Kanji
・Cloud Engineer / Freelance ・Geboren 1993 ・Aus Ehime / Wohnhaft in Shibuya, Tokio ・5 Jahre AWS-Erfahrung Profildetails
Inhaltsverzeichnis
AWS CloudTrail (hereafter “CloudTrail”) is a service that records actions taken in your AWS account .
It records three types of events: management events, data events, and insight events.
Management events log API calls that modify AWS resources using the AWS Management Console, AWS SDK, AWS CLI, AWS API, and more.
Data events log activities such as access to objects in S3 buckets and the execution of Lambda functions.
Insight events log findings related to the security and performance of your AWS account.
By default, CloudTrail is enabled when you create an AWS account.
Reference: What is AWS CloudTrail? - AWS CloudTrail
However, a “trail” is not created by default. You can view up to 90 days of events in the AWS Management Console, but since log files are not output, you cannot analyze them with Athena or CloudWatch Logs. If you want to extend the retention period, you need to configure output to an S3 bucket or CloudWatch Logs.
Reference: How CloudTrail Works - AWS CloudTrail
You need to create a CloudTrail trail if any of the following apply:
1: The first management event delivered to an S3 bucket is free. From the second management event delivered to an S3 bucket, delivery charges apply. 2: For management and data events, charges apply when delivered to an S3 bucket, while for insight events, charges apply based on the number of analyzed events.
- AWS::CloudTrail::Channel - AWS::CodeWhisperer::Customization - AWS::CodeWhisperer::Profile - AWS::Cognito::IdentityPool - AWS::DynamoDB::Stream - AWS::DynamoDB::Table - AWS::EC2::Snapshot - AWS::EMRWAL::Workspace - AWS::FinSpace::Environment - AWS::Glue::Table - AWS::GuardDuty::Detector - AWS::KendraRanking::ExecutionPlan - AWS::KinesisVideo::Stream - AWS::Lambda::Function - AWS::ManagedBlockchain::Network - AWS::ManagedBlockchain::Node - AWS::MedicalImaging::Datastore - AWS::PCAConnectorAD::Connector - AWS::S3::AccessPoint - AWS::S3::Object - AWS::S3ObjectLambda::AccessPoint - AWS::S3Outposts::Object - AWS::SageMaker::Endpoint - AWS::SageMaker::ExperimentTrialComponent - AWS::SageMaker::FeatureGroup - AWS::SNS::PlatformEndpoint - AWS::SNS::Topic - AWS::SSMMessages::ControlChannel - AWS::Timestream::Database - AWS::Timestream::Table - AWS::VerifiedPermissions::PolicyStore
The purpose of recording varies depending on the resource, so select as needed.
For example, by recording data events for S3 buckets, you can obtain a change history of objects in the bucket.
Note that while data events guarantee completeness, S3 server access logs do not.
Reference: How to deal with missing access logs in S3 server access logs | DevelopersIO
On the other hand, server access logs are sometimes used for buckets that output Config or CloudTrail logs created by Control Tower, and AWS Foundational Security Best Practices recommends outputting server access logs.
Reference: AWS Foundational Security Best Practices v1.0.0 (FSBP) standard - AWS Security Hub
The lack of guaranteed completeness may be a concern, but since data events can be costly, it may be an option to accept the lack of completeness and use server access logs.
Insight events use machine learning to analyze management events and detect abnormal activities when behavior deviates from the norm.
Write events detect abnormal activity when there are many API calls.
Write/Read events detect abnormal activity when the API error rate is high.
Main reasons for detecting abnormal activity include:
Malicious API access
Application bugs
Access denied due to permission misconfiguration, such as IAM roles or SCPs
Since insight events are more expensive than other events, you should carefully consider enabling them.
As mentioned above, if you frequently make changes to your system in a production environment, insight events may be generated, so consider enabling them as needed.