CloudTrail log file validation disabled

Use signed digests to verify CloudTrail log integrity.

Description

Enabling CloudTrail log file validation produces signed digest files that can be used to check whether logs were changed or deleted. This setting alone neither prevents tampering nor runs validation automatically.

Potential impact

Without digests, establishing that collected logs have not been changed or deleted can be harder.

Remediation

Set EnableLogFileValidation: true and retain the logs and digests. Use CloudTrail’s validation tools to check integrity when needed.

Examples

The examples enable digest generation for an existing trail. Configure the log bucket and access policies separately.

Before

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true
      EnableLogFileValidation: false

After

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true
      EnableLogFileValidation: true

References