Logs for actions on amazon s3 / other AWS services -
i trying see user responsible changes in s3 (at buckets level). not find audit trail actions done @ s3 bucket level or ec2 created instances. beanstalk has log of actions machine performed, not user.
is there way around aws can see info in iam or other location ?
p.s: not interested know s3 log buckets provide access logs
update
aws has announced aws cloudtrail, making auditing api calls available of today (and free), see introductory post aws cloudtrail - capture aws api activity details:
do have need track api calls 1 or more aws accounts? if so, new aws cloudtrail service you.
once enabled, aws cloudtrail records calls made aws apis using aws management console, aws command line interface (cli), own applications, , third-party software , publishes resulting log files amazon s3 bucket of choice. cloudtrail can issue notification amazon sns topic of selection each time file published. each phone call logged in json format easy parsing , processing.
please note next (temporary) constraints:
not services covered yet, though of import ones included in initial release , aws plans to add together back upwards additional services on time. update: aws has added seven new services, , 1 today, see below. more importantly, not regions supported yet (right us east (northern virginia), , west (oregon) regions only), though aws adding back upwards additional regions possible. update: aws has added more locations , services, approaching coverage of entire global infrastructure indeed. initial answerthis long standing feature request, unfortunately aws not provide (public) audit trails of today - reasonable way add together feature respective extension aws identity , access management (iam), increasingly ubiquitous authentication , authorization layer access aws resources across existing (and future) products & services.
accordingly there few respective answers provided within iam faqs along these lines:
will aws identity , access management administrative actions logged audit trail?: no. planned future release. will user actions in aws services logged audit trail? no. planned future release. amazon-web-services amazon-s3 amazon-ec2 amazon-cloudfront amazon-iam
No comments:
Post a Comment