Tencent Cloud CLB access logging is not configured

Collect access logs for supported CLB listeners.

Description

CLB access logs help investigate Layer 7 HTTP and HTTPS requests. Without a log destination, request flow and errors may be difficult to investigate later.

Potential impact

Outage or anomalous-traffic investigations may lack records of request times and processing results.

Remediation

Prepare a Cloud Log Service log set and topic, then associate them through the CLB’s log_set_id and log_topic_id. Set retention and verify that actual requests produce logs.

Examples

These excerpts add a log destination. The Layer 7 listener and referenced VPC and subnet configurations are omitted. This access-log feature does not cover Layer 4 traffic.

Before

hcl
resource "tencentcloud_clb_instance" "internal_clb" {
  network_type                 = "INTERNAL"
  clb_name                     = "clb_example"
  project_id                   = 0
  vpc_id                       = tencentcloud_vpc.vpc_test.id
  subnet_id                    = tencentcloud_subnet.subnet_test.id
  load_balancer_pass_to_target = true
}

After

hcl
resource "tencentcloud_clb_log_set" "set" {
  period = 7
}

resource "tencentcloud_clb_log_topic" "topic" {
  log_set_id = tencentcloud_clb_log_set.set.id
  topic_name = "clb-topic"
}

resource "tencentcloud_clb_instance" "internal_clb" {
  network_type                 = "INTERNAL"
  clb_name                     = "clb_example"
  project_id                   = 0
  vpc_id                       = tencentcloud_vpc.vpc_test.id
  subnet_id                    = tencentcloud_subnet.subnet_test.id
  load_balancer_pass_to_target = true
  log_set_id                   = tencentcloud_clb_log_set.set.id
  log_topic_id                 = tencentcloud_clb_log_topic.topic.id
}

References