Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch 412 #434

Merged
merged 21 commits into from
Nov 2, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
d4eecec
Update cloudfront-logging-enabled.md
shuklaalok87 Jan 5, 2022
c89b423
Update step2.png
shuklaalok87 Jan 5, 2022
6a125d5
Update step3.png
shuklaalok87 Jan 5, 2022
283e0f9
Update step4.png
shuklaalok87 Jan 5, 2022
bbc7fd9
Update cloudfront-logging-enabled.md
shuklaalok87 Jan 5, 2022
7e64070
Update step4.png
shuklaalok87 Jan 5, 2022
9ee4963
Merge branch 'patch-412' of https://github.com/shuklaalok87/security-…
shuklaalok87 Jan 5, 2022
69daa35
Update cloudfront-logging-enabled.md
shuklaalok87 Jan 5, 2022
98802c6
Updated images for step 5 & 6
shuklaalok87 Jan 5, 2022
02e7315
Merge branch 'patch-412' of https://github.com/shuklaalok87/security-…
shuklaalok87 Jan 5, 2022
823c0c1
Update cloudfront-logging-enabled.md
shuklaalok87 Jan 5, 2022
d567896
Update step7.png
shuklaalok87 Jan 5, 2022
b27f449
Merge branch 'patch-412' of https://github.com/shuklaalok87/security-…
shuklaalok87 Jan 5, 2022
0b34102
Update step8.png
shuklaalok87 Jan 5, 2022
a3aaf0f
Update cloudfront-logging-enabled.md
shuklaalok87 Jan 5, 2022
25b3b0a
Update step9.png
shuklaalok87 Jan 5, 2022
0f69298
Merge branch 'patch-412' of https://github.com/shuklaalok87/security-…
shuklaalok87 Jan 5, 2022
e860b5f
Update cloudfront-logging-enabled.md
shuklaalok87 Jan 5, 2022
a9a7cdb
Delete step10.png
shuklaalok87 Jan 5, 2022
4d4add8
Merge branch 'patch-412' of https://github.com/shuklaalok87/security-…
shuklaalok87 Jan 5, 2022
41283af
Apply suggestions from code review
alphadev4 Nov 2, 2022
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 8 additions & 9 deletions en/aws/cloudfront/cloudfront-logging-enabled.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,14 +15,13 @@
| **Recommended Action** | Enable CloudFront request logging. |

## Detailed Remediation Steps
1. Log into to the AWS Management Console.
1. Log in to the AWS Management Console.
2. Select the "Services" option and search for CloudFront. </br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step2.png"/>
3. Select the "CloudFront Distribution" that needs to be verified.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step3.png"/>
4. Click the "Distribution Settings" button from menu to get into the "CloudFront Distribution" configuration page. </br><img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step4.png"/>
5. Click the "Edit" button from the "General" tab on the top menu. </br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step5.png"/>
6. In the "Distribution Settings" tab scroll down and verify the "Logging" feature configuration status. If Logging is "Off" then it cannot create log files that contain detailed information about every user request that CloudFront receives.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step6.png"/>
7. Click on the "ON" option to initiate the Logging feature of CloudFront to log all viewer requests for files in your distribution.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step7.png"/>
8. Click on "Bucket for Logs" feature and specify the Amazon S3 bucket in which you want CloudFront to save web access logs.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step8.png"/>
9. Click on Log Prefix which is optional for the names of log files.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step9.png"/>
10. Scroll down and click on "Yes,Edit" to save the changes.</br><img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step10.png"/>
11. Repeat the steps number 5 and 6 to establish any other "CloudFront Distribution" has Logging enabled or not.
4. Click on the selected Distribution to get into the CloudFront Distribution configuration page. </br><img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step4.png"/>
5. In the "General" tab scroll down to settings and verify the "Standard logging" feature configuration status. If Logging is "Off" then it cannot create log files that contain detailed information about every user request that CloudFront receives.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step5.png"/>
6. To change the status click on "Edit" to get to the "Edit Settings" page. Scroll down to "Standard Logging" and select the "On" option to initiate the Logging feature of CloudFront to log all viewer requests for files in your distribution.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step6.png"/>
7. Click on "Bucket for Logs" feature and specify the Amazon S3 bucket in which you want CloudFront to save web access logs.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step7.png"/>
8. Click on Log Prefix which is optional for the names of log files.</br> <img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step8.png"/>
9. Scroll down and click on "Save changes" to save the new settings.</br><img src="/resources/aws/cloudfront/cloudfront-logging-enabled/step9.png"/>
10. Repeat the steps number 3 to 9 to verify if any other "CloudFront Distribution" has Logging enabled or not.
Binary file not shown.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step2.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step3.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step4.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step5.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step6.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step7.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step8.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified resources/aws/cloudfront/cloudfront-logging-enabled/step9.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.