Description
Enabling enable_log_file_validation makes CloudTrail provide signed digest files containing log-file hashes. When it is disabled, this integrity evidence is not generated for that period.
Potential impact
It can be harder to determine whether delivered logs were changed or deleted, limiting investigations and audits.
Remediation
Set enable_log_file_validation = true and retain both logs and digests. Perform the actual validation with a tool such as the AWS CLI.
Examples
Enabling this setting does not run validation or prevent log changes. The examples enable generation of the evidence used for validation.
Before
hcl
resource "aws_cloudtrail" "example" {
name = "example"
s3_bucket_name = "bucketlog1"
}
After
hcl
resource "aws_cloudtrail" "example" {
name = "example"
s3_bucket_name = "bucketlog1"
enable_log_file_validation = true
}