Skip to main content

delivery_destination_policies

Creates, updates, deletes, gets or lists a delivery_destination_policies resource.

Overview

Namedelivery_destination_policies
TypeResource
Idaws.logs.delivery_destination_policies

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
delivery_destination_policystringThe contents of the delivery destination policy.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
get_delivery_destination_policyselectregionRetrieves the delivery destination policy assigned to the delivery destination that you specify. For more information about delivery destinations and their policies, see PutDeliveryDestinationPolicy.
put_delivery_destination_policyreplaceregion, deliveryDestinationName, deliveryDestinationPolicyCreates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account. To configure the delivery of logs from an Amazon Web Services service in another account to a logs delivery destination in the current account, you must do the following: Create a delivery source, which is a logical object that represents the resource that is actually sending the logs. For more information, see PutDeliverySource. Create a delivery destination, which is a logical object that represents the actual delivery destination. For more information, see PutDeliveryDestination. Use this operation in the destination account to assign an IAM policy to the destination. This policy allows delivery to that destination. Create a delivery by pairing exactly one delivery source and one delivery destination. For more information, see CreateDelivery. Only some Amazon Web Services services support being configured as a delivery source. These services are listed as Supported [V2 Permissions] in the table at Enabling logging from Amazon Web Services services. The contents of the policy must include two statements. One statement enables general logs delivery, and the other allows delivery to the chosen destination. See the examples for the needed policies.
delete_delivery_destination_policydeleteregionDeletes a delivery destination policy. For more information about these policies, see PutDeliveryDestinationPolicy.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
regionstringAWS region (default: us-east-1)

SELECT examples

Retrieves the delivery destination policy assigned to the delivery destination that you specify. For more information about delivery destinations and their policies, see PutDeliveryDestinationPolicy.

SELECT
delivery_destination_policy
FROM aws.logs.delivery_destination_policies
WHERE region = '{{ region }}' -- required
;

REPLACE examples

Creates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account. To configure the delivery of logs from an Amazon Web Services service in another account to a logs delivery destination in the current account, you must do the following: Create a delivery source, which is a logical object that represents the resource that is actually sending the logs. For more information, see PutDeliverySource. Create a delivery destination, which is a logical object that represents the actual delivery destination. For more information, see PutDeliveryDestination. Use this operation in the destination account to assign an IAM policy to the destination. This policy allows delivery to that destination. Create a delivery by pairing exactly one delivery source and one delivery destination. For more information, see CreateDelivery. Only some Amazon Web Services services support being configured as a delivery source. These services are listed as Supported [V2 Permissions] in the table at Enabling logging from Amazon Web Services services. The contents of the policy must include two statements. One statement enables general logs delivery, and the other allows delivery to the chosen destination. See the examples for the needed policies.

REPLACE aws.logs.delivery_destination_policies
SET
deliveryDestinationName = '{{ deliveryDestinationName }}',
deliveryDestinationPolicy = '{{ deliveryDestinationPolicy }}'
WHERE
region = '{{ region }}' --required
AND deliveryDestinationName = '{{ deliveryDestinationName }}' --required
AND deliveryDestinationPolicy = '{{ deliveryDestinationPolicy }}' --required
RETURNING
policy;

DELETE examples

Deletes a delivery destination policy. For more information about these policies, see PutDeliveryDestinationPolicy.

DELETE FROM aws.logs.delivery_destination_policies
WHERE region = '{{ region }}' --required
;