Description
Global Accelerator flow logs record connection information for network traffic passing through an accelerator. Without these logs, there is less evidence for investigating abnormal traffic and connectivity problems.
Potential impact
Investigating affected connections and traffic patterns can take longer.
Remediation
Set flow_logs_enabled = true in attributes and specify the S3 bucket and prefix. Configure the required log-delivery permissions and verify that logs are stored.
Examples
The revised example stores flow logs in example-bucket. Prepare the destination bucket and required permissions separately.
Before
hcl
resource "aws_globalaccelerator_accelerator" "example" {
name = "Example"
ip_address_type = "IPV4"
enabled = true
}
After
hcl
resource "aws_globalaccelerator_accelerator" "example" {
name = "Example"
ip_address_type = "IPV4"
enabled = true
attributes {
flow_logs_enabled = true
flow_logs_s3_bucket = "example-bucket"
flow_logs_s3_prefix = "flow-logs/"
}
}