Skip to content

/AWS1/CL_R5R=>CREATERESOLVERQUERYLOGCONFIG()

About CreateResolverQueryLogConfig

Creates a Resolver query logging configuration, which defines where you want Resolver to save DNS query logs that originate in your VPCs. Resolver can log queries only for VPCs that are in the same Region as the query logging configuration.

To specify which VPCs you want to log queries for, you use AssociateResolverQueryLogConfig. For more information, see AssociateResolverQueryLogConfig.

You can optionally use Resource Access Manager (RAM) to share a query logging configuration with other Amazon Web Services accounts. The other accounts can then associate VPCs with the configuration. The query logs that Resolver creates for a configuration include all DNS queries that originate in all VPCs that are associated with the configuration.

Method Signature

IMPORTING

Required arguments:

IV_NAME TYPE /AWS1/R5RRESOLVERQUERYLOGCFG03 /AWS1/R5RRESOLVERQUERYLOGCFG03

The name that you want to give the query logging configuration.

IV_DESTINATIONARN TYPE /AWS1/R5RDESTINATIONARN /AWS1/R5RDESTINATIONARN

The ARN of the resource that you want Resolver to send query logs. You can send query logs to an S3 bucket, a CloudWatch Logs log group, or a Kinesis Data Firehose delivery stream. Examples of valid values include the following:

  • S3 bucket:

    arn:aws:s3:::examplebucket

    You can optionally append a file prefix to the end of the ARN.

    arn:aws:s3:::examplebucket/development/

  • CloudWatch Logs log group:

    arn:aws:logs:us-west-1:123456789012:log-group:/mystack-testgroup-12ABC1AB12A1:*

  • Kinesis Data Firehose delivery stream:

    arn:aws:kinesis:us-east-2:0123456789:stream/my_stream_name

IV_CREATORREQUESTID TYPE /AWS1/R5RCREATORREQUESTID /AWS1/R5RCREATORREQUESTID

A unique string that identifies the request and that allows failed requests to be retried without the risk of running the operation twice. CreatorRequestId can be any unique string, for example, a date/time stamp.

Optional arguments:

IT_TAGS TYPE /AWS1/CL_R5RTAG=>TT_TAGLIST TT_TAGLIST

A list of the tag keys and values that you want to associate with the query logging configuration.

RETURNING

OO_OUTPUT TYPE REF TO /AWS1/CL_R5RCRERESOLVERQUERY01 /AWS1/CL_R5RCRERESOLVERQUERY01