AWS CloudTrail logging disabled

Enable logging on the CloudTrail trail to deliver audit records.

Description

Stopping logging on a CloudTrail trail stops event delivery for that trail. It does not stop all account event history or other trails.

Potential impact

Audits and incident investigations that rely on this trail can have gaps in their records.

Remediation

Set enable_logging = true and verify delivery to the S3 bucket. If CloudWatch Logs is configured, check its delivery as well, and confirm that the required events and Regions are covered.

Examples

The examples disable or enable trail logging. The destination S3 bucket also needs a policy allowing CloudTrail to write logs.

Before

hcl
resource "aws_cloudtrail" "example" {
  name           = "trail-disabled"
  s3_bucket_name = "bucketlog"
  enable_logging = false
}

After

hcl
resource "aws_cloudtrail" "example" {
  name           = "trail-enabled"
  s3_bucket_name = "bucketlog"
  enable_logging = true
}

References