AWS CloudTrail
A security auditing service that records AWS API calls, user actions, and resource changes.
Last reviewed: July 25, 2026
AWS CloudTrail is a logging and auditing service that records every API call made within an AWS account — who made the call, what action was taken, which resource it affected, when it happened, and from what IP address — providing a complete audit trail of account activity for security investigation, compliance, and operational troubleshooting.
What Gets Logged
CloudTrail captures both management events (actions that create, modify, or delete AWS resources, like launching an EC2 instance or changing an IAM policy) and, optionally, data events (more granular, higher-volume actions like individual S3 object reads or DynamoDB item-level operations). Every logged event includes the identity that made the call — whether an IAM user, role, or an AWS service acting on the account’s behalf — making it possible to answer questions like “who deleted this S3 bucket” or “when was this security group rule changed” after the fact.
Why It’s a Security Baseline
Without a complete API activity log, a security incident investigation has to rely on inference from indirect evidence rather than a direct record of what actually happened. CloudTrail is one of the first things security teams and compliance auditors check for in an AWS environment, and it underpins many compliance frameworks (SOC 2, PCI DSS, HIPAA) that require demonstrable audit logging of access to sensitive systems and data.
Practical Configuration
CloudTrail is enabled by default in every AWS account with a 90-day event history visible in the console, but production environments should configure a dedicated “trail” that delivers logs continuously to an S3 bucket (ideally in a separate, tightly access-controlled account) for long-term retention, since the default 90-day history isn’t sufficient for most compliance or forensic requirements. CloudTrail logs are also commonly fed into a SIEM or monitoring system to enable automated alerting on suspicious activity patterns, like an unusual sequence of permission changes or API calls from an unfamiliar geographic location.
CloudTrail Lake and Advanced Querying
For organizations needing more sophisticated analysis than basic log storage, AWS CloudTrail Lake provides a managed, SQL-queryable data store specifically for CloudTrail events, letting security teams run complex queries across months of activity history without needing to build and maintain their own log analytics pipeline. This addresses a common pain point with raw CloudTrail logs delivered to S3 — while durable and complete, they require additional tooling to query efficiently at scale, and CloudTrail Lake is AWS’s answer to that gap, positioned as a middle ground between raw log storage and standing up a full third-party SIEM platform.
Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.