Description
Unnecessary wildcard actions or unrestricted principals in a CloudWatch Logs destination policy can broaden who can attach log subscriptions. Check effective policy conditions as well.
Potential impact
Unapproved senders may introduce unwanted data or increase processing costs by attaching log streams.
Remediation
Limit access to the required sender accounts or organization, and allow logs:PutSubscriptionFilter only for the intended destination ARN.
Examples
The examples define an IAM policy document for destination access. It must be attached to the destination to take effect; granting destination access does not itself grant permission to read stored logs.
Before
hcl
data "aws_iam_policy_document" "example" {
statement {
effect = "Allow"
principals {
type = "AWS"
identifiers = [data.aws_caller_identity.current.id]
}
actions = [
"logs:*",
]
resources = [
aws_cloudwatch_log_destination.test_destination.arn,
]
}
}
After
hcl
data "aws_iam_policy_document" "example" {
statement {
effect = "Allow"
principals {
type = "AWS"
identifiers = [
"123456789012",
]
}
actions = [
"logs:PutSubscriptionFilter",
]
resources = [
aws_cloudwatch_log_destination.test_destination.arn,
]
}
}