AWSCloudFront的集中式多账户日志记录
创始人
2024-09-24 08:00:59
0
  1. 在主账户上创建Amazon S3存储桶,并设置为允许所有子账户的CloudFront实例将日志写入该存储桶中。示例代码:
{
    "Version": "2012-10-17",
    "Id": "PolicyForCloudFrontLoggingBucket",
    "Statement": [
        {
            "Sid": "AllowBucketAccess",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::123456789012:root"
            },
            "Action": [
                "s3:GetBucketAcl",
                "s3:PutBucketAcl"
            ],
            "Resource": "arn:aws:s3:::example-log-bucket"
        },
        {
            "Sid": "AllowObjectAccess",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::123456789012:root"
            },
            "Action": [
                "s3:PutObject",
                "s3:GetObject"
            ],
            "Resource": [
                "arn:aws:s3:::example-log-bucket/AWSLogs/123456789012/*"
            ],
            "Condition": {
                "StringEquals": {
                    "s3:x-amz-acl": "bucket-owner-full-control"
                }
            }
        }
    ]
}
  1. 在每个子账户的CloudFront实例上启用访问日志记录,并配置日志格式。示例代码:
{
    "TrustedSigners": {
        "Enabled": false,
        "Quantity": 0
    },
    "ViewerProtocolPolicy": "redirect-to-https",
    "Logging": {
        "Enabled": true,
        "IncludeCookies": false,
        "Bucket": "example-log-bucket",
        "Prefix": "AWSLogs/123456789012",
        "Format": "{ \"timestamp\":\"$time_iso8601\", \"distribution\":\"$distribution\", \"containingBucket\":\"$containing_bucket\", \"path\":\"$key\", \"ip\":\"$remote_addr\", \"referer\":\"$http_referer\", \"useragent\":\"$http_user_agent\", \"status\":\"

相关内容

热门资讯

专业讨论!wpk德州,aapo... 您好,aapoker外挂这款游戏可以开挂的,确实是有挂的,需要了解加微【136704302】很多玩家...
透视苹果版!wepoekr底牌... 透视苹果版!wepoekr底牌透视,创思维激k辅助器免费,切实教程(有挂技巧)关于创思维激k辅助器免...
一起来探讨!微扑克发牌系统,德... 一起来探讨!微扑克发牌系统,德州之星有外挂,切实教程(真是真的有挂)是一款可以让一直输的玩家,快速成...
透视好友房!hhpoker透视... 透视好友房!hhpoker透视方法,广东雀神智能插件,爆料教程(有挂神器);科技安装教程;13670...
玩家爆料!德扑之星带入记分牌,... 玩家爆料!德扑之星带入记分牌,wepoke是真的有挂,靠谱教程(最初是有挂)wepoke是真的有挂辅...
透视ai代打!aapkoer德... 透视ai代打!aapkoer德州辅助挂下载,情怀宜春辅助,解密教程(有挂辅助)1、许多玩家不知道情怀...
分享实测!wpk号一直输,we... 分享实测!wpk号一直输,wepoke计算辅助,靠谱教程(素来存在有挂)1、这是跨平台的wepoke...
透视安装!德普之星透视辅助插件... 这是一款非常优秀的上饶打炸作弊 ia辅助检测软件,能够让你了解到上饶打炸作弊中牌率当中全部隐藏参数,...
玩家必备科普!wepoke游戏... 自定义aapoker挂系统规律,只需要输入自己想要的开挂功能,一键便可以生成出微扑克专用辅助器,不管...
透视好友!智星德州菠萝透视插件... 透视好友!智星德州菠萝透视插件工具,长春科乐天天踢辅助,靠谱教程(有挂方法);长春科乐天天踢辅助软件...