Description
CloudFront access logs help analyze incoming requests and the responses returned. Without the required request logs, security analysis and incident investigation may lack supporting evidence.
distributionConfig.logging configures legacy standard logging to S3. Also review other collection paths, such as standard logging v2. Delivery can be delayed or incomplete, so these logs do not guarantee an immediate record of every request.
Potential impact
- Abnormal requests or attempted attacks may be harder to discover and investigate.
- Evidence needed to reconstruct failures and operational history may be missing.
Remediation
- When using legacy standard logging, set
distributionConfig.logging.enabledtotrueand specify the actual log bucket. The destination must have ACLs enabled and grant the required CloudFront log delivery permissions. - Decide whether cookie logging is necessary, and restrict log access and retention.
- Verify actual delivery after test requests, and check collection failures and the analysis and alerting path.
Examples
These partial examples show only legacy logging settings. Replace sample.s3.amazonaws.com with an actual log bucket meeting the delivery requirements.
Before
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
forProvider:
distributionConfig:
enabled: true
logging:
enabled: false
bucket: sample.s3.amazonaws.com
This legacy log delivery configuration is disabled. Check whether another path collects the required logs.
After
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
forProvider:
distributionConfig:
enabled: true
logging:
enabled: true
bucket: sample.s3.amazonaws.com
Legacy standard logging is enabled. Complete the configuration by checking bucket permissions and actual log arrival.