Optional
Readonly
enable(OPTIONAL) Enable site-to-site VPN tunnel logging to CloudWatch Logs.
Optional
Readonly
log(OPTIONAL) The name of the CloudWatch Logs log group that you would like tunnel logs to be sent to.
Default - Randomly generated name based on CDK stack and VPN resource name.
Optional
Readonly
output(OPTIONAL) The output format of the VPN tunnel logs.
Default - json
NetworkConfig / CustomerGatewayConfig / VpnConnectionConfig / VpnTunnelOptionsSpecificationsConfig / VpnLoggingConfig
AWS Site-to-Site VPN logging configuration.
Description
Use this configuration to define CloudWatch log groups for your Site-to-Site VPN connections. AWS Site-to-Site VPN logs provide you with deeper visibility into your Site-to-Site VPN deployments. With this feature, you have access to Site-to-Site VPN connection logs that provide details on IP Security (IPsec) tunnel establishment, Internet Key Exchange (IKE) negotiations, and dead peer detection (DPD) protocol messages.
Example
Custom settings:
Default settings: