AWS Route53: Document resource_id field in Resolver query log format
Summary
Adds the resource_id field to the query log format, describing the Route 53 Profile ID and noting vpc_id is omitted when logging is configured via Route 53 Profiles.
Security assessment
Documents a new log field for Route 53 Profile-based query logging, improving audit/forensic visibility into which profile a query logging configuration belongs to; no vulnerability is referenced.
Evidence
+ * `resource_id` – The ID of the Route 53 Profile that the query logging configuration is associated with. Included only when the configuration is associated with a Route 53 Profile.
Diff
diff --git a/Route53/latest/DeveloperGuide/resolver-query-logs-format.md b/Route53/latest/DeveloperGuide/resolver-query-logs-format.md index 143cf1a5f..d2b38d730 100644 --- a//Route53/latest/DeveloperGuide/resolver-query-logs-format.md +++ b//Route53/latest/DeveloperGuide/resolver-query-logs-format.md @@ -32 +32,7 @@ The AWS Region that you created the VPC in. -**vpc_id** +**vpc_id | resource_id** + + + * `vpc_id` – The ID of the VPC that the query originated in. VPC ID is not included when the query logging configuration is applied through Route 53 Profiles. + + * `resource_id` – The ID of the Route 53 Profile that the query logging configuration is associated with. Included only when the configuration is associated with a Route 53 Profile. + @@ -35 +40,0 @@ The AWS Region that you created the VPC in. -The ID of the VPC that the query originated in.