CloudWatch alarm missing for CloudTrail changes

Monitor CloudTrail configuration changes and logging stops.

Description

Creating, updating, or deleting a trail and starting or stopping logging affect audit log collection. Configure notifications for these changes to identify unintended interruptions.

Potential impact

Without notifications, gaps caused by trail changes or stopped logging may remain unnoticed.

Remediation

Use a log metric filter for CreateTrail, UpdateTrail, DeleteTrail, StartLogging, and StopLogging events. Connect an alarm to the metric emitted by the filter and configure notification actions.

Examples

The examples connect the alarm to the correct metric. CloudTrail log delivery and notification recipients require separate configuration.

Before

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-CloudTrailChanges"
  pattern        = "{ ($.eventName = CreateTrail) || ($.eventName = UpdateTrail) || ($.eventName = DeleteTrail) || ($.eventName = StartLogging) || ($.eventName = StopLogging) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-CloudTrailChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.5-CloudTrailChanges"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = "XXXX NOT YOUR FILTER XXXX"
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

After

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-CloudTrailChanges"
  pattern        = "{ ($.eventName = CreateTrail) || ($.eventName = UpdateTrail) || ($.eventName = DeleteTrail) || ($.eventName = StartLogging) || ($.eventName = StopLogging) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-CloudTrailChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.5-CloudTrailChanges"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = aws_cloudwatch_log_metric_filter.example.id
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

References