure ACLs and required delivery permissions on the log bucket. Standard logging v2 uses a separate configuration.
Before
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: true
Origins:
- DomainName: mybucket.s3.amazonaws.com
Id: myS3Origin
S3OriginConfig:
OriginAccessIdentity: origin-access-identity/cloudfront/E127EXAMPLE51Z
After
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: true
Origins:
- DomainName: mybucket.s3.amazonaws.com
Id: myS3Origin
S3OriginConfig:
OriginAccessIdentity: origin-access-identity/cloudfront/E127EXAMPLE51Z
Logging:
Bucket: mylogs.s3.amazonaws.com
Prefix: cloudfront/
IncludeCookies: false