ansible/test/integration/targets/cloudtrail/templates/cloudwatch-policy.j2
2019-09-20 18:46:37 -07:00

17 lines
485 B
Django/Jinja

{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "CloudTrail2CloudWatch",
"Effect": "Allow",
"Action": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": [
"arn:aws:logs:{{ aws_region }}:{{ aws_caller_info.account }}:log-group:{{ cloudwatch_log_group }}:log-stream:*",
"arn:aws:logs:{{ aws_region }}:{{ aws_caller_info.account }}:log-group:{{ cloudwatch_log_group }}-2:log-stream:*"
]
}
]
}