AWS CloudTrail
AWS CloudTrail records the activity in an AWS account: every call to the AWS API, made from the console, the CLI, an SDK, Terraform or another AWS service, is an event with the identity, the time, the source IP address, the action, the resources and the result.
Key concepts #
- Event history: the last 90 days of management events, searchable in the console at no cost.
- Trail: delivers the events to an S3 bucket (optionally also to CloudWatch Logs) for long-term storage. A trail can cover all the Regions and, with AWS Organizations, all the accounts.
- Event types: management events (control plane: creating an instance, changing a security group), data events (S3 object or Lambda invocation level, off by default, they have a cost) and Insights events (unusual activity).
- CloudTrail Lake: stores events in a queryable data store, with SQL.
- Log file validation detects changes in the delivered files; encrypt them with KMS and protect the bucket from deletion.
- Typical uses: security analysis (who deleted that resource?), compliance audits, detecting changes made outside of Terraform (drift) and alarms on sensitive events such as root user logins.
Pricing #
Management events: one copy in the event history and the first trail are free of charge; additional copies, data events, Insights and Lake have a cost. See the CloudTrail pricing.
With Terraform #
The resources are aws_cloudtrail, aws_cloudtrail_event_data_store and the bucket with its policy.
See also: AWS IAM.