Review CloudFront request logging

Collect CloudFront request logs to investigate failures and abnormal traffic.

Description

Without CloudFront request logs, there is less evidence for analyzing viewer requests and edge responses. Configure logging to collect the request information you need.

Potential impact

Finding the cause of abnormal traffic or cache problems can take longer.

Remediation

Configure the destination and permissions for your chosen log-delivery method. Use logging_config for legacy S3 standard logging, and verify actual delivery and retention.

Examples

The examples show a partial distribution configuration that adds legacy S3 standard logging. Other required settings, including cache behavior and certificates, are omitted.

Before

hcl
resource "aws_cloudfront_distribution" "example" {
  origin {
    domain_name = aws_s3_bucket.b.bucket_regional_domain_name
    origin_id   = local.s3_origin_id

    s3_origin_config {
      origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
    }
  }

  enabled             = true
  is_ipv6_enabled     = true
  comment             = "Some comment"
  default_root_object = "index.html"
}

After

hcl
resource "aws_cloudfront_distribution" "example" {
  origin {
    domain_name = aws_s3_bucket.b.bucket_regional_domain_name
    origin_id   = local.s3_origin_id

    s3_origin_config {
      origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
    }
  }

  enabled             = true
  is_ipv6_enabled     = true
  comment             = "Some comment"
  default_root_object = "index.html"

  logging_config {
    include_cookies = false
    bucket          = "mylogs.s3.amazonaws.com"
    prefix          = "myprefix"
  }
}

References