ALB access logging is disabled

Store ALB access logs in S3 to support request investigations.

Description

With ALB access logging disabled, that feature does not record request paths, response status or processing times.

Potential impact

Information needed to investigate service errors or unusual requests may be missing.

Remediation

Set access_logs.s3.enabled to true and specify a log bucket in the same Region as the ALB. Configure delivery permissions and retention, then verify collection.

Examples

LogBucketName is the name of a prepared S3 log bucket. Define the subnets and security group separately. Logs are provided on a best-effort basis, so do not assume every request is recorded.

Before

yaml
Resources:
  LoadBalancer:
    Type: AWS::ElasticLoadBalancingV2::LoadBalancer
    Properties:
      Subnets: !Ref Subnets
      SecurityGroups:
        - !Ref SecurityGroup

After

yaml
Resources:
  LoadBalancer:
    Type: AWS::ElasticLoadBalancingV2::LoadBalancer
    Properties:
      Subnets: !Ref Subnets
      SecurityGroups:
        - !Ref SecurityGroup
      LoadBalancerAttributes:
        - Key: access_logs.s3.enabled
          Value: 'true'
        - Key: access_logs.s3.bucket
          Value: !Ref LogBucketName

References