CloudTrail trail logging is stopped

Enable log delivery for the CloudTrail trails you need.

Description

When enable_logging is disabled on a CloudTrail trail, that trail stops recording events and delivering log files. The separate 90-day history of management events remains available, but it does not replace a long-term audit record.

Potential impact

Security analysis and change tracking that depend on the trail can have gaps, including missing required data events or long-term records.

Remediation

Enable enable_logging and verify destination permissions and actual log delivery. Configure events and regions to meet the audit purpose.

Examples

The examples use an existing S3 bucket with permissions for log delivery. Set audit_bucket to the actual bucket name and configure required event selectors separately.

Before

yaml
- name: example
  amazon.aws.cloudtrail:
    state: present
    name: default
    s3_bucket_name: "{{ audit_bucket }}"
    enable_logging: false

After

yaml
- name: example
  amazon.aws.cloudtrail:
    state: present
    name: default
    s3_bucket_name: "{{ audit_bucket }}"
    enable_logging: true

References