Network Firewall logging should be enabled

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This control verifies whether at least one type of logging is enabled for an AWS Network Firewall.

Enabling logging is essential for ensuring the reliability, availability, and performance of your firewalls. AWS Network Firewall logging provides detailed insights into network traffic, including timestamps of when the stateful engine processed a packet flow, detailed packet flow information, and any actions taken by stateful rules against the packet flow.

Remediation

For guidance on configuring firewall logging, please refer to the Updating a firewall’s logging configuration section of the AWS Network Firewall Developer Guide.