Review S3 object-level CloudTrail data event coverage

Verify that CloudTrail data events cover the S3 object reads and writes you need.

Description

CloudTrail data events support investigations of S3 object reads and writes. Collecting management events alone may not meet object-level audit needs, so review the selected buckets and events.

The default for read_write_type in event_selector is All. Omitting it does not by itself exclude reads or writes; coverage also depends on the selected data resources and other selector settings.

Potential impact

  • Missing required object events makes reads and changes harder to trace.
  • Evidence for investigating bulk downloads, deletion, or overwrites may be insufficient.

Remediation

  • Select the S3 objects that require data event logging and explicitly set read_write_type = "All" when both reads and writes are needed.
  • Review bucket, prefix, and Region coverage, and consider data event costs.
  • Verify delivery, then configure notifications, log access permissions, and retention.

Examples

The examples compare the default with an explicit All; both select read and write events. arn:aws:s3::: covers a broad S3 scope, so narrow it to the required buckets and prefixes. The log destination bucket and CloudTrail delivery policy are omitted.

Before

hcl
resource "aws_cloudtrail" "example" {
  name                          = "tf-trail-foobar"
  s3_bucket_name                = aws_s3_bucket.foo.id
  s3_key_prefix                 = "prefix"
  include_global_service_events = false

  event_selector {
    include_management_events = true

    data_resource {
      type   = "AWS::S3::Object"
      values = ["arn:aws:s3:::"]
    }
  }
}

After

hcl
resource "aws_cloudtrail" "example" {
  name                          = "tf-trail-foobar"
  s3_bucket_name                = aws_s3_bucket.foo.id
  s3_key_prefix                 = "prefix"
  include_global_service_events = false

  event_selector {
    read_write_type           = "All"
    include_management_events = true

    data_resource {
      type   = "AWS::S3::Object"
      values = ["arn:aws:s3:::"]
    }
  }
}

Explanation:

The second example makes the intended read_write_type = "All" explicit. The omitted value in the first also defaults to All; check selector scope and delivery to determine whether required events are missing.

References