CloudTrail trail logging is stopped

Enable event recording and log delivery for CloudTrail trails needed for auditing.

Description

When a CloudTrail trail has IsLogging set to false, event recording and log file delivery for that trail stop. This can leave gaps in change investigations or long-term audit records that depend on the trail.

The separate 90-day management event history and records from other trails remain available. Configure the required data events and Regions separately through event selection and related settings.

Potential impact

  • Activity during the interruption may be unavailable in that trail’s log files.
  • Audit records needed for long-term retention may be missing.

Remediation

Set IsLogging to true for required trails and verify S3 destination permissions and actual log delivery. Configure event types, Regions, retention and log access for the audit purpose. Apply log file integrity validation and alerts as needed.

Examples

These excerpts show part of the same trail. Prepare AuditBucket and a bucket policy allowing CloudTrail log delivery separately.

Before

yaml
Resources:
  AuditTrail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref AuditBucket
      IsLogging: false
      IsMultiRegionTrail: true

This stops log delivery for the trail. The multi-Region setting does not enable recording by itself.

After

yaml
Resources:
  AuditTrail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref AuditBucket
      IsLogging: true
      IsMultiRegionTrail: true
      EnableLogFileValidation: true

This enables delivery and generation of digest files for integrity validation. Integrity validation does not replace access controls that prevent log deletion or modification.

References