Review CloudFront access logging

Collect CloudFront access logs and verify delivery to retain request history for security analysis and troubleshooting.

Description

CloudFront access logs help analyze incoming requests and the responses returned. Without the required request logs, security analysis and incident investigation may lack supporting evidence.

distributionConfig.logging configures legacy standard logging to S3. Also review other collection paths, such as standard logging v2. Delivery can be delayed or incomplete, so these logs do not guarantee an immediate record of every request.

Potential impact

  • Abnormal requests or attempted attacks may be harder to discover and investigate.
  • Evidence needed to reconstruct failures and operational history may be missing.

Remediation

  • When using legacy standard logging, set distributionConfig.logging.enabled to true and specify the actual log bucket. The destination must have ACLs enabled and grant the required CloudFront log delivery permissions.
  • Decide whether cookie logging is necessary, and restrict log access and retention.
  • Verify actual delivery after test requests, and check collection failures and the analysis and alerting path.

Examples

These partial examples show only legacy logging settings. Replace sample.s3.amazonaws.com with an actual log bucket meeting the delivery requirements.

Before

yaml
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
  forProvider:
    distributionConfig:
      enabled: true
      logging:
        enabled: false
        bucket: sample.s3.amazonaws.com

This legacy log delivery configuration is disabled. Check whether another path collects the required logs.

After

yaml
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
  forProvider:
    distributionConfig:
      enabled: true
      logging:
        enabled: true
        bucket: sample.s3.amazonaws.com

Legacy standard logging is enabled. Complete the configuration by checking bucket permissions and actual log arrival.

References