How to enable logging for WebACL in AWS WAF using Cloudformation?

Viewed 1894

I was going through AWS WAF Cloudformation documentation and I couldn't see a way to enable logging. I can enable logging by console, however I want to do it by Cloudformation so that it is enabled by default in new stacks.

How do I enable logging in AWS WAF WebACL by Cloudformation.

Thanks

4 Answers

It's not available at the moment but it is possible to use AWS Config to set up logging as new web ACLs are created.

AWS WAF Security Automations has used lambda to sovle this.

   ConfigureAWSWAFLogs:
    Type: 'Custom::ConfigureAWSWAFLogs'
    Condition: HttpFloodProtectionLogParserActivated
    Properties:
      ServiceToken: !GetAtt CustomResource.Arn
      WAFWebACLArn: !GetAtt WebACLStack.Outputs.WAFWebACLArn
      DeliveryStreamArn: !GetAtt FirehoseAthenaStack.Outputs.FirehoseWAFLogsDeliveryStreamArn

CustomResource lambda funtion

elif event['ResourceType'] == "Custom::ConfigureAWSWAFLogs":
            if 'CREATE' in request_type:
                put_logging_configuration(log, event['ResourceProperties']['WAFWebACLArn'],
                                          event['ResourceProperties']['DeliveryStreamArn'])

check it out at https://github.com/awslabs/aws-waf-security-automations

It's already available. Official documentation here

Related release note for added support (CloudWatch and S3) here

Related