By Implementation

Service Control PoliciesConfig RulesAuto Remediation RulesConformance PacksAmazon GuardDutyAmazon InspectorAWS Security HubAWS Network FirewallRoute53 Resolver SecurityAmazon MacieS3 Bucket PoliciesCloudWatch Alarms and Event RulesAWS WAFAWS Secrets ManagerAWS Systems ManagerSecurity Groups & NACLsAWS KMSIAM PoliciesAmazon ECRRDS Event Subscriptions

By Service Protected

Configuration Packages

Strategy Guides

Other

Route53 Resolver Security

VPC DNS Query Logging (Route53 Resolver Query Logging)

Configuration to enable logging the DNS queries that originate in an Amazon VPC using the Route53 Resolver Query Logging feature. Query logs can be sent to CloudWatch logs, S3 Buckets, or Kinesis Data Firehose

Provide the following details to configure Route53 Resolver Query Logging: 

  • VPC Id: The VPC Id for which DNS queries should be logged
  • Destination Arn: The ARN of the CloudWatch Log Group, S3 bucket, or Kinesis Data Firehose Delivery Stream
Items
2
Size
0.5 KB
Missing Parameters
AWSTemplateFormatVersion: "2010-09-09"
Description: ""
Resources:
  Route53QueryLoggingConfig:
    Type: "AWS::Route53Resolver::ResolverQueryLoggingConfig"
    Properties:
      DestinationArn: ""
  Route53QueryLoggingConfigAssociation:
    Type: "AWS::Route53Resolver::ResolverQueryLoggingConfigAssociation"
    Properties:
      ResolverQueryLogConfigId:
        Fn::GetAtt:
          - "Route53QueryLoggingConfig"
          - "Id"
      ResourceId: ""
Parameters: {}
Metadata: {}
Conditions: {}

Actions



Customize Template

* Required field