AWS Security ChangesHomeSearch

AWS transfer: Document proxy-protocol-v2-header CloudWatch log field

Service: transfer · 2026-09-27 · Documentation medium

File: transfer/latest/userguide/cw-structure-logs.md · Type: logging

Summary

Adds documentation for the `proxy-protocol-v2-header` log field and the `ProxyProtocolV2Header=ignored` value in the Logins/Logouts example, explaining when a PROXY protocol v2 header was ignored or applied based on the server's SftpMode.

Security assessment

Adds a CloudWatch structured-log field that records whether the client source IP header was honored, improving auditability of connections and the accuracy of IP-based access decisions. Logging/audit related, no specific vulnerability referenced.

Evidence

+proxy-protocol-v2-header | Present only when the connection included a PROXY protocol v2 (PPv2) header. The value is `ignored` when the server's `SftpMode` is `NONE`, and `applied` when `SftpMode` is `PROXY_PROTOCOL_V2_ENFORCED` and the server honored the header. For more information, see [Working with Network Load Balancers](./working-with-nlb.html). | ignored

Diff

diff --git a/transfer/latest/userguide/cw-structure-logs.md b/transfer/latest/userguide/cw-structure-logs.md
index a30f6a701..55058db60 100644
--- a//transfer/latest/userguide/cw-structure-logs.md
+++ b//transfer/latest/userguide/cw-structure-logs.md
@@ -39,0 +40 @@ path | Actual file path affected | /amzn-s3-demo-bucket/test-file-1.pdf
+proxy-protocol-v2-header | Present only when the connection included a PROXY protocol v2 (PPv2) header. The value is `ignored` when the server's `SftpMode` is `NONE`, and `applied` when `SftpMode` is `PROXY_PROTOCOL_V2_ENFORCED` and the server honored the header. For more information, see [Working with Network Load Balancers](./working-with-nlb.html). | ignored  
@@ -71 +72 @@ Downloads |  lhr.33a8fb495ffb383b OPEN Path=/bucket/user/123.jpg Mode=READ llhr.
-Logins/Logouts |  user.914984e553bcddb6 CONNECTED SourceIP=1.22.111.222 User=lhr HomeDir=LOGICAL Client=SSH-2.0-OpenSSH_7.4 Role=arn:aws::iam::123456789012:role/sftp-s3-access user.914984e553bcddb6 DISCONNECTED  
+Logins/Logouts |  user.914984e553bcddb6 CONNECTED SourceIP=1.22.111.222 User=lhr HomeDir=LOGICAL Client=SSH-2.0-OpenSSH_7.4 Role=arn:aws::iam::123456789012:role/sftp-s3-access ProxyProtocolV2Header=ignored user.914984e553bcddb6 DISCONNECTED The `ProxyProtocolV2Header` field is present only when the connection included a PROXY protocol v2 (PPv2) header. For more information, see the `proxy-protocol-v2-header` field description earlier in this topic.