AWS AmazonCloudWatch: CloudWatch vended logs doc: reorganized service list and permissions wording
Summary
Rewrote the intro paragraphs pointing users to a searchable catalog and the 'Supported log destinations and permissions' table, replaced the 'Some AWS services use a common infrastructure...' paragraph with clearer wording about V1/V2 permissions models and each label linking to required policies, reordered/added/removed entries in the service list (e.g., added CloudWatch Logs Insights query execution logs, Amazon Quick, AWS Shield Advanced, Route 53 Global Resolver; removed stale Bedrock/SES entries), and renamed the 'Supported log destinations' link/label.
Security assessment
The edit is a documentation reorganization: it rephrases intro text, links to a destinations/permissions table, and reorders the list of services (adding and removing entries). Although it mentions permissions models for log delivery, it documents no new feature, fix, or vulnerability; it only points readers to existing policy references, so no concrete security remediation or new security guidance is introduced.
Evidence
+Some services require additional permissions before they can deliver logs. Without these permissions, log delivery fails. In the comparison table, services that use the original permissions model are labeled **Supported (V1 permissions)**. Services that use the current model are labeled **Supported (V2 permissions)**. Each label links to the required policies.
Diff
diff --git a/AmazonCloudWatch/latest/logs/AWS-logs-and-resource-policy.md b/AmazonCloudWatch/latest/logs/AWS-logs-and-resource-policy.md index 39aafec68..9f452b437 100644 --- a//AmazonCloudWatch/latest/logs/AWS-logs-and-resource-policy.md +++ b//AmazonCloudWatch/latest/logs/AWS-logs-and-resource-policy.md @@ -9 +9 @@ -While many services publish logs only to CloudWatch Logs, some AWS services can publish logs directly to Amazon Simple Storage Service or Amazon Data Firehose. If your main requirement for logs is storage or processing in one of these services, you can easily have the service that produces the logs send them directly to Amazon S3 or Firehose without additional setup. +Use the searchable catalog to find an AWS service and open its logging setup guide. For more information about the destinations and permissions models for each service, see [Supported log destinations and permissions](./AWS-logs-destinations-table.html). @@ -11 +11 @@ While many services publish logs only to CloudWatch Logs, some AWS services can -Even when you publish logs directly to Amazon S3 or Firehose, CloudWatch delivery charges apply. If you send logs to Amazon S3, then ``AWS_REGION`-S3-Egress-Bytes` charges appear in Cost Explorer or on your bill. If you send logs to Firehose, then ``AWS_REGION`-FH-Egress-Bytes` charges appear. For more information about vended logs pricing, see the **Logs** tab at [Amazon CloudWatch Pricing](https://aws.amazon.com/cloudwatch/pricing/). +Many services publish logs only to CloudWatch Logs, but others use vended log delivery to send logs directly to Amazon Simple Storage Service or Amazon Data Firehose. Direct delivery is useful when your main requirement is long-term storage or processing in one of those destinations. @@ -13 +13 @@ Even when you publish logs directly to Amazon S3 or Firehose, CloudWatch deliver -Some AWS services use a common infrastructure to send their logs. To enable logging from these services, you must be logged in as a user that has certain permissions. Additionally, you must grant permissions to AWS to enable the logs to be sent. +Even when you publish logs directly to Amazon S3 or Firehose, CloudWatch delivery charges apply. If you send logs to Amazon S3, then ``AWS_REGION`-S3-Egress-Bytes` charges appear in Cost Explorer or on your bill. If you send logs to Firehose, then ``AWS_REGION`-FH-Egress-Bytes` charges appear. For more information about vended logs pricing, see the **Logs** tab at [Amazon CloudWatch Pricing](https://aws.amazon.com/cloudwatch/pricing/). @@ -15 +15 @@ Some AWS services use a common infrastructure to send their logs. To enable logg -For services that require these permissions, there are two versions of the permissions needed. The services that require these extra permissions are noted as **Supported (V1 permissions)** and **Supported (V2 permissions)** in the [Supported log destinations](./AWS-logs-destinations-table.html). For information about these required permissions, see the sections after the table. +Some services require additional permissions before they can deliver logs. Without these permissions, log delivery fails. In the comparison table, services that use the original permissions model are labeled **Supported (V1 permissions)**. Services that use the current model are labeled **Supported (V2 permissions)**. Each label links to the required policies. @@ -21,3 +20,0 @@ For services that require these permissions, there are two versions of the permi - * [Amazon Bedrock Knowledge Bases](https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-bases-logging.html) - * [Amazon Bedrock Agents](https://docs.aws.amazon.com/bedrock/latest/userguide/model-invocation-logging.html) - * [Amazon Bedrock AgentCore Runtime](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agents-tools-runtime.html) @@ -27,0 +25 @@ For services that require these permissions, there are two versions of the permi + * [Amazon Bedrock AgentCore Runtime](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agents-tools-runtime.html) @@ -28,0 +27,2 @@ For services that require these permissions, there are two versions of the permi + * [Amazon Bedrock Agents](https://docs.aws.amazon.com/bedrock/latest/userguide/model-invocation-logging.html) + * [Amazon Bedrock Knowledge Bases](https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-bases-logging.html) @@ -31,0 +32 @@ For services that require these permissions, there are two versions of the permi + * [AWS CloudTrail](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/monitor-cloudtrail-log-files-with-cloudwatch-logs.html) @@ -34 +35 @@ For services that require these permissions, there are two versions of the permi - * [AWS CloudTrail](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/monitor-cloudtrail-log-files-with-cloudwatch-logs.html) + * [CloudWatch Logs Insights query execution logs](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AWS-vended-logs-permissions-V2.html#vended-logs-insights-query-execution-source) @@ -41,2 +42 @@ For services that require these permissions, there are two versions of the permi - * [Amazon ElastiCache (Redis OSS)](https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/Log_Delivery.html) - * [AWS Elastic Beanstalk](https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/AWSHowTo.cloudwatchlogs.html) + * [EC2 Spot Instance](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-data-feeds.html) @@ -46,0 +47,2 @@ For services that require these permissions, there are two versions of the permi + * [AWS Elastic Beanstalk](https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/AWSHowTo.cloudwatchlogs.html) + * [Amazon ElastiCache (Redis OSS)](https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/Log_Delivery.html) @@ -49,0 +52 @@ For services that require these permissions, there are two versions of the permi + * [Amazon EventBridge Event Buses](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-event-bus-logs.html) @@ -51 +53,0 @@ For services that require these permissions, there are two versions of the permi - * [Amazon EventBridge Event Buses](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-pipes-logs.html) @@ -58 +59,0 @@ For services that require these permissions, there are two versions of the permi - * [Amazon IVS Chat](https://docs.aws.amazon.com/ivs/latest/LowLatencyUserGuide/chat-logging.html) @@ -60,0 +62 @@ For services that require these permissions, there are two versions of the permi + * [Amazon IVS Chat](https://docs.aws.amazon.com/ivs/latest/LowLatencyUserGuide/chat-logging.html) @@ -63 +64,0 @@ For services that require these permissions, there are two versions of the permi - * [Amazon SES](https://docs.aws.amazon.com/ses/latest/dg/eb-logging.html) @@ -65,0 +67 @@ For services that require these permissions, there are two versions of the permi + * [Amazon MQ](https://docs.aws.amazon.com/amazon-mq/latest/developer-guide/configure-logging-monitoring-activemq.html) @@ -68 +69,0 @@ For services that require these permissions, there are two versions of the permi - * [Amazon MQ](https://docs.aws.amazon.com/amazon-mq/latest/developer-guide/configure-logging-monitoring-activemq.html) @@ -72 +72,0 @@ For services that require these permissions, there are two versions of the permi - * [Amazon OpenSearch Service](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/createdomain-configure-slow-logs.html) @@ -73,0 +74 @@ For services that require these permissions, there are two versions of the permi + * [Amazon OpenSearch Service](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/createdomain-configure-slow-logs.html) @@ -77 +78,2 @@ For services that require these permissions, there are two versions of the permi - * [Amazon Quick Chat and Feedback](https://docs.aws.amazon.com/quicksuite/latest/userguide/monitoring-quicksuite-chat-feedback-cloudwatch.html) + * [Amazon Q in Connect AI agents](https://docs.aws.amazon.com/connect/latest/adminguide/monitor-q-assistants-cloudwatch.html) + * [Amazon Quick](https://docs.aws.amazon.com/quick/latest/userguide/monitoring-cloudwatch-logs.html) @@ -79,3 +81 @@ For services that require these permissions, there are two versions of the permi - * [AWS RTB Fabric](https://docs.aws.amazon.com/rtb-fabric/latest/userguide/what-is-rtb-fabric.html) - * [AWS Security Hub CSPM](https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html) - * [AWS Security Hub](https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html) + * [Amazon Route 53 Global Resolver](https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/gr-monitoring.html) @@ -83,0 +84 @@ For services that require these permissions, there are two versions of the permi + * [AWS RTB Fabric](https://docs.aws.amazon.com/rtb-fabric/latest/userguide/what-is-rtb-fabric.html) @@ -87 +88,2 @@ For services that require these permissions, there are two versions of the permi - * [AWS Site-to-Site VPN](https://docs.aws.amazon.com/vpn/latest/s2svpn/monitoring-logs.html) + * [AWS Security Hub](https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html) + * [AWS Security Hub CSPM](https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html) @@ -88,0 +91,2 @@ For services that require these permissions, there are two versions of the permi + * [AWS Shield Advanced](https://docs.aws.amazon.com/waf/latest/developerguide/ddos-flow-logs.html) + * [AWS Site-to-Site VPN](https://docs.aws.amazon.com/vpn/latest/s2svpn/monitoring-logs.html) @@ -91 +94,0 @@ For services that require these permissions, there are two versions of the permi - * [EC2 Spot Instance](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-data-feeds.html) @@ -112 +115 @@ Filter pattern syntax -Supported log destinations +Supported log destinations and permissions