AWS Global Accelerator flow logs disabled

Enable AWS Global Accelerator flow logs to collect connection information.

Description

Global Accelerator flow logs record connection information for network traffic passing through an accelerator. Without these logs, there is less evidence for investigating abnormal traffic and connectivity problems.

Potential impact

Investigating affected connections and traffic patterns can take longer.

Remediation

Set flow_logs_enabled = true in attributes and specify the S3 bucket and prefix. Configure the required log-delivery permissions and verify that logs are stored.

Examples

The revised example stores flow logs in example-bucket. Prepare the destination bucket and required permissions separately.

Before

hcl
resource "aws_globalaccelerator_accelerator" "example" {
  name            = "Example"
  ip_address_type = "IPV4"
  enabled         = true
}

After

hcl
resource "aws_globalaccelerator_accelerator" "example" {
  name            = "Example"
  ip_address_type = "IPV4"
  enabled         = true

  attributes {
    flow_logs_enabled   = true
    flow_logs_s3_bucket = "example-bucket"
    flow_logs_s3_prefix = "flow-logs/"
  }
}

References