Logs sent to Amazon S3
For an AWS CLI example, see Create a delivery to Amazon S3.
User permissions
To enable sending logs to Amazon S3, you must be signed in with the following permissions.
Amazon S3 bucket resource policy
The S3 bucket where the logs are being sent must have a resource policy that
includes certain permissions. If the bucket currently does not have a resource
policy and the user setting up the logging has the S3:GetBucketPolicy
and S3:PutBucketPolicy permissions for the bucket, then AWS
automatically creates the following policy for it when you begin sending the logs to
Amazon S3.
In the previous policy, for aws:SourceAccount, specify the list of
account IDS for which logs are being delivered to this bucket. For
aws:SourceArn, specify the list of ARNs of the resource that
generates the logs, in the form
arn:aws:logs:. source-region:source-account-id:*
If the bucket has a resource policy but that policy doesn't contain the statement
shown in the previous policy, and the user setting up the logging has the
S3:GetBucketPolicy and S3:PutBucketPolicy permissions
for the bucket, that statement is appended to the bucket's resource policy.
Note
In some cases, you may see AccessDenied errors in AWS CloudTrail if the
s3:ListBucket permission has not been granted to
delivery.logs.amazonaws.com. To avoid these errors in your CloudTrail
logs, you must grant the s3:ListBucket permission to
delivery.logs.amazonaws.com and you must include the
Condition parameters shown with the
s3:GetBucketAcl permission set in the preceding bucket policy.
To make this simpler, instead of creating a new Statement, you can
directly update the AWSLogDeliveryAclCheck to be “Action”:
[“s3:GetBucketAcl”, “s3:ListBucket”]
Amazon S3 bucket server-side encryption
You can protect the data in your Amazon S3 bucket by enabling server-side encryption. You can use Amazon S3-managed keys (SSE-S3) or a AWS KMS key stored in AWS Key Management Service (SSE-KMS). For more information, see Protecting data using server-side encryption.
If you choose SSE-S3, no additional configuration is required. Amazon S3 handles the encryption key.
Customer managed key required
If you choose SSE-KMS, you must use a customer managed key. You can't use an AWS managed key. If you configure encryption with an AWS managed key, CloudWatch Logs delivers the logs in an unreadable format.
For SSE-KMS, specify the Amazon Resource Name (ARN) of the key when you enable bucket encryption. Add the following to the key policy (not to the bucket policy for your S3 bucket), so that the log delivery account can write to your S3 bucket.
{ "Sid": "Allow Logs Delivery to use the key", "Effect": "Allow", "Principal": { "Service": [ "delivery.logs.amazonaws.com" ] }, "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey" ], "Resource": "*", "Condition": { "StringEquals": { "aws:SourceAccount": ["012345678901"] }, "ArnLike": { "aws:SourceArn": ["arn:aws:logs:us-east-1:012345678901:delivery-source:*"] } } }
For aws:SourceAccount, specify the account IDs whose logs are
delivered to this bucket. For aws:SourceArn, specify the delivery
source ARNs in the following format:
arn:aws:logs:.source-region:source-account-id:delivery-source:*
Amazon S3 object key format
For deliveries that use V2 permissions, the Amazon S3 object key is determined by the destination prefix, the log type, the delivery's suffix path, and whether Hive-compatible paths are enabled. The exact service-defined path and supported suffix variables vary by log type.
- Destination prefix
-
An optional path that you append to the bucket ARN when you call PutDeliveryDestination. For example,
arn:aws:s3:::. Delivered objects begin with this prefix, followed by the log type's service-defined path, such asbucket-name/MyLogPrefixAWSLogs/. For CloudFront standard logging (v2), the destination prefix replaces, rather than precedes, that default path.source-account-id/service-name/ - Suffix path
-
An optional path that you configure for an individual delivery in its S3DeliveryConfiguration. A suffix can contain static text and variables. To find the variables supported by a log type, call DescribeConfigurationTemplates and check
allowedSuffixPathFields. If you don't specify a suffix path, the log type's default suffix path is used when one is available. - Hive-compatible path
-
When
enableHiveCompatiblePathistrue, supported variables in an explicitsuffixPathare rendered as. For log types such as Application Load Balancer access logs, this formatting also changes the service-defined account segment. For example,key=valueAWSLogs/becomessource-account-id/AWSLogs/aws-account-id=.source-account-id/If you omit
suffixPath, Hive-compatible formatting applies only when the log type's default suffix path supports it. For example, Application Load Balancer access logs support this formatting. Other log types, including Amazon S3 server access logs, retain their original default suffix in non-Hive form, including resource and date directories.For a log type whose default does not support Hive-compatible formatting, specify a valid
suffixPaththat contains supported variables. An explicit suffix replaces the default suffix. Include the resource and date variables that you need, using the log type'sallowedSuffixPathFieldsfrom DescribeConfigurationTemplates.
The following examples show the beginning of an Application Load Balancer access-log object key
for account 111122223333 in us-east-1. Unless noted,
the examples assume no destination prefix.
| Configuration | Beginning of the object key |
|---|---|
| Hive-compatible path disabled, suffix omitted | AWSLogs/111122223333/elasticloadbalancing/us-east-1/2026/09/10/ |
| Hive-compatible path enabled, suffix omitted | AWSLogs/aws-account-id=111122223333/elasticloadbalancing/region=us-east-1/year=2026/month=09/day=10/ |
Hive-compatible path enabled, suffix
myFolder/{yyyy}/{MM}/{dd} |
AWSLogs/aws-account-id=111122223333/elasticloadbalancing/myFolder/year=2026/month=09/day=10/ |
Hive-compatible path enabled, suffix
myFolder/ |
AWSLogs/111122223333/elasticloadbalancing/myFolder/ |
Destination prefix MyLogPrefix,
Hive-compatible path disabled, suffix omitted |
MyLogPrefix/AWSLogs/111122223333/elasticloadbalancing/us-east-1/2026/09/10/ |
Static suffix paths and bucket permissions
For log types such as Application Load Balancer access logs, a suffixPath that
contains only static text does not enable Hive-compatible formatting of
the service-defined account prefix. For example, myFolder/
uses the plain account prefix shown in the table. Delivery fails if
CloudWatch Logs tries to write under the plain account prefix and the bucket policy
allows only the Hive-compatible prefix.
When you create an Application Load Balancer delivery with
enableHiveCompatiblePath set to true, the
automatically created bucket policy grants s3:PutObject on
the Hive-compatible prefix. Include at least one supported variable from
the log type's
allowedSuffixPathFields in suffixPath, or omit
suffixPath for a log type whose default suffix path
supports Hive-compatible formatting.
CloudFront standard logging (v2) formats its default prefix independently of
variables in suffixPath.
Note
CloudFront documents its standard logging (v2) path behavior and examples in Send logs to Amazon S3.
Note
Updating the suffix path or Hive-compatible setting affects subsequent deliveries after the configuration propagates. Existing objects are not moved. You cannot change a destination's ARN, including its prefix, while active deliveries reference that destination.
The bucket policy must allow s3:PutObject for the resulting
prefix. When you manage the bucket policy, keep the
aws:SourceAccount and
aws:SourceArn conditions shown in the Amazon S3 bucket policy in
Amazon S3 bucket resource policy,
and grant access only to the required prefix.