For our EC2 instances to be able to send session logs to an S3 bucket, we will need to update the IAM Role attached to the EC2 instances by adding a policy that allows access permissions to S3.
Access the IAM service management console

Click Attach policies.

In the Search box enter AmazonS3FullAccess.

In practice we will grant stricter permissions to the specified S3 bucket. Within the scope of this lab we use the AmazonS3FullAccess policy for convenience.
Next we will proceed to create an S3 bucket to store session logs.