CloudTrail log integrity digests are disabled

Generate digest files for verifying changes to CloudTrail logs.

Description

Enabling enable_log_file_validation makes CloudTrail provide signed digest files containing log-file hashes. When it is disabled, this integrity evidence is not generated for that period.

Potential impact

It can be harder to determine whether delivered logs were changed or deleted, limiting investigations and audits.

Remediation

Set enable_log_file_validation = true and retain both logs and digests. Perform the actual validation with a tool such as the AWS CLI.

Examples

Enabling this setting does not run validation or prevent log changes. The examples enable generation of the evidence used for validation.

Before

hcl
resource "aws_cloudtrail" "example" {
  name           = "example"
  s3_bucket_name = "bucketlog1"
}

After

hcl
resource "aws_cloudtrail" "example" {
  name                       = "example"
  s3_bucket_name             = "bucketlog1"
  enable_log_file_validation = true
}

References