data "aws_caller_identity" "current" {}
data "aws_region" "current" {}
module "secure-baseline" {
source = "nozaq/secure-baseline/aws"
version = "0.9.0"
# insert the 4 required variables here
audit_log_bucket_name = "${var.client}.${var.stage}-cloudwatch-logs"
aws_account_id = "${data.aws_caller_identity.current.account_id}"
region = "${data.aws_region.current.name}"
support_iam_role_principal_arn = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:role/SomethingSomethingAdministrator"
}
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 39236d11-5b8d-11e9-b912-db18f0fda047: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_ap-south-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 394c2a9a-5b8d-11e9-82f0-079f92f291ce: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_us-east-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 3927d9c8-5b8d-11e9-82f0-079f92f291ce: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.guardduty_baseline_us-east-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 388cd2a0-5b8d-11e9-bcba-f9c17b376a5f
* module.secure-baseline.module.guardduty_baseline_ap-southeast-2.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 39326183-5b8d-11e9-8260-13e36b5f3390
* module.secure-baseline.module.guardduty_baseline_ap-northeast-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 3948a815-5b8d-11e9-9ecc-ddb290e7f0c2
* module.secure-baseline.module.vpc_baseline_ap-northeast-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 393fa81a-5b8d-11e9-a0f1-b3dd1ae35edf: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.guardduty_baseline_us-east-2.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 38e26bff-5b8d-11e9-a515-737af496302a
* module.secure-baseline.module.vpc_baseline_us-east-2.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 392282d6-5b8d-11e9-b852-5ff5b1767983: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.audit_log_bucket.aws_s3_bucket.access_log: 1 error(s) occurred:
* aws_s3_bucket.access_log: Error creating S3 bucket: BucketAlreadyOwnedByYou: Your previous request to create the named bucket succeeded and you already own it.
status code: 409, request id: 8665EC6287ABDA3E, host id: 64W3mdLPTgyjx0YjOcV7yUM1JgZzciz3+QGRMSDRynHJ/KFEB+oDdkWZtHcVxda88ACjs7sJMHY=
* module.secure-baseline.module.guardduty_baseline_us-west-2.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 38f2e738-5b8d-11e9-85e3-dbb00e6dba04
* module.secure-baseline.module.guardduty_baseline_ap-southeast-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 38d06a98-5b8d-11e9-962a-f7841804025e
* module.secure-baseline.module.guardduty_baseline_ap-northeast-2.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 3922aa05-5b8d-11e9-93fe-af52707faa87
* module.secure-baseline.module.guardduty_baseline_eu-central-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 39376a98-5b8d-11e9-af5f-b36cc1cb7a95
* module.secure-baseline.module.guardduty_baseline_ap-south-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 394d3ca8-5b8d-11e9-b7b0-8d305d83bc6b
* module.secure-baseline.module.guardduty_baseline_eu-west-3.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 3943ed87-5b8d-11e9-bb7c-f1886c601912
* module.secure-baseline.module.vpc_baseline_ap-southeast-2.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 393287eb-5b8d-11e9-90e6-bd28cc14ba49: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.aws_iam_role.recorder: 1 error(s) occurred:
* aws_iam_role.recorder: Error creating IAM Role Config-Recorder: EntityAlreadyExists: Role with name Config-Recorder already exists.
status code: 409, request id: 38b716a2-5b8d-11e9-85bf-f1422f566699
* module.secure-baseline.module.vpc_baseline_sa-east-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 39245743-5b8d-11e9-95f3-a7b2d1ae7ec7: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.guardduty_baseline_eu-west-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 39426730-5b8d-11e9-93fe-af52707faa87
* module.secure-baseline.module.vpc_baseline_us-west-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 3931c51e-5b8d-11e9-ac40-a1deac0117ba: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_us-west-2.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 3925ddf4-5b8d-11e9-96f5-e7fe73a60eee: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_eu-west-2.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 3931501b-5b8d-11e9-b912-db18f0fda047: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_eu-north-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 39231f1b-5b8d-11e9-b852-5ff5b1767983: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_eu-west-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 393fa81b-5b8d-11e9-a0f1-b3dd1ae35edf: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.guardduty_baseline_us-west-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 388e5915-5b8d-11e9-a3cd-274b24e3c410
* module.secure-baseline.module.vpc_baseline_eu-west-3.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 39465e13-5b8d-11e9-82f0-079f92f291ce: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.vpc_baseline_ap-northeast-2.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 39236d23-5b8d-11e9-a00b-3721a4259847: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.guardduty_baseline_ca-central-1.aws_guardduty_detector.default: 1 error(s) occurred:
* aws_guardduty_detector.default: Creating GuardDuty Detector failed: BadRequestException: The request is rejected because a detector already exists for the current account.
status code: 400, request id: 391b7d57-5b8d-11e9-8f4d-4f105a9996e8
* module.secure-baseline.module.vpc_baseline_eu-central-1.aws_cloudwatch_log_group.default_vpc_flow_logs: 1 error(s) occurred:
* aws_cloudwatch_log_group.default_vpc_flow_logs: Creating CloudWatch Log Group failed: ResourceAlreadyExistsException: The specified log group already exists
status code: 400, request id: 39376a86-5b8d-11e9-a0f1-b3dd1ae35edf: The CloudWatch Log Group 'default-vpc-flow-logs' already exists.
* module.secure-baseline.module.guardduty_baseline_eu-west-2.aws_guardduty_detector.default: 1 error(s) occurred:
We couldn't figure what happened here. Seek your assistance.