Description
Server access logs for an S3 bucket storing CloudTrail logs help investigate requests to that bucket. Without the required access records, access to log files and operational problems may be harder to investigate afterward.
S3 server access logging is separate from trail event recording and CloudTrail data events. Delivery is best effort and records may be delayed or missing, so do not treat it as a complete record of every request.
Potential impact
- Evidence of access to the bucket holding log files may be unavailable.
- Required retention periods or investigation coverage may not be met.
Remediation
Collect the required server access logs through LoggingConfiguration. For an S3 destination, prepare a separate bucket in the same account and Region with log delivery permissions, then manage access restrictions and retention. Verify delivery and review CloudTrail event coverage separately.
Examples
Only bucket settings are shown. The CloudTrail trail and its bucket policy are not included. Supply the actual destination bucket name through AccessLogBucketName and configure log delivery service permissions separately.
Before
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
VersioningConfiguration:
Status: Enabled
The bucket has no server access log destination. This alone does not mean that the CloudTrail trail has stopped recording events.
After
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
VersioningConfiguration:
Status: Enabled
LoggingConfiguration:
DestinationBucketName: !Ref AccessLogBucketName
LogFilePrefix: loga/
Server access logs are sent to a separate S3 bucket. Versioning does not replace request logging, and delivery may be delayed.