Control: CodeBuild projects should have logging enabled
Description
This control checks if an AWS CodeBuild project environment has at least one log option enabled. The rule is non-compliant if the status of all present log configurations is set to 'DISABLED'.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.codebuild_project_logging_enabledSnapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.codebuild_project_logging_enabled --shareSQL
This control uses a named query:
select  arn as resource,  case    when logs_config -> 'CloudWatchLogs' ->> 'Status' = 'ENABLED' or logs_config -> 'S3Logs' ->> 'Status' = 'ENABLED' then 'ok'    else 'alarm'  end as status,  case    when logs_config -> 'CloudWatchLogs' ->> 'Status' = 'ENABLED' or logs_config -> 'S3Logs' ->> 'Status' = 'ENABLED' then title || ' logging enabled.'    else title || ' logging disabled.'  end as reason    , region, account_idfrom  aws_codebuild_project;