Terraform: configuring cloudwatch log subscription delivery to lambda?

前端 未结 2 1161
-上瘾入骨i
-上瘾入骨i 2020-12-29 03:30

I need to ship my cloudwatch logs to a log analysis service.

I\'ve followed along with these articles here and here and got it working by hand, no worries.

2条回答
  •  攒了一身酷
    2020-12-29 04:08

    I had the aws_cloudwatch_log_subscription_filter resource defined incorrectly - you should not provide the role_arn argument in this situation.

    You also need to add an aws_lambda_permission resource (with a depends_on relationship defined on the filter or TF may do it in the wrong order).

    Note that the AWS lambda console UI adds the lambda permission for you invisibly, so beware that the aws_cloudwatch_log_subscription_filter will work without the permission resource if you happen to have done the same action before in the console UI.

    The necessary TF config looks like this (the last two resources are the relevant ones for configuring the actual cloudwatch->lambda trigger):

    // intended for application logs (access logs, modsec, etc.)
    resource "aws_cloudwatch_log_group" "test-app-loggroup" {
      name              = "test-app"
      retention_in_days = 90
    }
    
    resource "aws_security_group" "cloudwatch-sumologic-lambda-sg" {
      name = "cloudwatch-sumologic-lambda-sg"
    
      tags {
        Name = "cloudwatch-sumologic-lambda-sg"
      }
    
      description = "Security group for lambda to move logs from CWL to SumoLogic"
      vpc_id      = "${aws_vpc.dev-vpc.id}"
    }
    
    resource "aws_security_group_rule" "https-egress-cloudwatch-sumologic-to-internet" {
      type              = "egress"
      from_port         = 443
      to_port           = 443
      protocol          = "tcp"
      security_group_id = "${aws_security_group.cloudwatch-sumologic-lambda-sg.id}"
      cidr_blocks       = ["0.0.0.0/0"]
    }
    
    resource "aws_iam_role" "test-cloudwatch-lambda-role" {
      name = "test-cloudwatch-lambda-role"
    
      assume_role_policy = <

    EDIT: Please note that the above TF code was written years ago, using version 0.11.x - it should still work but there may be better ways of doing things. Specifically, don't use an inline policy like this unless needed, use an aws_iam_policy_document instead - they're just way easier to maintain over time.

提交回复
热议问题