AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: ArnLike for aws:SourceArn plus Firehose link fix in subscription filters

Service: AmazonCloudWatch · 2026-09-27 · Documentation medium

File: AmazonCloudWatch/latest/logs/SubscriptionFilters.md · Type: iam

Summary

Sample subscription filter policies were changed from StringLike to ArnLike for the aws:SourceArn condition key, and a Firehose example link was corrected to the full AmazonCloudWatch/latest/logs path.

Security assessment

The ArnLike change makes the aws:SourceArn condition in the example resource policies match ARNs correctly, supporting the documented confused-deputy protection; the link edit is purely editorial. No specific vulnerability or CVE is referenced.

Evidence

+            "ArnLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } 

Diff

diff --git a/AmazonCloudWatch/latest/logs/SubscriptionFilters.md b/AmazonCloudWatch/latest/logs/SubscriptionFilters.md
index 7650964dc..2b26c3f6f 100644
--- a//AmazonCloudWatch/latest/logs/SubscriptionFilters.md
+++ b//AmazonCloudWatch/latest/logs/SubscriptionFilters.md
@@ -96 +96 @@ This policy includes a `aws:SourceArn` global condition context key to help prev
-            "StringLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } 
+            "ArnLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } 
@@ -372 +372 @@ The actual log data, represented as an array of log event records. The "id" prop
-In this example, you'll create a CloudWatch Logs subscription that sends any incoming log events that match your defined filters to your Amazon Data Firehose delivery stream. Data sent from CloudWatch Logs to Amazon Data Firehose is already compressed with gzip level 6 compression, so you do not need to use compression within your Firehose delivery stream. You can then use the decompression feature in Firehose to automatically decompress the logs. For more information, see [ Send CloudWatch Logs to Firehose](https://docs.aws.amazon.com/logs/SubscriptionFilters.html#FirehoseExample).
+In this example, you'll create a CloudWatch Logs subscription that sends any incoming log events that match your defined filters to your Amazon Data Firehose delivery stream. Data sent from CloudWatch Logs to Amazon Data Firehose is already compressed with gzip level 6 compression, so you do not need to use compression within your Firehose delivery stream. You can then use the decompression feature in Firehose to automatically decompress the logs. For more information, see [ Send CloudWatch Logs to Firehose](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/SubscriptionFilters.html#FirehoseExample).
@@ -506 +506 @@ This policy includes a `aws:SourceArn` global condition context key to help prev
-             "StringLike": { 
+             "ArnLike": {