0

I am trying to set up logging for my AWS S3 buckets.

I ran accross this AWS Config rule s3-bucket-logging-enabled. The logs here are server access logs.
From the CIS AWS Foundations 1.5.0 I also need to set up object-level logging for read events.

I found this in S3 doc about logging options. I just can't get my head around this. Can anyone help me understand if server access logs and object-level logs are different or the same and what service I must use between S3 server logs, CloudTrail and Cloudwatch.
I am also not sure about what log type does the Config rule check.

Thank you for your time

Achi
  • 27
  • 3
  • 1
    The difference between those two logging types is displayed in a helpful table here: https://docs.aws.amazon.com/AmazonS3/latest/userguide/logging-with-S3.html – Mark B Jul 25 '23 at 18:16

0 Answers0