흐름 로그가 비활성화된 AWS Global Accelerator

AWS Global Accelerator의 흐름 로그를 활성화해 연결 정보를 수집하세요.

설명

Global Accelerator 흐름 로그는 가속기를 통과하는 네트워크 트래픽의 연결 정보를 기록합니다. 로그가 없으면 비정상 트래픽과 연결 문제를 분석할 근거가 줄어듭니다.

잠재적 영향

문제가 발생한 연결과 트래픽 패턴을 조사하는 데 시간이 더 걸릴 수 있습니다.

해결 방법

attributes에 flow_logs_enabled = true를 설정하고 S3 버킷과 접두사를 지정하세요. 필요한 로그 전달 권한을 구성하고 로그가 실제로 저장되는지 확인하세요.

예시

변경 후 예시는 흐름 로그를 example-bucket에 저장하도록 설정합니다. 대상 버킷과 필요한 권한은 별도로 준비합니다.

변경 전

hcl
resource "aws_globalaccelerator_accelerator" "example" {
  name            = "Example"
  ip_address_type = "IPV4"
  enabled         = true
}

변경 후

hcl
resource "aws_globalaccelerator_accelerator" "example" {
  name            = "Example"
  ip_address_type = "IPV4"
  enabled         = true

  attributes {
    flow_logs_enabled   = true
    flow_logs_s3_bucket = "example-bucket"
    flow_logs_s3_prefix = "flow-logs/"
  }
}

참조