Description
CloudTrail data events support investigations of S3 object reads and writes. Collecting management events alone may not meet object-level audit needs, so review the selected buckets and events.
The default for read_write_type in event_selector is All. Omitting it does not by itself exclude reads or writes; coverage also depends on the selected data resources and other selector settings.
Potential impact
- Missing required object events makes reads and changes harder to trace.
- Evidence for investigating bulk downloads, deletion, or overwrites may be insufficient.
Remediation
- Select the S3 objects that require data event logging and explicitly set
read_write_type = "All"when both reads and writes are needed. - Review bucket, prefix, and Region coverage, and consider data event costs.
- Verify delivery, then configure notifications, log access permissions, and retention.
Examples
The examples compare the default with an explicit All; both select read and write events. arn:aws:s3::: covers a broad S3 scope, so narrow it to the required buckets and prefixes. The log destination bucket and CloudTrail delivery policy are omitted.
Before
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.foo.id
s3_key_prefix = "prefix"
include_global_service_events = false
event_selector {
include_management_events = true
data_resource {
type = "AWS::S3::Object"
values = ["arn:aws:s3:::"]
}
}
}
After
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.foo.id
s3_key_prefix = "prefix"
include_global_service_events = false
event_selector {
read_write_type = "All"
include_management_events = true
data_resource {
type = "AWS::S3::Object"
values = ["arn:aws:s3:::"]
}
}
}
Explanation:
The second example makes the intended read_write_type = "All" explicit. The omitted value in the first also defaults to All; check selector scope and delivery to determine whether required events are missing.