Description
ALB access logs provide request information for traffic analysis and troubleshooting. NLB S3 access logs cover TLS connections on TLS listeners, so account for that scope.
Potential impact
Without the required logs, investigating traffic and errors at the load balancer is harder.
Remediation
Specify the S3 bucket and prefix in access_logs and set enabled = true. Configure a bucket policy that permits log delivery and verify that logs arrive.
Examples
The examples enable S3 access logging on an ALB. The referenced network resources and bucket policy are defined separately.
Before
hcl
resource "aws_lb" "example" {
name = "test-lb-tf"
internal = false
load_balancer_type = "application"
security_groups = [aws_security_group.lb_sg.id]
subnets = [for subnet in aws_subnet.public : subnet.id]
access_logs {
bucket = aws_s3_bucket.lb_logs.id
prefix = "test-lb"
enabled = false
}
}
After
hcl
resource "aws_lb" "example" {
name = "test-lb-tf"
internal = false
load_balancer_type = "application"
security_groups = [aws_security_group.lb_sg.id]
subnets = [for subnet in aws_subnet.public : subnet.id]
access_logs {
bucket = aws_s3_bucket.lb_logs.id
prefix = "test-lb"
enabled = true
}
}