wafv2-logging-enabled - Amazon Config
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

wafv2-logging-enabled

Checks if logging is enabled on Amazon WAFv2 regional and global web access control lists (web ACLs). The rule is NON_COMPLIANT if the logging is enabled but the logging destination does not match the value of the parameter.

Note

Amazon Security Lake Exception

This rule does not check logging done with Security Lake for Amazon WAFV2 web ACLs.

Identifier: WAFV2_LOGGING_ENABLED

Resource Types: AWS::WAFv2::WebACL

Trigger type: Periodic

Amazon Web Services Region: All supported Amazon regions except Asia Pacific (Thailand), Mexico (Central), Asia Pacific (Taipei) Region

Parameters:

KinesisFirehoseDeliveryStreamArns (Optional)
Type: CSV

Comma separated list of Kinesis Firehose delivery stream ARNs

Amazon CloudFormation template

To create Amazon Config managed rules with Amazon CloudFormation templates, see Creating Amazon Config Managed Rules With Amazon CloudFormation Templates.