Remediation
Perform the following to enable global (Multi-region) CloudTrail logging:
From Consoleβ
-
Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/cloudtrail.
-
Click on
Trailson the left navigation pane. -
Click
Get Started Now, if presented.- Click
Add new trail. - Enter a trail name in the
Trail namebox. - A trail created in the console is a multi-region trail by default.
- Specify an S3 bucket name in the
S3 bucketbox. - Specify the AWS KMS alias under the
Log file SSE-KMS encryptionsection or create a new key. - Click
Next.
- Click
-
Ensure
Management eventscheck box is selected. -
Ensure both
ReadandWriteare check under API activity. -
Click
Next. -
Review your trail settings and click
Create trail.
From Command Lineβ
Create a multi-region trail:
aws cloudtrail create-trail \
--name {{trail-name}} \
--bucket-name {{s3-bucket-name}} \
--is-multi-region-trail
Enable multi-region on an existing trail:
aws cloudtrail update-trail --name {{trail-name}} --is-multi-region-trail
Note: Creating a CloudTrail trail via the CLI without providing any overriding options
configures all read and write Management Events to be logged by default.