Remediation
Perform the following to enable global (Multi-region) CloudTrail logging:
From Consoleβ
- Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/cloudtrail.
- Click on Trailson the left navigation pane.
- Click Get Started Now, if presented.
- Click Add new trail.
- Enter a trail name in the Trail namebox.
- A trail created in the console is a multi-region trail by default.
- Specify an S3 bucket name in the S3 bucketbox.
- Specify the AWS KMS alias under the Log file SSE-KMS encryptionsection or create a new key.
- Click Next.
- Ensure Management eventscheck box is selected.
- Ensure both ReadandWriteare check under API activity.
- Click Next.
- Review your trail settings and click Create trail.
From Command Lineβ
Create a multi-region trail:
aws cloudtrail create-trail --name <trail_name> --bucket-name <s3_bucket_for_cloudtrail> --is-multi-region-trail aws cloudtrail update-trail --name <trail_name> --is-multi-region-trail
Enable multi-region on an existing trail:
aws cloudtrail update-trail --name <trail-name> --is-multi-region-trail
Note: Creating a CloudTrail trail via the CLI without providing any overriding options
configures all read and write Management Events to be logged by default.