> For the complete documentation index, see [llms.txt](https://notes.radifine.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.radifine.com/aws/other-aws-services/logging-and-monitoring/aws-cloudtrail.md).

# AWS CloudTrail

AWS CloudTrail is an AWS Service that records all activities performed in an AWS account (via cli or Mgmt Console or SDKs). This logging and auditing service from AWS can also be integrated in SIEM Solution for helping not only in Visibility, Incident Response, Debugging as well as fulfil the compliance requirements.

Event Logging in AWS:

<figure><img src="/files/PwjrC8cVwuQVRJbuX33U" alt=""><figcaption><p>Source: <a href="https://quizlet.com/616135849/aws-cloudtrail-flash-cards/">https://quizlet.com/616135849/aws-cloudtrail-flash-cards/</a></p></figcaption></figure>

As shown above,  there are mainly two types of events, management events: (control plane operations) and data events (data plane operations) and both types of events will log AWS Account, User ID/Role, IP Address, Time and resource details etc.&#x20;

Events from 90 days can be viewed from Event History.

Some of the things that should be considered while setting up CloudTrail

* Not all services are supported
* Only 5 trails per region are allowed

The logs collected in CloudTrail can be used with S3, Lamda, Athena and even CloudWatch for analysing, storage etc.

### CloudTrail Creation:

To create an audit trail in this service, steps can be as follows:

<figure><img src="/files/pFBcCAWkyrPlxKw4RhJx" alt=""><figcaption></figcaption></figure>

Quick Trail Console:

<figure><img src="/files/F6XiKJ5fQG5ejqom0b6n" alt=""><figcaption></figcaption></figure>

More Detailed Console:

<figure><img src="/files/HK9RpH2GdDJYx2jOVnXg" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/HMxG2fAt1pN1XftnBMP0" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/pPHHCGQuxqZQhix8ZMB3" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/jCp6mmXiJYQszzsvxDlj" alt=""><figcaption></figcaption></figure>

Finally create the trail:

<figure><img src="/files/xwuLFblAxe5KIOZ7U9c0" alt=""><figcaption></figcaption></figure>

Event History would look something like this:

<figure><img src="/files/45iDBYsTlMU239AMcEsg" alt=""><figcaption></figcaption></figure>
