Description
Enabling CloudTrail log file validation produces signed digest files that can be used to check whether logs were changed or deleted. This setting alone neither prevents tampering nor runs validation automatically.
Potential impact
Without digests, establishing that collected logs have not been changed or deleted can be harder.
Remediation
Set EnableLogFileValidation: true and retain the logs and digests. Use CloudTrail’s validation tools to check integrity when needed.
Examples
The examples enable digest generation for an existing trail. Configure the log bucket and access policies separately.
Before
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
EnableLogFileValidation: false
After
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
EnableLogFileValidation: true