AWS CloudTrail
CloudTrail
You need a tamper-proof audit trail of every API call made in your AWS account for compliance and security auditing.
Reach for it when
- Tracking down which developer or deployment role modified a security group rule that caused an outage.
- Satisfying compliance requirements by archiving all account activity logs to an S3 bucket with MFA delete.
- Detecting unauthorized console logins or privilege escalation attempts in near real-time.
Do not reach for it when
- Monitoring application-level logs and server performance metrics — use CloudWatch Logs instead.
- Debugging application database queries or tracking HTTP traffic paths — use X-Ray or database logs instead.
- Storing and querying application access logs from load balancers or CloudFront — use ELB/CloudFront access logging instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| CloudWatch Logs | Choose it when monitoring application console output, server metrics, and custom logs. |
| Config | Choose it when you need to track resource configuration history and compliance status over time. |
How you pay
- The model
- First copy of management events is free; you pay for additional trails, data events, and S3 storage.
- The line item that surprises people
- Enabling Data Events for high-throughput resources like S3 objects or Lambda invokes can generate massive ingest charges.
What trips people up
- CloudTrail is region-specific; you must explicitly create a multi-region trail to capture events from all AWS regions.
- API logs can take up to 15 minutes from the time of execution to appear in the CloudTrail console or S3 destination.
- CloudTrail records the IAM identity used, but if multiple systems share a single role, tracing the root user is difficult.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.