Description
S3 server access logs help investigate requests to a bucket and their response status. Without retained request records, unusual access or operational errors may be harder to analyze.
Server access logs are delivered on a best-effort basis, and some records may be delayed or missing. They do not replace access controls or provide a complete audit of every request.
Potential impact
- Evidence needed to investigate requests or errors may be missing.
- Poor log access and retention controls may expose request information.
Remediation
Collect the required access logs through LoggingConfiguration. For an S3 destination, prepare a separate bucket in the same account and Region and grant log delivery permissions. Restrict log access and retention, then verify collection after sending requests, allowing for delivery delays.
Examples
AccessLogBucketName is the actual destination bucket name. Prepare the bucket and log delivery service permissions separately. Versioning and access logging serve different purposes.
Before
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
VersioningConfiguration:
Status: Enabled
No server access log destination is configured. Also check whether another audit mechanism captures the required records.
After
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
VersioningConfiguration:
Status: Enabled
LoggingConfiguration:
DestinationBucketName: !Ref AccessLogBucketName
LogFilePrefix: loga/
Server access logs are stored in a separate S3 bucket. This does not guarantee immediate recording of every request.