Skip to content

Latest commit

 

History

History
27 lines (23 loc) · 2.68 KB

cloudtrail-bucket-access-logging.md

File metadata and controls

27 lines (23 loc) · 2.68 KB

CloudSploit

AWS / CloudTrail / CloudTrail Bucket Access Logging

Quick Info

Plugin Title CloudTrail Bucket Access Logging
Cloud AWS
Category CloudTrail
Description Ensures CloudTrail logging bucket has access logging enabled to detect tampering of log files
More Info CloudTrail buckets should utilize access logging for an additional layer of auditing. If the log files are deleted or modified in any way, the additional access logs can help determine who made the changes.
AWS Link http://docs.aws.amazon.com/AmazonS3/latest/UG/ManagingBucketLogging.html
Recommended Action Enable access logging on the CloudTrail bucket from the S3 console

Detailed Remediation Steps

  1. Log into the AWS Management Console.
  2. Select the "Services" option and search for "CloudTrail".
    Step 2
  3. In the "Dashboard" panel click on "View trails" button.
    Step 3
  4. Select the "trail" that needs to be verified under "Name" column.
    Step 4
  5. Scroll down and under the "Storage location" option check the S3 bucket used to store log data.
    Step 5
  6. Go to "Services" and search for "S3" to go into S3 buckets dashboard.
    Step 6
  7. Select the "S3 bucket" used to store data log in CloudTrail.
    Step 7
  8. Click the "Properties" tab from panel to get into Properties configuration options.
    Step 8
  9. From "Server Access Login" check if the "Enabled" checkbox is selected and if the "Disable Logging" checkbox is selected the logging feature is not enabled for the selected "CloudTrail" bucket.
    Step 9
  10. Click on "Enabled" checkbox and specify the "Target bucket" used to store data log files. Provide a "Prefix" that S3 can assign to all log object keys. Save the changes after review.
    Step 10