Description
Without a CloudWatch Logs integration, CloudTrail logs are unavailable through that path for log searches and metric filters. CloudTrail can still store logs in S3 independently.
Potential impact
If monitoring relies on CloudWatch, gaps can occur in identifying important events and turning them into alarms.
Remediation
Set cloud_watch_logs_group_arn and cloud_watch_logs_role_arn, and grant the role permission to deliver logs. Configure the metric filters and alarms you need.
Examples
The examples add CloudWatch Logs delivery to an existing trail. Create the log group and role separately; delivery can be delayed.
Before
hcl
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.foo.id
s3_key_prefix = "prefix"
include_global_service_events = false
}
After
hcl
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.foo.id
s3_key_prefix = "prefix"
include_global_service_events = false
cloud_watch_logs_group_arn = "${aws_cloudwatch_log_group.cloudtrail_log_group.arn}:*"
cloud_watch_logs_role_arn = aws_iam_role.cloud_watch_logs_role.arn
}