CloudTrail log-file delivery notifications are not configured

Associate an SNS topic when log-file arrival notifications are needed.

Description

CloudTrail’s optional sns_topic_name setting sends SNS notifications when new log files reach S3. It does not classify individual security events or raise security alerts.

Potential impact

Log-processing jobs that depend on these notifications may miss new arrivals. Check any alternative processing system if SNS notifications are not used.

Remediation

If file-delivery notifications are needed, configure sns_topic_name, permit CloudTrail to publish, and subscribe the receiving system.

Examples

The examples associate an SNS topic with an existing trail. Configure the topic and subscription separately, then confirm actual delivery notifications.

Before

hcl
resource "aws_cloudtrail" "example" {
  # ... other configuration ...
}

After

hcl
resource "aws_cloudtrail" "example" {
  # ... other configuration ...
  sns_topic_name = "some-topic"
}

References