AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Clarifies AllowVendedLogDeliveryForResource policy placeholders

Service: AmazonCloudWatch · 2026-09-27 · Documentation medium

File: AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-service-specific.md · Type: iam

Summary

Rewrites the guidance for the service-specific vended logs authorization policy: clarifies that the policy authorizes the AllowVendedLogDeliveryForResource action, adds region and account-id as placeholders alongside service and resource-type, and warns that not every service uses this action so the service's vended logs documentation must be consulted.

Security assessment

The change documents an IAM authorization control (AllowVendedLogDeliveryForResource) that acts as an additional layer of security restricting which resources may vend logs, and adds account/region scoping placeholders to reduce overly broad or incorrect policy construction. It is security best-practice documentation rather than a fix for a specific vulnerability, so medium severity.

Evidence

+In addition to the destination-specific permissions listed in the previous sections, some services require explicit authorization that customers are allowed to send logs from their resources, as an additional layer of security. This policy authorizes the `AllowVendedLogDeliveryForResource` action for resources that vend logs within that service. For these services, use the following policy and replace the service namespace (`service`), the Region (`region`), the AWS account ID (`account-id`), and the resource type (`resource-type`) with the appropriate values for your resource. Not every service that vends logs uses this action. Confirm the required permissions and values, including whether the `AllowVendedLogDeliveryForResource` action applies, in the vended logs documentation for the service that you are granting access to. The following example shows the policy for vending logs from Amazon SES.

Diff

diff --git a/AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-service-specific.md b/AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-service-specific.md
index 494569ded..4bc7888d5 100644
--- a//AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-service-specific.md
+++ b//AmazonCloudWatch/latest/logs/AWS-logs-infrastructure-V2-service-specific.md
@@ -9 +9 @@
-In addition to the destination-specific permissions listed in the previous sections, some services require explicit authorization that customers are allowed to send logs from their resources, as an additional layer of security. It authorizes the `AllowVendedLogDeliveryForResource` action for resources that vend logs within that service. For these services, use the following policy and replace `service` and `resource-type` with the appropriate values. For the service-specific values for these fields, see those services' documentation page for vended logs. In the following example, the policy has been updated to enable vended logs from Amazon SES.
+In addition to the destination-specific permissions listed in the previous sections, some services require explicit authorization that customers are allowed to send logs from their resources, as an additional layer of security. This policy authorizes the `AllowVendedLogDeliveryForResource` action for resources that vend logs within that service. For these services, use the following policy and replace the service namespace (`service`), the Region (`region`), the AWS account ID (`account-id`), and the resource type (`resource-type`) with the appropriate values for your resource. Not every service that vends logs uses this action. Confirm the required permissions and values, including whether the `AllowVendedLogDeliveryForResource` action applies, in the vended logs documentation for the service that you are granting access to. The following example shows the policy for vending logs from Amazon SES.