CloudWatch Logs destination policy grants excessive access

Allow only the senders and actions needed for log subscriptions.

Description

Unnecessary wildcard actions or unrestricted principals in a CloudWatch Logs destination policy can broaden who can attach log subscriptions. Check effective policy conditions as well.

Potential impact

Unapproved senders may introduce unwanted data or increase processing costs by attaching log streams.

Remediation

Limit access to the required sender accounts or organization, and allow logs:PutSubscriptionFilter only for the intended destination ARN.

Examples

The examples define an IAM policy document for destination access. It must be attached to the destination to take effect; granting destination access does not itself grant permission to read stored logs.

Before

hcl
data "aws_iam_policy_document" "example" {
  statement {
    effect = "Allow"

    principals {
      type = "AWS"
      identifiers = [data.aws_caller_identity.current.id]
    }

    actions = [
      "logs:*",
    ]

    resources = [
      aws_cloudwatch_log_destination.test_destination.arn,
    ]
  }
}

After

hcl
data "aws_iam_policy_document" "example" {
  statement {
    effect = "Allow"

    principals {
      type = "AWS"
      identifiers = [
        "123456789012",
      ]
    }

    actions = [
      "logs:PutSubscriptionFilter",
    ]

    resources = [
      aws_cloudwatch_log_destination.test_destination.arn,
    ]
  }
}

References