Review ELBv2 load-balancer access logging

Configure access logging for the load-balancer type and listeners in use.

Description

ALB access logs provide request information for traffic analysis and troubleshooting. NLB S3 access logs cover TLS connections on TLS listeners, so account for that scope.

Potential impact

Without the required logs, investigating traffic and errors at the load balancer is harder.

Remediation

Specify the S3 bucket and prefix in access_logs and set enabled = true. Configure a bucket policy that permits log delivery and verify that logs arrive.

Examples

The examples enable S3 access logging on an ALB. The referenced network resources and bucket policy are defined separately.

Before

hcl
resource "aws_lb" "example" {
  name               = "test-lb-tf"
  internal           = false
  load_balancer_type = "application"
  security_groups    = [aws_security_group.lb_sg.id]
  subnets            = [for subnet in aws_subnet.public : subnet.id]

  access_logs {
    bucket  = aws_s3_bucket.lb_logs.id
    prefix  = "test-lb"
    enabled = false
  }
}

After

hcl
resource "aws_lb" "example" {
  name               = "test-lb-tf"
  internal           = false
  load_balancer_type = "application"
  security_groups    = [aws_security_group.lb_sg.id]
  subnets            = [for subnet in aws_subnet.public : subnet.id]

  access_logs {
    bucket  = aws_s3_bucket.lb_logs.id
    prefix  = "test-lb"
    enabled = true
  }
}

References