Amazon recommends enabling logging for purposes such as security and access audits. These standard logs can be stored in an Amazon S3 bucket and can later be analyzed by products such as Amazon Athena. For more information, see the AWS documentation.
References:
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/logging.html
In AWS Console -
In Terraform -
References:
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/logging.html
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudfront_distribution