본문 바로가기
[AWS-DR]/VPC&Subnet

[중요2][VPC플로우로그] How to write VPC flow logs to an S3 bucket on another AWS account !!

by METAVERSE STORY 2024. 7. 7.
반응형
728x170

 

 

## 소스 - 2995 계정에서 VPC 생성

 

## 목적지 - 8749 계정에서 S3 버킷 생성
- S3 버킷 속성 ==> ARN 복사 및 저장

 

 

 

## 소스 - 2995 계정에서 Create flow log

 

- S3 버킷 접근에러 발생

 

 

 

 

 

## 목적지 - 8749 계정에서 S3 버킷 정책생성


{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AWSLogDeliveryWrite",
            "Effect": "Allow",
            "Principal": {
                "Service": "delivery.logs.amazonaws.com"
            },
            "Action": "s3:PutObject",
            "Resource": [
                "arn:aws:s3:::bucketname",
                "arn:aws:s3:::bucketname/*"
            ],
            "Condition": {
                "StringEquals": {
                    "s3:x-amz-acl": "bucket-owner-full-control",
                    "aws:SourceAccount": "sourceaccountid"
                },
                "ArnLike": {
                    "aws:SourceArn": "arn:aws:logs:ap-south-1:sourceaccountid:*"
                }
            }
        },
        {
            "Sid": "AWSLogDeliveryCheck",
            "Effect": "Allow",
            "Principal": {
                "Service": "delivery.logs.amazonaws.com"
            },
            "Action": [
                "s3:GetBucketAcl",
                "s3:ListBucket"
            ],
            "Resource": [
                "arn:aws:s3:::bucketname",
                "arn:aws:s3:::bucketname/*"
            ],
            "Condition": {
                "StringEquals": {
                    "aws:SourceAccount": "sourceaccountid"
                },
                "ArnLike": {
                    "aws:SourceArn": "arn:aws:logs:ap-south-1:sourceaccountid:*"
                }
            }
        }
    ]
}

 

 

 

## 소스 - 2995 계정에서 Create flow log 성공

 

 

## 목적지 - 8749 계정에서 S3 버킷 하위 디렉토리 생성 확인

 

 

 

 

 

 

https://www.youtube.com/watch?v=EzOa7QfPf6Q

 

반응형
그리드형

댓글