Description
Without query logs for a Route 53 public hosted zone, DNS queries received by Route 53 and their response status can be harder to investigate. These logs do not include every query answered from a resolver’s cache.
The CloudWatch Logs group for public DNS query logs must be in us-east-1. For private DNS queries, consider the separate Route 53 Resolver query logging feature.
Potential impact
- Insufficient records can hinder analysis of suspicious query patterns or DNS errors.
- Inappropriate retention or access permissions can cause loss of records or disclosure of query information.
Remediation
Set QueryLoggingConfig on the public hosted zone to the actual log group ARN in us-east-1. Configure a CloudWatch Logs resource policy allowing Route 53 delivery, set retention and access controls, and verify that actual query records arrive.
Examples
These are public hosted zone excerpts. Replace the domain and log group ARN with actual values, and prepare the log group and delivery permissions separately.
Before
Resources:
HostedZone:
Type: AWS::Route53::HostedZone
Properties:
Name: example.com
This does not configure a public DNS query log destination. Query-count metrics and individual query records are separate.
After
Resources:
HostedZone:
Type: AWS::Route53::HostedZone
Properties:
Name: example.com
QueryLoggingConfig:
CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/route53/example
This configures delivery to a log group in us-east-1. A log group in another Region does not meet this public DNS logging requirement.