Description
With ALB access logging disabled, that feature does not record request paths, response status or processing times.
Potential impact
Information needed to investigate service errors or unusual requests may be missing.
Remediation
Set access_logs.s3.enabled to true and specify a log bucket in the same Region as the ALB. Configure delivery permissions and retention, then verify collection.
Examples
LogBucketName is the name of a prepared S3 log bucket. Define the subnets and security group separately. Logs are provided on a best-effort basis, so do not assume every request is recorded.
Before
yaml
Resources:
LoadBalancer:
Type: AWS::ElasticLoadBalancingV2::LoadBalancer
Properties:
Subnets: !Ref Subnets
SecurityGroups:
- !Ref SecurityGroup
After
yaml
Resources:
LoadBalancer:
Type: AWS::ElasticLoadBalancingV2::LoadBalancer
Properties:
Subnets: !Ref Subnets
SecurityGroups:
- !Ref SecurityGroup
LoadBalancerAttributes:
- Key: access_logs.s3.enabled
Value: 'true'
- Key: access_logs.s3.bucket
Value: !Ref LogBucketName