Control: 5.3 Ensure that logging is enabled for OSS buckets
Description
OSS Bucket Access Logging generates a log that contains access records for each request made to your OSS bucket. An access log record contains details about the request, such as the request type, the resources specified in the request worked, and the time and date the request was processed. It is recommended that bucket access logging be enabled on the OSS bucket.
Remediation
From Console
Perform the following to enable OSS bucket logging:
- Logon to OSS console.
- In the bucket-list pane, click on a target OSS bucket.
- Under
Log
, clickConfigure
. - Configure bucket logging.
- Click the
Enabled
checkbox. - Select Target Bucket from list.
- Enter a Target Prefix.
- Click
Save
.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_5_3
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_5_3 --share
SQL
This control uses a named query:
oss_bucket_logging_enabled