Review CloudTrail regional and global-event coverage

Include the Regions and global service events required for auditing.

Description

A single-Region trail does not cover activity in other Regions. Disabling global service events further narrows the audit coverage available through that trail.

Potential impact

Unless other trails or collection systems provide coverage, investigating some regional and global service activity can be harder.

Remediation

For audit coverage across Regions, set is_multi_region_trail = true and include_global_service_events = true. Also verify the required event types and selectors.

Examples

The examples expand coverage while retaining the same log bucket. A multi-Region trail covers Regions enabled in the account; it does not automatically select all data events.

Before

hcl
resource "aws_cloudtrail" "example" {
  name                  = "trail"
  s3_bucket_name        = "bucketlog-2"
  is_multi_region_trail = false
}

After

hcl
resource "aws_cloudtrail" "example" {
  name                          = "trail"
  s3_bucket_name                = "bucketlog-2"
  is_multi_region_trail         = true
  include_global_service_events = true
}

References