CloudTrail is not integrated with CloudWatch Logs

Configure CloudTrail delivery to analyze audit logs in CloudWatch.

Description

Without a CloudWatch Logs integration, CloudTrail logs are unavailable through that path for log searches and metric filters. CloudTrail can still store logs in S3 independently.

Potential impact

If monitoring relies on CloudWatch, gaps can occur in identifying important events and turning them into alarms.

Remediation

Set cloud_watch_logs_group_arn and cloud_watch_logs_role_arn, and grant the role permission to deliver logs. Configure the metric filters and alarms you need.

Examples

The examples add CloudWatch Logs delivery to an existing trail. Create the log group and role separately; delivery can be delayed.

Before

hcl
resource "aws_cloudtrail" "example" {
  name                          = "tf-trail-foobar"
  s3_bucket_name                = aws_s3_bucket.foo.id
  s3_key_prefix                 = "prefix"
  include_global_service_events = false
}

After

hcl
resource "aws_cloudtrail" "example" {
  name                          = "tf-trail-foobar"
  s3_bucket_name                = aws_s3_bucket.foo.id
  s3_key_prefix                 = "prefix"
  include_global_service_events = false
  cloud_watch_logs_group_arn    = "${aws_cloudwatch_log_group.cloudtrail_log_group.arn}:*"
  cloud_watch_logs_role_arn     = aws_iam_role.cloud_watch_logs_role.arn
}

References