Description
Without Classic ELB access logs, request flow, errors and client patterns are harder to investigate. Load balancer logs support troubleshooting and security investigations.
Verify both the logging configuration and actual delivery to S3. Logs contain request information, so manage their access permissions and retention as well.
Potential impact
- Identifying unusual traffic or error patterns and diagnosing incidents may take longer.
- Missing records can limit operational audits and incident analysis.
Remediation
Set Enabled to true in AccessLoggingPolicy and specify an S3 log bucket in the same Region. Configure a bucket policy permitting log delivery and the supported SSE-S3 encryption. Restrict log access and retention, then verify that actual requests produce records in S3.
Examples
These excerpts compare access logging settings. The HTTPS listener's required SSLCertificateId and networking are omitted. Replace the Availability Zone and bucket name with values for your environment.
Before
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
AvailabilityZones:
- us-east-2a
Listeners:
- InstancePort: "80"
LoadBalancerPort: "443"
Protocol: HTTPS
Access logging is not enabled. Logs from other layers, such as the application, do not fully replace the load balancer's request records.
After
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
AvailabilityZones:
- us-east-2a
Listeners:
- InstancePort: "80"
LoadBalancerPort: "443"
Protocol: HTTPS
AccessLoggingPolicy:
Enabled: true
S3BucketName: my-elb-access-logs
This configures access log delivery to the specified bucket. Prepare its delivery permissions and verify actual records.