Description
Connecting CloudTrail to CloudWatch Logs makes delivered events available for searches, metric filters, and alarms. S3 log storage and other analysis paths can still be used without this integration.
Potential impact
In an environment relying on CloudWatch monitoring, missing delivery can delay event analysis and alerts.
Remediation
Set CloudWatchLogsLogGroupArn and CloudWatchLogsRoleArn, and grant the required write permissions. Configure metric filters, alarms, and log retention separately.
Examples
The examples connect a log group and role to an existing trail. Replace the ARNs with actual resources and check the role’s trust policy and write permissions.
Before
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
After
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
CloudWatchLogsLogGroupArn: arn:aws:logs:us-west-2:123456789012:log-group:CloudTrail/DefaultLogGroup:*
CloudWatchLogsRoleArn: arn:aws:iam::123456789012:role/CloudTrailToCloudWatchLogsRole