Description
CloudTrail SNS notifications announce that log files have been delivered to an S3 bucket. They are not immediate alerts for individual security events; configure a topic for workflows that need these delivery notifications.
Potential impact
A workflow relying on SNS notifications may not start processing new log files without a topic.
Remediation
Set SnsTopicName to the intended topic, and configure CloudTrail’s publishing permission and subscriptions. Verify that notifications arrive after log delivery.
Examples
The examples connect a separately defined Topic to an existing trail. Topic policies and subscriptions are omitted from these excerpts.
Before
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
IsLogging: true
IsMultiRegionTrail: true
After
yaml
Resources:
Trail:
Type: AWS::CloudTrail::Trail
Properties:
S3BucketName: !Ref LogBucket
SnsTopicName: !GetAtt Topic.TopicName
IsLogging: true
IsMultiRegionTrail: true