본문 바로가기

Ops/AWS

AWS IAM Policy - CloudWatch log to S3

반응형

AWS IAM Policy - CloudWatch log to S3

 

 

 

 

■ 설명

CloudWatch 로그를 S3에서 받기 위한 Policy

 

 

■ 코드

{
    "Version": "2012-10-17",
    "Statement": [
      {
          "Action": "s3:GetBucketAcl",
          "Effect": "Allow",
          "Resource": "arn:aws:s3:::bucketname",
          "Principal": { "Service": "logs.us-east-1.amazonaws.com" }
      },
      {
          "Action": "s3:PutObject" ,
          "Effect": "Allow",
          "Resource": "arn:aws:s3:::bucketname/*",
          "Condition": { "StringEquals": { "s3:x-amz-acl": "bucket-owner-full-control" } },
          "Principal": { "Service": "logs.us-east-1.amazonaws.com" }
      }
    ]
}

07, 13 라인 : S3 버킷 이름 수정

08, 15 라인 : Region 이름 수정

 

 

 


by mkdir-chandler


 

 

 

 

 

728x90
반응형

'Ops > AWS' 카테고리의 다른 글

AWS IAM Policy - lambda edge  (0) 2023.09.03
AWS IAM Policy - file download from S3 on EC2  (0) 2023.09.02
AWS IAM Policy - EC2 monitoring on CloudWatch  (0) 2023.08.31
AWS IAM Policy - console ip 제한  (0) 2023.08.30
AWS IAM Policy - inline policies  (0) 2023.08.29