To enable server access logging for a bucket, select the name of the bucket.
Click Properties.
Click Server access logging.
Click Enable Logging.
📘 Notes
For the target, select the name of the bucket that you want to receive the log record objects.
The target bucket must be in the same Region as the source bucket and must not have a default retention period configuration.
Click Save.
CLI Command
The example below sets the logging policy for MyBucket. The AWS user bob@example.com will have full control over the log files, no one else has any access.