SimAWSby ShahriarLabs
Search

AWS CloudTrail

CloudTrail

You need a tamper-proof audit trail of every API call made in your AWS account for compliance and security auditing.

Regional serviceConcept reference · no service console simulation

Reach for it when

  • Tracking down which developer or deployment role modified a security group rule that caused an outage.
  • Satisfying compliance requirements by archiving all account activity logs to an S3 bucket with MFA delete.
  • Detecting unauthorized console logins or privilege escalation attempts in near real-time.

Do not reach for it when

  • Monitoring application-level logs and server performance metrics — use CloudWatch Logs instead.
  • Debugging application database queries or tracking HTTP traffic paths — use X-Ray or database logs instead.
  • Storing and querying application access logs from load balancers or CloudFront — use ELB/CloudFront access logging instead.

Alternatives, and how to choose

ServicePick it instead when
CloudWatch LogsChoose it when monitoring application console output, server metrics, and custom logs.
ConfigChoose it when you need to track resource configuration history and compliance status over time.

How you pay

The model
First copy of management events is free; you pay for additional trails, data events, and S3 storage.
The line item that surprises people
Enabling Data Events for high-throughput resources like S3 objects or Lambda invokes can generate massive ingest charges.

What trips people up

  • CloudTrail is region-specific; you must explicitly create a multi-region trail to capture events from all AWS regions.
  • API logs can take up to 15 minutes from the time of execution to appear in the CloudTrail console or S3 destination.
  • CloudTrail records the IAM identity used, but if multiple systems share a single role, tracing the root user is difficult.

Verify the live service

This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.