Description
Storing CloudTrail logs does not itself collect the request history of that S3 bucket. Server access logging can help investigate requests to the audit-log repository.
Delivery is best effort, so it does not guarantee an immediate, complete record of every request. Also consider CloudTrail data events for the object operations you need to audit.
Potential impact
- Insufficient access records make requests to the log bucket harder to investigate.
- Identifying attempts to read or delete audit logs may take longer.
Remediation
- Configure server access logging with
aws_s3_bucket_loggingand verify actual delivery. - Grant log-delivery permissions to a separate destination bucket in the same account and Region. Use a bucket policy when ACLs are disabled.
- Review access permissions, retention, and deletion protection for both buckets.
Examples
These examples use the inline logging and ACL syntax from AWS provider 3.x. Use a separate logging resource and destination bucket policy for current configurations. Supply suitable bucket names and CloudTrail delivery policies, and review whether force_destroy = true meets your audit-log retention requirements.
Before
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.foo.id
s3_key_prefix = "prefix"
include_global_service_events = false
}
resource "aws_s3_bucket" "foo" {
bucket = "tf-test-trail"
force_destroy = true
}
After
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.foo2.id
s3_key_prefix = "prefix"
include_global_service_events = false
}
resource "aws_s3_bucket" "log_bucket" {
bucket = "my-tf-log-bucket"
acl = "log-delivery-write"
}
resource "aws_s3_bucket" "foo2" {
bucket = "my-tf-test-bucket"
acl = "private"
logging {
target_bucket = aws_s3_bucket.log_bucket.id
target_prefix = "log/"
}
}
Explanation:
The second example sends server access logs from the CloudTrail storage bucket to a separate bucket. Logging itself does not block requests or prevent log deletion.