To capture the ip addresses of clients in your web server access logs configure the following for application load balancers and classic load balancers with http https listeners the x forwarded for http header captures client ip addresses you can then configure your web server access logs to record these ip addresses.

Check the elb access log for duplicate http 502 errors 502 errors for both elb status code and backend status code indicate that there is a problem with one or more of the web server instances identify which web server instances are exhibiting the problem then check the web server logs of the backend web server instances.

Finally elb alb and nlb all export useful metrics to cloudwatch and can log pertinent information to cloudwatch logs something to keep in mind is that if you anticipate a sudden spike in traffic sale testing etc you might want to contact aws support to ldquo pre warm rdquo your load balancer.

