ELB access logging disabled

Collect and protect access logs needed to investigate Classic ELB requests.

Description

Without Classic ELB access logs, request flow, errors and client patterns are harder to investigate. Load balancer logs support troubleshooting and security investigations.

Verify both the logging configuration and actual delivery to S3. Logs contain request information, so manage their access permissions and retention as well.

Potential impact

  • Identifying unusual traffic or error patterns and diagnosing incidents may take longer.
  • Missing records can limit operational audits and incident analysis.

Remediation

Set Enabled to true in AccessLoggingPolicy and specify an S3 log bucket in the same Region. Configure a bucket policy permitting log delivery and the supported SSE-S3 encryption. Restrict log access and retention, then verify that actual requests produce records in S3.

Examples

These excerpts compare access logging settings. The HTTPS listener's required SSLCertificateId and networking are omitted. Replace the Availability Zone and bucket name with values for your environment.

Before

yaml
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      AvailabilityZones:
        - us-east-2a
      Listeners:
        - InstancePort: "80"
          LoadBalancerPort: "443"
          Protocol: HTTPS

Access logging is not enabled. Logs from other layers, such as the application, do not fully replace the load balancer's request records.

After

yaml
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      AvailabilityZones:
        - us-east-2a
      Listeners:
        - InstancePort: "80"
          LoadBalancerPort: "443"
          Protocol: HTTPS
      AccessLoggingPolicy:
        Enabled: true
        S3BucketName: my-elb-access-logs

This configures access log delivery to the specified bucket. Prepare its delivery permissions and verify actual records.

References