Remediation
Perform the following to enable global (Multi-region) CloudTrail logging:
From Consoleβ
- Sign in to the AWS Management Console and open the IAM console at https://console.aws.amazon.com/cloudtrail.
- Click on
Trailson the left navigation pane. - Click
Get Started Now, if presented.
- Click
Add new trail. - Enter a trail name in the
Trail namebox. - A trail created in the console is a multi-region trail by default.
- Specify an S3 bucket name in the
S3 bucketbox. - Specify the AWS KMS alias under the
Log file SSE-KMS encryptionsection or create a new key. - Click
Next.
- Ensure
Management eventscheck box is selected. - Ensure both
ReadandWriteare check under API activity. - Click
Next. - Review your trail settings and click
Create trail.
From Command Lineβ
Create a multi-region trail:
aws cloudtrail create-trail --name <trail_name> --bucket-name <s3_bucket_for_cloudtrail> --is-multi-region-trail aws cloudtrail update-trail --name <trail_name> --is-multi-region-trail
Enable multi-region on an existing trail:
aws cloudtrail update-trail --name <trail-name> --is-multi-region-trail
Note: Creating a CloudTrail trail via the CLI without providing any overriding options
configures all read and write Management Events to be logged by default.