Centralise S3 access logging in a Control Tower environment.


In a control tower environment, is it possible to have the S3 access logs from each account sent to a central bucket in the Log Archive account? Thanks, DJ

Yes this is possible. When setting up server access logging on your S3 buckets, be sure to specify a S3 bucket in the logging archive account.

Note, this setting is on a per bucket and not an account setting

