Skip to main content
{ Reporting and Compliance / Infrastructure Operations }

AWS Resource Logging and Delivery

Identifies the AWS log sources in an account that are not enabled or not delivering logs.

What this agent does

This read-only agent checks that the log sources an AWS account needs are configured and delivering logs. It covers CloudTrail, GuardDuty exports, load balancers, VPC flow logs, S3 access logs, RDS audit logs, and the EKS control plane. It checks every enabled region, and it judges which resources need logging from their exposure and role.

The challenge

Teams often find a logging gap only when they need the logs for an investigation. A trail can report that it is logging while its bucket rejects every write. A new internet-facing load balancer launches without access logs, or a resource appears in a region nobody watches. A flat checklist either skips these cases or mixes them in with idle and internal resources.

The solution

The agent confirms that each log source is actually delivering logs, not just turned on, so the team can resolve failed logging pipelines proactively. It checks every enabled region and picks up new exposed resources automatically. It ignores resources that do not need logging, and it lists every exception it applied. Provides a unified list of logging issues to address.

Workflow

  1. 01

    Find regions and resources

    List every enabled region, and the resources of each active log source type.

  2. 02

    Decide what needs logging

    Judge account-wide sources by coverage, and other resources by exposure and role, then apply the exception list.

  3. 03

    Check delivery

    Confirm each in-scope source is enabled and delivering to a destination that accepts its logs.

  4. 04

    Report

    Report each gap with its fix, the exceptions applied, and any region not assessed.

Agent template

# AWS Resource Logging and Delivery

## Measurable outcomes

Every AWS log source the account needs is enabled and delivering. Every gap is in the report with its fix. Track the covered and uncovered source counts on every run.

## Procedure

For a given AWS account, check every enabled region. Cover these log source types, and let me choose which ones are active: CloudTrail, GuardDuty finding exports, load balancer access logs, VPC flow logs, S3 server access logs, RDS audit logs, and EKS control plane logs. Judge CloudTrail and GuardDuty exports by coverage of each region, and count coverage the organization provides. Judge the other types by exposure and role, such as internet-facing load balancers and production or sensitive data stores. Skip the resources on an exception list I maintain, and report each exception applied with its reason. A source passes only when it is enabled and delivering: no delivery errors, recent delivery where AWS reports it, and a destination that exists and accepts the logs. A quiet source with no activity is healthy, not failing. Report a region the agent cannot read as not assessed.

## Requirements

It needs a read-only AWS role for the account, and nothing more. It never turns on logging or changes any resource.