AWS AmazonCloudWatch: CloudWatch vended logs permissions: add delivery examples and cross-account limits
Summary
Adds a 'Log delivery setup examples' section with CLI examples for creating delivery sources/destinations (CloudWatch Logs, S3, Firehose, X-Ray), states that cross-account delivery supports only S3 and Firehose destinations, links to a cross-account example, and adds links to per-destination user permissions and resource-policy topics (log group, S3 bucket, Firehose IAM roles, X-Ray resource policy).
Security assessment
The added content is permission-oriented documentation: it clarifies that cross-account vended-log delivery is restricted to S3 and Firehose destinations and that PutDeliveryDestinationPolicy is required in the destination account, and it links directly to user-permission and resource-policy (log group, S3 bucket, Firehose role, X-Ray) guidance. This improves authorization guidance for log delivery but does not reference or remediate a specific vulnerability, CVE, or incident.
Evidence
+ * [Log group resource policy](./AWS-logs-infrastructure-V2-CloudWatchLogs.html#AWS-logs-infrastructure-V2-CloudWatchLogs-log-group-resource-policy)
Diff
diff --git a/AmazonCloudWatch/latest/logs/AWS-vended-logs-permissions-V2.md b/AmazonCloudWatch/latest/logs/AWS-vended-logs-permissions-V2.md index 3cedfc803..d068262f1 100644 --- a//AmazonCloudWatch/latest/logs/AWS-vended-logs-permissions-V2.md +++ b//AmazonCloudWatch/latest/logs/AWS-vended-logs-permissions-V2.md @@ -6,0 +7,2 @@ +Log delivery setup examples + @@ -28 +30 @@ To configure logs delivery between a supported AWS service and a destination, yo - * If you are delivering logs cross-account, you must use [ PutDeliveryDestinationPolicy](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_PutDeliveryDestinationPolicy.html) in the destination account to assign an IAM policy to the destination. This policy authorizes creating a delivery from the delivery source in account A to the delivery destination in account B. For cross-account delivery, you must manually create the permission policies yourself. + * If you are delivering logs cross-account, you can use only Amazon S3 and Firehose destinations. You must use [ PutDeliveryDestinationPolicy](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_PutDeliveryDestinationPolicy.html) in the destination account to assign an IAM policy to the destination. This policy authorizes creating a delivery from the delivery source in account A to the delivery destination in account B. For cross-account delivery, you must manually create the permission policies yourself. For setup examples, see [Cross-account delivery example](./vended-logs-crossaccount-example.html). @@ -34,0 +37,103 @@ To configure logs delivery between a supported AWS service and a destination, yo +## Log delivery setup examples + +The following examples create the delivery source and delivery destination in the same AWS account. Replace the source resource ARN and log type with values supported by the service that generates the logs. These examples don't require a delivery destination policy. + +### Create a delivery source for CloudWatch Logs Insights query execution logs + +The following example creates a delivery source for CloudWatch Logs Insights query execution logs. For the full `logType` and resource ARN requirements, see [PutDeliverySource](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_PutDeliverySource.html). + +###### Note + +The trailing wildcard in `log-group:*` is required because query execution logs are not tied to one log group. AWS does not support a specific log group ARN for this log type. + + + aws logs put-delivery-source \ + --name insights-query-logs \ + --resource-arn arn:aws:logs:region:account-id:log-group:* \ + --log-type INSIGHTS_QUERY_LOGS + +### Create a delivery source + +Create the delivery source, and then use one of the destination examples that follow. + + + aws logs put-delivery-source \ + --name my-delivery-source \ + --resource-arn source-resource-arn \ + --log-type log-type + +### Create a delivery to CloudWatch Logs + +Create a delivery destination for an existing log group. + + + aws logs put-delivery-destination \ + --name my-cwl-delivery-destination \ + --delivery-destination-configuration \ + "destinationResourceArn=arn:aws:logs:region:account-id:log-group:log-group-name" + +Create the delivery. + + + aws logs create-delivery \ + --delivery-source-name my-delivery-source \ + --delivery-destination-arn arn:aws:logs:region:account-id:delivery-destination:my-cwl-delivery-destination + +### Create a delivery to Amazon S3 + +Create a delivery destination for an existing bucket. + + + aws logs put-delivery-destination \ + --name my-s3-delivery-destination \ + --delivery-destination-configuration \ + "destinationResourceArn=arn:aws:s3:::bucket-name" + +Create the delivery. + + + aws logs create-delivery \ + --delivery-source-name my-delivery-source \ + --delivery-destination-arn arn:aws:logs:region:account-id:delivery-destination:my-s3-delivery-destination + +To configure a destination prefix, suffix path, or Hive-compatible path, see [Amazon S3 object key format](./AWS-logs-infrastructure-V2-S3.html#AWS-logs-infrastructure-V2-S3-object-key). + +### Create a delivery to Firehose + +Create a delivery destination for an existing DirectPut delivery stream. + + + aws logs put-delivery-destination \ + --name my-firehose-delivery-destination \ + --delivery-destination-configuration \ + "destinationResourceArn=arn:aws:firehose:region:account-id:deliverystream/delivery-stream-name" + +Create the delivery. + + + aws logs create-delivery \ + --delivery-source-name my-delivery-source \ + --delivery-destination-arn arn:aws:logs:region:account-id:delivery-destination:my-firehose-delivery-destination + +### Create a delivery to X-Ray + +For trace delivery, use a source service and log type that supports delivery to X-Ray. Create the logical X-Ray delivery destination. + + + aws logs put-delivery-destination \ + --name my-xray-delivery-destination \ + --delivery-destination-type XRAY + +Create the delivery. + + + aws logs create-delivery \ + --delivery-source-name my-delivery-source \ + --delivery-destination-arn arn:aws:logs:region:account-id:delivery-destination:my-xray-delivery-destination + +To verify the delivery, use the following command. + + + aws logs describe-deliveries \ + --delivery-source-name-prefix my-delivery-source + @@ -53,0 +159,4 @@ It is your responsibility to remove log delivery resources after deleting the lo + * [User permissions](./AWS-logs-infrastructure-V2-CloudWatchLogs.html#AWS-logs-infrastructure-V2-CloudWatchLogs-user-permissions) + + * [Log group resource policy](./AWS-logs-infrastructure-V2-CloudWatchLogs.html#AWS-logs-infrastructure-V2-CloudWatchLogs-log-group-resource-policy) + @@ -55,0 +165,4 @@ It is your responsibility to remove log delivery resources after deleting the lo + * [User permissions](./AWS-logs-infrastructure-V2-S3.html#AWS-logs-infrastructure-V2-S3-user-permissions) + + * [Amazon S3 bucket resource policy](./AWS-logs-infrastructure-V2-S3.html#AWS-logs-infrastructure-V2-S3-bucket-resource-policy) + @@ -57,0 +171,2 @@ It is your responsibility to remove log delivery resources after deleting the lo + * [Amazon S3 object key format](./AWS-logs-infrastructure-V2-S3.html#AWS-logs-infrastructure-V2-S3-object-key) + @@ -59,0 +175,4 @@ It is your responsibility to remove log delivery resources after deleting the lo + * [User permissions](./AWS-logs-infrastructure-V2-Firehose.html#AWS-logs-infrastructure-V2-Firehose-user-permissions) + + * [IAM roles used for resource permissions](./AWS-logs-infrastructure-V2-Firehose.html#AWS-logs-infrastructure-V2-Firehose-resource-permissions) + @@ -61,0 +181,6 @@ It is your responsibility to remove log delivery resources after deleting the lo + * [User permissions](./AWS-logs-infrastructure-V2-XRayTraces.html#AWS-logs-infrastructure-V2-XRayTraces-user-permissions) + + * [X-Ray resource policy](./AWS-logs-infrastructure-V2-XRayTraces.html#AWS-logs-infrastructure-V2-XRayTraces-resource-policy) + + * [Enable transaction search](./AWS-logs-infrastructure-V2-XRayTraces.html#AWS-logs-infrastructure-V2-XRayTraces-transaction-search) +