aws-cloudfront-access-log-object-content

CloudFront logs can contain URI query strings, cookies, headers selected for real-time logs, and client identifiers.

awshigh service: aws:cloudfront emits ContainsSecret

Where it sits

locationS3 CloudFront standard or real-time log record
location kindlog_field
data kindscredential api_key bearer_token session_token pii sensitive_data
emits edgeContainsSecret
serviceCloudFront (aws:cloudfront)

Collection recipe

access modeindirect_destination
operations3:GetObject or logs:FilterLogEvents
response pathlog record fields
encodingstring
params{"Destination": "\u003cconfigured-log-destination\u003e"}

Required permissions

cloudfront:GetDistributionConfig
s3:GetObject

References

move · open · esc close