Review access logging for the CloudTrail log bucket

Record access to the bucket that stores CloudTrail logs.

Description

Storing CloudTrail logs does not itself collect the request history of that S3 bucket. Server access logging can help investigate requests to the audit-log repository.

Delivery is best effort, so it does not guarantee an immediate, complete record of every request. Also consider CloudTrail data events for the object operations you need to audit.

Potential impact

  • Insufficient access records make requests to the log bucket harder to investigate.
  • Identifying attempts to read or delete audit logs may take longer.

Remediation

  • Configure server access logging with aws_s3_bucket_logging and verify actual delivery.
  • Grant log-delivery permissions to a separate destination bucket in the same account and Region. Use a bucket policy when ACLs are disabled.
  • Review access permissions, retention, and deletion protection for both buckets.

Examples

These examples use the inline logging and ACL syntax from AWS provider 3.x. Use a separate logging resource and destination bucket policy for current configurations. Supply suitable bucket names and CloudTrail delivery policies, and review whether force_destroy = true meets your audit-log retention requirements.

Before

hcl
resource "aws_cloudtrail" "example" {
  name                          = "tf-trail-foobar"
  s3_bucket_name                = aws_s3_bucket.foo.id
  s3_key_prefix                 = "prefix"
  include_global_service_events = false
}

resource "aws_s3_bucket" "foo" {
  bucket        = "tf-test-trail"
  force_destroy = true
}

After

hcl
resource "aws_cloudtrail" "example" {
  name                          = "tf-trail-foobar"
  s3_bucket_name                = aws_s3_bucket.foo2.id
  s3_key_prefix                 = "prefix"
  include_global_service_events = false
}

resource "aws_s3_bucket" "log_bucket" {
  bucket = "my-tf-log-bucket"
  acl    = "log-delivery-write"
}

resource "aws_s3_bucket" "foo2" {
  bucket = "my-tf-test-bucket"
  acl    = "private"

  logging {
    target_bucket = aws_s3_bucket.log_bucket.id
    target_prefix = "log/"
  }
}

Explanation:

The second example sends server access logs from the CloudTrail storage bucket to a separate bucket. Logging itself does not block requests or prevent log deletion.

References