Skip to content

CKV_AWS_86 only validates v1 logging, not v2 #7385

Description

@Atachi

Describe the issue
In CKV_AWS_86 only the old v1 logging of a CloudFront distribution will be validated.
If one uses v2 logging, it complains.

Version (please complete the following information):

  • Checkov Docker Image Tag 3.2.495

Additional context
See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudfront_distribution#with-v2-logging-to-s3 for a valid configuration.

Activity

  1. stale commented on May 28, 2026

    @stale

    Thanks for contributing to Checkov! We've automatically marked this issue as stale to keep our issues list tidy, because it has not had any activity for 6 months. It will be closed in 14 days if no further activity occurs. Commenting on this issue will remove the stale tag. If you want to talk through the issue or help us understand the priority and context, feel free to add a comment or join us in the Checkov slack channel at codifiedsecurity.slack.com
    Thanks!

  2. stale commented on Jun 14, 2026

    @stale

    Closing issue due to inactivity. If you feel this is in error, please re-open, or reach out to the community via slack: codifiedsecurity.slack.com Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    checksCheck additions or changesstale

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions