AWS CloudTrail records API activity in your account: who made a call, from which IP address, with which credentials, when, and whether it succeeded. Almost every console click, CLI command and SDK call becomes a CloudTrail event. That makes CloudTrail the first place you look in an investigation and the backbone of most audit requirements.
Events come in types. Management events are control-plane operations, such as CreateUser, PutBucketPolicy or RunInstances. Data events are high-volume, resource-level operations, such as S3 GetObject and DeleteObject, Lambda Invoke or DynamoDB item actions; they are off by default and cost extra, so you enable them selectively with advanced event selectors. Insights events flag unusual rates of API calls or errors compared with a baseline. Event history in the console shows 90 days of management events per Region at no cost, but for anything longer you need a trail or CloudTrail Lake.
A trail delivers log files to an S3 bucket, optionally to CloudWatch Logs, and can encrypt them with SSE-KMS. An organization trail is created in the management account or a delegated administrator account and logs every member account, including new ones; member accounts can see it but cannot change or delete it. Turning on log file integrity validation makes CloudTrail deliver a digest file each hour containing hashes of the log files, signed by CloudTrail, and aws cloudtrail validate-logs proves whether any file was modified, deleted or forged.
CloudTrail Lake is a managed data lake for events. You create an event data store, choose which events it keeps and for how long, and query it with SQL, across accounts and Regions of an organization. It suits investigations and audits where you want to query months of activity without building an Athena pipeline yourself. For the exam, remember: object-level S3 activity needs data events; tamper evidence needs integrity validation; one trail nobody in member accounts can disable is an organization trail.
Key terms
- Management event
- A control-plane API call, such as creating a user or changing a bucket policy, logged by trails by default.
- Data event
- A high-volume resource operation, such as reading an S3 object or invoking a Lambda function, logged only when enabled.
- Organization trail
- A trail created from the management or delegated administrator account that logs all member accounts and cannot be changed by them.
- Digest file
- An hourly signed file with hashes of delivered log files, used to validate log integrity.
After a bucket of customer exports is emptied, the team finds nothing in Event history because object deletions are data events. They turn on S3 data events for sensitive buckets in the organization trail, and next time a CloudTrail Lake query shows the exact role, IP and time of each DeleteObject call.
Check yourself
How long does Event history keep events, and which types?
90 days of management events per Region, for free.
Can a member account administrator delete an organization trail?
No. Member accounts can view it, but only the management or delegated administrator account can change or delete it.