Description
Server access logging collects request information for S3 buckets and objects to support operational analysis and security investigations. Obtain the access records you need for buckets containing sensitive data, backups, or application assets.
Delivery is best effort. It does not guarantee immediate logging of every request or a complete audit history; also consider CloudTrail data events for the object operations you need to audit.
Potential impact
- Missing access records make bucket request history harder to investigate.
- Investigating deletion, downloads, or unusual access may take longer.
Remediation
- Configure server access logging with
aws_s3_bucket_loggingand verify delivery. - Use a separate destination bucket in the same account and Region, and manage delivery permissions and retention.
- Use a bucket policy to permit delivery when destination ACLs are disabled, and restrict read and delete access to sensitive logs.
Examples
These examples use the inline logging and versioning syntax from AWS provider 3.x. Supply the destination logs bucket and delivery permissions separately. mfa_delete = true reflects existing AWS state; this code alone does not enable MFA Delete. Use a separate logging resource for current configurations.
Before
resource "aws_s3_bucket" "example" {
bucket = "my-tf-test-bucket"
acl = "private"
tags = {
Name = "My bucket"
Environment = "Dev"
}
versioning {
mfa_delete = true
}
}
After
resource "aws_s3_bucket" "example" {
bucket = "my-tf-test-bucket"
acl = "private"
tags = {
Name = "My bucket"
Environment = "Dev"
}
logging {
target_bucket = "logs"
}
versioning {
mfa_delete = true
}
}
Explanation:
The second example configures delivery of server access logs to the destination bucket. Verify actual receipt and confirm that the collected records meet your audit needs.