Description
When a CloudTrail trail has IsLogging set to false, event recording and log file delivery for that trail stop. This can leave gaps in change investigations or long-term audit records that depend on the trail.
The separate 90-day management event history and records from other trails remain available. Configure the required data events and Regions separately through event selection and related settings.
Potential impact
- Activity during the interruption may be unavailable in that trail’s log files.
- Audit records needed for long-term retention may be missing.
Remediation
Set IsLogging to true for required trails and verify S3 destination permissions and actual log delivery. Configure event types, Regions, retention and log access for the audit purpose. Apply log file integrity validation and alerts as needed.
Examples
These excerpts show part of the same trail. Prepare AuditBucket and a bucket policy allowing CloudTrail log delivery separately.
Before
Resources:
AuditTrail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref AuditBucket
IsLogging: false
IsMultiRegionTrail: true
This stops log delivery for the trail. The multi-Region setting does not enable recording by itself.
After
Resources:
AuditTrail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref AuditBucket
IsLogging: true
IsMultiRegionTrail: true
EnableLogFileValidation: true
This enables delivery and generation of digest files for integrity validation. Integrity validation does not replace access controls that prevent log deletion or modification.