AWS::FSx::FileSystem AuditLogConfiguration
The configuration that Amazon FSx for Windows File Server uses to audit and log user accesses of files, folders, and file shares on the Amazon FSx for Windows File Server file system.
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "AuditLogDestination" :
String
, "FileAccessAuditLogLevel" :String
, "FileShareAccessAuditLogLevel" :String
}
YAML
AuditLogDestination:
String
FileAccessAuditLogLevel:String
FileShareAccessAuditLogLevel:String
Properties
AuditLogDestination
-
The Amazon Resource Name (ARN) for the destination of the audit logs. The destination can be any Amazon CloudWatch Logs log group ARN or Amazon Kinesis Data Firehose delivery stream ARN.
The name of the Amazon CloudWatch Logs log group must begin with the
/aws/fsx
prefix. The name of the Amazon Kinesis Data Firehose delivery stream must begin with theaws-fsx
prefix.The destination ARN (either CloudWatch Logs log group or Kinesis Data Firehose delivery stream) must be in the same AWS partition, AWS Region, and AWS account as your Amazon FSx file system.
Required: No
Type: String
Pattern:
^arn:[^:]{1,63}:[^:]{0,63}:[^:]{0,63}:(?:|\d{12}):[^/].{0,1023}$
Minimum:
8
Maximum:
1024
Update requires: No interruption
FileAccessAuditLogLevel
-
Sets which attempt type is logged by Amazon FSx for file and folder accesses.
-
SUCCESS_ONLY
- only successful attempts to access files or folders are logged. -
FAILURE_ONLY
- only failed attempts to access files or folders are logged. -
SUCCESS_AND_FAILURE
- both successful attempts and failed attempts to access files or folders are logged. -
DISABLED
- access auditing of files and folders is turned off.
Required: Yes
Type: String
Allowed values:
DISABLED | SUCCESS_ONLY | FAILURE_ONLY | SUCCESS_AND_FAILURE
Update requires: No interruption
-
-
Sets which attempt type is logged by Amazon FSx for file share accesses.
-
SUCCESS_ONLY
- only successful attempts to access file shares are logged. -
FAILURE_ONLY
- only failed attempts to access file shares are logged. -
SUCCESS_AND_FAILURE
- both successful attempts and failed attempts to access file shares are logged. -
DISABLED
- access auditing of file shares is turned off.
Required: Yes
Type: String
Allowed values:
DISABLED | SUCCESS_ONLY | FAILURE_ONLY | SUCCESS_AND_FAILURE
Update requires: No interruption
-