AWS AmazonCloudWatch: CloudWatch Logs V2 S3 delivery: encryption, bucket policy, key format docs
Summary
Restructures the V2 S3 delivery doc, clarifies that SSE-KMS requires a customer managed key (AWS managed keys produce unreadable logs), corrects example account IDs, adds an Amazon S3 object key format section, and adds guidance to keep aws:SourceAccount/aws:SourceArn conditions and grant only the required prefix in the bucket policy.
Security assessment
The change documents security-relevant configuration: SSE-KMS with customer managed keys for log confidentiality, and bucket policy hardening via aws:SourceAccount/aws:SourceArn conditions plus least-privilege prefix scoping to prevent cross-account or overly broad write access. It is best-practice guidance rather than a fix for a specific vulnerability, so it is documentation, not an incident response.
Evidence
Changing the destination prefix, suffix path, or Hive-compatible setting affects new objects only. Existing objects are not moved. The bucket policy must allow `s3:PutObject` for the resulting prefix. When you manage the bucket policy, keep the `aws:SourceAccount` and `aws:SourceArn` conditions shown in the Amazon S3 bucket policy in Amazon S3 bucket resource policy, and grant access only to the required prefix.
Diff
diff --git a/AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-S3.md b/AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-S3.md index d21ecb79f..d9477c9d0 100644 --- a//AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-S3.md +++ b//AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-S3.md @@ -7 +7 @@ -Amazon S3 bucket server-side encryption +User permissionsAmazon S3 bucket resource policyAmazon S3 bucket server-side encryptionAmazon S3 object key format @@ -11 +11,3 @@ Amazon S3 bucket server-side encryption -**User permissions** +For an AWS CLI example, see [Create a delivery to Amazon S3](./AWS-vended-logs-permissions-V2.html#vended-logs-same-account-example-s3). + +## User permissions @@ -72,0 +75,2 @@ JSON +## Amazon S3 bucket resource policy + @@ -122 +126 @@ In some cases, you may see `AccessDenied` errors in AWS CloudTrail if the `s3:Li -You can protect the data in your Amazon S3 bucket by enabling either server-side Encryption with Amazon S3-managed keys (SSE-S3) or server-side encryption with a AWS KMS key stored in AWS Key Management Service (SSE-KMS). For more information, see [ Protecting data using server-side encryption](https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html). +You can protect the data in your Amazon S3 bucket by enabling server-side encryption. You can use Amazon S3-managed keys (SSE-S3) or a AWS KMS key stored in AWS Key Management Service (SSE-KMS). For more information, see [ Protecting data using server-side encryption](https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html). @@ -126,3 +130 @@ If you choose SSE-S3, no additional configuration is required. Amazon S3 handles -###### Warning - -If you choose SSE-KMS, you must use a customer managed key, because using an AWS managed key is not supported for this scenario. If you set up encryption using an AWS managed key, the logs will be delivered in an unreadable format. +###### Customer managed key required @@ -130 +132 @@ If you choose SSE-KMS, you must use a customer managed key, because using an AWS -When you use a customer managed AWS KMS key, you can specify the Amazon Resource Name (ARN) of the customer managed key when you enable bucket encryption. You must add the following to the key policy for your customer managed key (not to the bucket policy for your S3 bucket), so that the log delivery account can write to your S3 bucket. +If you choose SSE-KMS, you must use a customer managed key. You can't use an AWS managed key. If you configure encryption with an AWS managed key, CloudWatch Logs delivers the logs in an unreadable format. @@ -132 +134 @@ When you use a customer managed AWS KMS key, you can specify the Amazon Resource -If you choose SSE-KMS, you must use a customer managed key, because using an AWS managed key is not supported for this scenario. When you use a customer managed AWS KMS key, you can specify the Amazon Resource Name (ARN) of the customer managed key when you enable bucket encryption. You must add the following to the key policy for your customer managed key (not to the bucket policy for your S3 bucket), so that the log delivery account can write to your S3 bucket. +For SSE-KMS, specify the Amazon Resource Name (ARN) of the key when you enable bucket encryption. Add the following to the key policy (not to the bucket policy for your S3 bucket), so that the log delivery account can write to your S3 bucket. @@ -151 +153 @@ If you choose SSE-KMS, you must use a customer managed key, because using an AWS - "aws:SourceAccount": ["0123456789"] + "aws:SourceAccount": ["012345678901"] @@ -154 +156 @@ If you choose SSE-KMS, you must use a customer managed key, because using an AWS - "aws:SourceArn": ["arn:aws:logs:us-east-1:0123456789:delivery-source:*"] + "aws:SourceArn": ["arn:aws:logs:us-east-1:012345678901:delivery-source:*"] @@ -159 +161,37 @@ If you choose SSE-KMS, you must use a customer managed key, because using an AWS -For `aws:SourceAccount`, specify the list of account IDS for which logs are being delivered to this bucket. For `aws:SourceArn`, specify the list of ARNs of the resource that generates the logs, in the form `arn:aws:logs:`source-region`:`source-account-id`:*`. +For `aws:SourceAccount`, specify the account IDs whose logs are delivered to this bucket. For `aws:SourceArn`, specify the delivery source ARNs in the following format: `arn:aws:logs:`source-region`:`source-account-id`:delivery-source:*`. + +## Amazon S3 object key format + +For deliveries that use V2 permissions, the Amazon S3 object key is determined by the destination prefix, the log type, the delivery's suffix path, and whether Hive-compatible paths are enabled. The exact service-defined path and supported suffix variables vary by log type. + +Destination prefix + + +An optional path that you append to the bucket ARN when you call [PutDeliveryDestination](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_PutDeliveryDestination.html). For example, `arn:aws:s3:::`bucket-name`/`MyLogPrefix``. Delivered objects begin with this prefix. For log types that otherwise use a default `AWSLogs/`source-account-id`/`service-name`/` path, the destination prefix replaces that default path. + +Suffix path + + +An optional path that you configure for an individual delivery in its [S3DeliveryConfiguration](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_S3DeliveryConfiguration.html). A suffix can contain static text and variables. To find the variables supported by a log type, call [DescribeConfigurationTemplates](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_DescribeConfigurationTemplates.html) and check `allowedSuffixPathFields`. If you don't specify a suffix path, the log type's default suffix path is used when one is available. + +Hive-compatible path + + +When `enableHiveCompatiblePath` is `true`, variables in the effective path are rendered as ``key`=`value``. For example, the default account segment `AWSLogs/`source-account-id`/` becomes `AWSLogs/aws-account-id=`source-account-id`/`. Hive-compatible formatting also applies when you omit `suffixPath` and the log type uses its default suffix. + +The following examples show the beginning of an Application Load Balancer access-log object key for account `111122223333` in `us-east-1`. Unless noted, the examples assume no destination prefix. + +Configuration | Beginning of the object key +---|--- +Hive-compatible path disabled, suffix omitted | `AWSLogs/111122223333/elasticloadbalancing/us-east-1/2026/09/10/` +Hive-compatible path enabled, suffix omitted | `AWSLogs/aws-account-id=111122223333/elasticloadbalancing/region=us-east-1/year=2026/month=09/day=10/` +Hive-compatible path enabled, suffix `myFolder/{yyyy}/{MM}/{dd}` | `AWSLogs/aws-account-id=111122223333/elasticloadbalancing/myFolder/year=2026/month=09/day=10/` +Destination prefix `MyLogPrefix`, Hive-compatible path disabled, suffix omitted | `MyLogPrefix/us-east-1/2026/09/10/` + +###### Note + +CloudFront documents its standard logging (v2) path behavior and examples in [Send logs to Amazon S3](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/standard-logging.html#send-logs-s3). + +###### Note + +Changing the destination prefix, suffix path, or Hive-compatible setting affects new objects only. Existing objects are not moved. The bucket policy must allow `s3:PutObject` for the resulting prefix. When you manage the bucket policy, keep the `aws:SourceAccount` and `aws:SourceArn` conditions shown in the Amazon S3 bucket policy in Amazon S3 bucket resource policy, and grant access only to the required prefix.