Classic ELB access logging disabled

Enable Classic ELB access logs for request analysis.

Description

A Classic ELB receives requests in front of the application. Without access logs, information needed for troubleshooting, traffic analysis, and investigation of abnormal requests is reduced.

Potential impact

Finding the cause of errors or abnormal traffic can take longer.

Remediation

Specify the destination S3 bucket in access_logs and set enabled = true. Configure log-delivery permissions on the bucket and choose a retention period.

Examples

The examples change only whether access logging is enabled. Required listeners and the log bucket policy are omitted.

Before

hcl
resource "aws_elb" "example" {
  name               = "foobar-terraform-elb"
  availability_zones = ["us-west-2a", "us-west-2b", "us-west-2c"]

  access_logs {
    bucket        = "foo"
    bucket_prefix = "bar"
    interval      = 60
    enabled       = false
  }
}

After

hcl
resource "aws_elb" "example" {
  name               = "foobar-terraform-elb"
  availability_zones = ["us-west-2a", "us-west-2b", "us-west-2c"]

  access_logs {
    bucket        = "foo"
    bucket_prefix = "bar"
    interval      = 60
    enabled       = true
  }
}

References