Description
Creating, updating, or deleting a trail and starting or stopping logging affect audit log collection. Configure notifications for these changes to identify unintended interruptions.
Potential impact
Without notifications, gaps caused by trail changes or stopped logging may remain unnoticed.
Remediation
Use a log metric filter for CreateTrail, UpdateTrail, DeleteTrail, StartLogging, and StopLogging events. Connect an alarm to the metric emitted by the filter and configure notification actions.
Examples
The examples connect the alarm to the correct metric. CloudTrail log delivery and notification recipients require separate configuration.
Before
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-CloudTrailChanges"
pattern = "{ ($.eventName = CreateTrail) || ($.eventName = UpdateTrail) || ($.eventName = DeleteTrail) || ($.eventName = StartLogging) || ($.eventName = StopLogging) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-CloudTrailChanges"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.5-CloudTrailChanges"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = "XXXX NOT YOUR FILTER XXXX"
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}
After
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-CloudTrailChanges"
pattern = "{ ($.eventName = CreateTrail) || ($.eventName = UpdateTrail) || ($.eventName = DeleteTrail) || ($.eventName = StartLogging) || ($.eventName = StopLogging) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-CloudTrailChanges"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.5-CloudTrailChanges"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = aws_cloudwatch_log_metric_filter.example.id
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}