{"id":3514,"date":"2023-02-04T10:55:33","date_gmt":"2023-02-04T10:55:33","guid":{"rendered":"https:\/\/exceedthecloud.com\/?p=3514"},"modified":"2023-02-11T11:44:55","modified_gmt":"2023-02-11T11:44:55","slug":"how-to-create-a-trail-in-cloudtrail","status":"publish","type":"post","link":"https:\/\/exceedthecloud.com\/?p=3514","title":{"rendered":"How to Create a Trail in CloudTrail"},"content":{"rendered":"\n<p>AWS CloudTrail is an AWS service that helps you enable operational and risk auditing, governance, and compliance of your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. Events include actions taken in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs. Ref: <a href=\"https:\/\/docs.aws.amazon.com\/cloudtrail\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/docs.aws.amazon.com\/cloudtrail\/index.html<\/a><\/p>\n\n\n\n<p>Prerequisites: Having a valid AWS Account (Follow the step in this link to create an AWS Account) <a href=\"https:\/\/exceedthecloud.com\/?p=3419\" target=\"_blank\" rel=\"noreferrer noopener\">How to Sign Up for a new Amazon Web Services Account<\/a><\/p>\n\n\n\n<p>Sign in in AWS console as IAM user<\/p>\n\n\n\n<p>Login to the AWS management console (<a href=\"https:\/\/console.aws.amazon.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/console.aws.amazon.com\/<\/a>) with our IAM user<\/p>\n\n\n\n<p>Create a Trail to monitor and log and activity of all AWS Account activity into an S3 bucket storage account<\/p>\n\n\n\n<p>In the search bar \/ Type CloudTrail<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"416\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture1-3.png\" alt=\"\" class=\"wp-image-3515\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture1-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture1-3-300x200.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Click on Cloud Trail Dashboard<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"404\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture2-3.png\" alt=\"\" class=\"wp-image-3516\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture2-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture2-3-300x194.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>View the CloudTrail Dashboard<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"405\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture3-3.png\" alt=\"\" class=\"wp-image-3517\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture3-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture3-3-300x195.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>You can list all the event in your account by clicking on Event history<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"414\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture4-3.png\" alt=\"\" class=\"wp-image-3518\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture4-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture4-3-300x199.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Notes: Events are store in CloudTrail for 90 days by default<\/p>\n\n\n\n<p>To save event for more than 90 days you must create a trail<\/p>\n\n\n\n<p>Click on Dashboard \/ Create trail<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"345\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture5-3.png\" alt=\"\" class=\"wp-image-3519\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture5-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture5-3-300x166.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Enter a Trail name \/ Create or Select an S3 bucket \/ Review the others option \/ Click Next<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"641\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture6-3.png\" alt=\"\" class=\"wp-image-3520\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture6-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture6-3-292x300.png 292w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Add data and insights event \/ review all the other option \/ Choose Data event type S3 \/ Click Next<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"575\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture7-3.png\" alt=\"\" class=\"wp-image-3521\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture7-3.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture7-3-300x276.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Review your options and click Create trail<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"234\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture8-2.png\" alt=\"\" class=\"wp-image-3522\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture8-2.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture8-2-300x113.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Click on your trail name<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"234\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture9-2.png\" alt=\"\" class=\"wp-image-3523\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture9-2.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture9-2-300x113.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>You have the option to delete or stop trail logging<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"488\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture10-2.png\" alt=\"\" class=\"wp-image-3524\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture10-2.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture10-2-300x235.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>You can view the logs in the S3 Buckets <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"334\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture11-2.png\" alt=\"\" class=\"wp-image-3525\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture11-2.png 624w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/Picture11-2-300x161.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p>Credit: <em><a href=\"https:\/\/www.aosnote.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Azeez<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AWS CloudTrail is an AWS service that helps you enable operational and risk auditing, governance, and compliance of your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. Events include actions &hellip; <a href=\"https:\/\/exceedthecloud.com\/?p=3514\">Continued<\/a><\/p>\n","protected":false},"author":1,"featured_media":3526,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"kt_blocks_editor_width":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[121,118,123],"tags":[119,120,126],"class_list":["post-3514","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-amazon-web-services","category-aws","category-aws-basics","tag-aws","tag-aws-account","tag-cloudtrail"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2023\/02\/cloudtrail.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts\/3514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3514"}],"version-history":[{"count":2,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts\/3514\/revisions"}],"predecessor-version":[{"id":3718,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts\/3514\/revisions\/3718"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/media\/3526"}],"wp:attachment":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}