aws-bedrock-model-invocation-log-destination

Model invocation logging can persist full request and response data, including prompts and completions, in S3 or CloudWatch Logs.

awscritical service: aws:bedrock emits ContainsSecret

Where it sits

locationConfigured S3/CloudWatch Bedrock model invocation log record
location kindlog_field
data kindscredential password api_key customer_data pii source_code_secret sensitive_data
emits edgeContainsSecret
serviceBedrock (aws:bedrock)

Collection recipe

access modeindirect_destination
operationGetModelInvocationLoggingConfiguration then s3:GetObject/logs:FilterLogEvents
response pathinvocation request/response log fields
encodingjson
params{"Destination": "\u003cconfigured-destination\u003e"}

Required permissions

bedrock:GetModelInvocationLoggingConfiguration
s3:GetObject

References

move · open · esc close