CloudTrail log-delivery notification topic is not configured

Connect an SNS topic when log-delivery notifications are needed.

Description

CloudTrail SNS notifications announce that log files were delivered to S3. They do not classify individual security events or provide immediate event-specific alarms.

Potential impact

Log-processing or delivery-check workflows that depend on SNS notifications may not run.

Remediation

Specify the topic name in sns_topic_name when delivery notifications are needed. Verify CloudTrail’s publishing permission, subscriptions, and actual notification delivery.

Examples

The examples replace a missing or empty topic setting with an actual SNS topic name. Subscription configuration is omitted.

Before

yaml
- name: Create CloudTrail
  community.aws.cloudtrail:
    state: present
    name: default
    s3_bucket_name: mylogbucket
    s3_key_prefix: cloudtrail
    region: us-east-1

- name: Create CloudTrail2
  community.aws.cloudtrail:
    state: present
    name: default
    s3_bucket_name: mylogbucket
    s3_key_prefix: cloudtrail
    region: us-east-1
    sns_topic_name:

After

yaml
- name: Create CloudTrail
  community.aws.cloudtrail:
    state: present
    name: default
    s3_bucket_name: mylogbucket
    s3_key_prefix: cloudtrail
    region: us-east-1
    sns_topic_name: some_topic_name

References