Description
A single-Region trail does not provide coverage of regional activity across all AWS Regions. A multi-Region trail helps collect events across the Regions enabled in the account.
Potential impact
Missing activity from Regions outside the audit scope can make account-wide change and incident investigations harder.
Remediation
Set IsMultiRegionTrail: true when logging across Regions is required. Check event selectors to include the required management and data events.
Examples
The examples expand the trail’s regional scope. The multi-Region setting alone does not automatically collect every data event.
Before
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: false
After
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true