Description
A single-Region trail does not cover activity in other Regions. Disabling global service events further narrows the audit coverage available through that trail.
Potential impact
Unless other trails or collection systems provide coverage, investigating some regional and global service activity can be harder.
Remediation
For audit coverage across Regions, set is_multi_region_trail = true and include_global_service_events = true. Also verify the required event types and selectors.
Examples
The examples expand coverage while retaining the same log bucket. A multi-Region trail covers Regions enabled in the account; it does not automatically select all data events.
Before
hcl
resource "aws_cloudtrail" "example" {
name = "trail"
s3_bucket_name = "bucketlog-2"
is_multi_region_trail = false
}
After
hcl
resource "aws_cloudtrail" "example" {
name = "trail"
s3_bucket_name = "bucketlog-2"
is_multi_region_trail = true
include_global_service_events = true
}