CloudTrail not integrated with CloudWatch Logs

Configure log delivery when CloudWatch is used to analyze audit events.

Description

Connecting CloudTrail to CloudWatch Logs makes delivered events available for searches, metric filters, and alarms. S3 log storage and other analysis paths can still be used without this integration.

Potential impact

In an environment relying on CloudWatch monitoring, missing delivery can delay event analysis and alerts.

Remediation

Set CloudWatchLogsLogGroupArn and CloudWatchLogsRoleArn, and grant the required write permissions. Configure metric filters, alarms, and log retention separately.

Examples

The examples connect a log group and role to an existing trail. Replace the ARNs with actual resources and check the role’s trust policy and write permissions.

Before

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true

After

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true
      CloudWatchLogsLogGroupArn: arn:aws:logs:us-west-2:123456789012:log-group:CloudTrail/DefaultLogGroup:*
      CloudWatchLogsRoleArn: arn:aws:iam::123456789012:role/CloudTrailToCloudWatchLogsRole

References