CloudTrail SNS notification topic not configured

Connect an SNS topic when log-file delivery notifications are needed.

Description

CloudTrail SNS notifications announce that log files have been delivered to an S3 bucket. They are not immediate alerts for individual security events; configure a topic for workflows that need these delivery notifications.

Potential impact

A workflow relying on SNS notifications may not start processing new log files without a topic.

Remediation

Set SnsTopicName to the intended topic, and configure CloudTrail’s publishing permission and subscriptions. Verify that notifications arrive after log delivery.

Examples

The examples connect a separately defined Topic to an existing trail. Topic policies and subscriptions are omitted from these excerpts.

Before

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      IsLogging: true
      IsMultiRegionTrail: true

After

yaml
Resources:
  Trail:
    Type: AWS::CloudTrail::Trail
    Properties:
      S3BucketName: !Ref LogBucket
      SnsTopicName: !GetAtt Topic.TopicName
      IsLogging: true
      IsMultiRegionTrail: true

References