> For the complete documentation index, see [llms.txt](https://docs.getlimy.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.getlimy.ai/limy-pixel/cdn-integration/amazon-cloudfront.md).

# Amazon CloudFront

### Overview <a href="#overview" id="overview"></a>

This integration uses Amazon Data Firehose to deliver CloudFront logs directly to our Agent Monitor. Amazon Data Firehose (formerly Kinesis Data Firehose) is a fully managed AWS service for loading streaming data into a variety of destinations, including HTTP endpoints.

For additional details, refer to the[ AWS documentation](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/real-time-logs.html).

### Setup <a href="#configuration" id="configuration"></a>

{% stepper %}
{% step %}
Log into your AWS Console and head over to the Amazon Data Firehose section. This is where we'll create the pipeline that sends you to Limy.

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FP3iItMIl0P4wEGa2AzMv%2FScreenshot%202025-11-18%20at%2011.36.43.png?alt=media&amp;token=438d63d9-e71b-43b1-b6db-5e0db7cf59be" alt=""><figcaption></figcaption></figure>

<br>
{% endstep %}

{% step %}
Click to create a new delivery stream and configure it with these settings:

* **Source:** Choose "Direct PUT"
* **Destination:** Select "HTTP Endpoint"\
  These settings tell Data Firehose to accept data directly and send it to an HTTP endpoint (which will be Limy's API).
* **Content encoding:** Choose "Disabled"

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FgRcTX1CooVF1YkJHObBB%2FScreenshot%202025-11-18%20at%2011.39.35.png?alt=media&amp;token=5646875e-465e-4be4-a9b7-0c214d23abc1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Now for the important part - connecting to Limy:

```
https://stream.getlimy.ai
```

**Authentication:** You'll need to provide your Limy key as the access key. We strongly recommend using AWS Secrets Manager to store this securely.

Create a secret in AWS Secrets Manager with this JSON structure:

```json
{ "api_key": "your_limy_api_key" }
```

{% hint style="warning" %}
I**mportant Settings:**\
**Backup S3 Bucket:**\
AWS requires you to specify an S3 bucket for failed deliveries. Create a new bucket or select an existing one - this is just for error cases.
{% endhint %}

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FHLWrGiWUEUUynZVSGnr3%2FScreenshot%202025-11-18%20at%2011.44.11.png?alt=media&amp;token=9739c6b7-ecf9-4813-b333-6f68ff706960" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Navigate to your CloudFront distribution in the AWS Console and click over to the "Logging" tab. Hit the "Add" button and choose "Kinesis Data Firehose" as your destination.

{% hint style="warning" %}
**Note:**

You might see it called "Kinesis Data Firehose" in CloudFront even though AWS renamed it to Amazon Data Firehose - they're the same thing.
{% endhint %}

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FFq8zcTPfkkXLhjFWLCiv%2FScreenshot%202025-11-18%20at%2011.46.01.png?alt=media&amp;token=7a9b6194-7eda-4ba7-96d1-9b9d7af8952c" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
You'll be on the "Add standard logging destination" screen now. Pick the delivery stream you just created, then scroll down to "Additional settings - optional" and select these fields:

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FQE4kK6BoIxm3NtU9PffM%2Fimage%20(11).png?alt=media&amp;token=9611668c-b570-4156-a25c-03133b14cc27" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FhN4Xi8WrHqGO3jOgBNiJ%2Fimage%20(8).png?alt=media&amp;token=5e790079-48d5-4790-8ebc-c4f428b14e53" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FF8EUrZokSPDo6R4sYIrO%2Fimage%20(9).png?alt=media&amp;token=3a95db31-b8e5-4eaa-bd6b-7dc410c36a7c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FhN4Xi8WrHqGO3jOgBNiJ%2Fimage%20(8).png?alt=media&amp;token=5e790079-48d5-4790-8ebc-c4f428b14e53" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2FHVnLHw7lLEBcVxOrv7zX%2Fimage%20(7).png?alt=media&amp;token=da078f71-04d0-4c62-b94b-10e55ec58689" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Under "Output format", select **JSON**. This ensures the data is structured properly for Limy to process.

<figure><img src="https://3264818889-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfwoYt71NlEqR8u7MWxGE%2Fuploads%2F1d87yfrvx6oP3SuHsMOR%2FScreenshot%202025-11-18%20at%2012.16.22.png?alt=media&amp;token=2fb9bc56-82d9-49f9-982e-f3c5e9ff5ed9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Add the `LogDeliveryEnabled = true`  Tag

In order to enable the log delivery, the Kinesis firehose must have this tag included.

{% endstep %}
{% endstepper %}

### Need More Help?

* Contact `answers@limy.ai` for any further questions
