CloudTrail multi-Region logging disabled

Configure the trail to record activity across the required Regions.

Description

A single-Region trail does not provide coverage of regional activity across all AWS Regions. A multi-Region trail helps collect events across the Regions enabled in the account.

Potential impact

Missing activity from Regions outside the audit scope can make account-wide change and incident investigations harder.

Remediation

Set IsMultiRegionTrail: true when logging across Regions is required. Check event selectors to include the required management and data events.

Examples

The examples expand the trail’s regional scope. The multi-Region setting alone does not automatically collect every data event.

Before

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: false

After

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true

References