Cloudanix home pagelight logodark logo
  • Community
  • Login
  • Login
  • Overview
  • AWS
  • Azure
  • GCP
  • GitHub
  • On-Demand Scan
  • Kubernetes
  • Integrations
  • AWS Introduction
    • Security of your AWS Account
    AWS Pricing
    • AWS Services which determine your cost
    AWS Threats
    • Getting Started with AWS Realtime Events
    AWS Misconfigurations
    • Getting Started with AWS Audit
    • Permissions required for Misconfigurations Detection
    • API Gateway Audit
    • Cloudformation Audit
    • CloudFront Audit
    • CloudTrail Audit
    • Cloudwatch Audit
    • DynamoDB Audit
    • EC2 Audit
    • Elastic Search Audit
    • ELB Audit
    • IAM Audit
    • KMS Audit
    • Kubernetes Audit
    • Lambda Audit
    • RDS Audit
    • Redshift Audit
    • Route53 Audit
    • S3 Audit
    • Security Groups Audit
    • SES Audit
    • SNS Audit
    • IAM Deep Dive
    • App Sync Audit
    • Code Build Audit
    • Open Search Audit
    • Shield Audit
    • SQS Audit
    On this page
    • Checks Performed
    AWS Misconfigurations

    CloudTrail Audit

    ​
    Checks Performed

    • CloudTrail Must Log Data Events
    • Log files Should Be Delivered Without Any Failures
    • CloudTrail Must Be Enabled For All Regions
    • Trails Should Record Both Regional And Global Events
    • Duplicate Entries Should Be Avoided In CloudTrail Logs
    • CloudTrail Events Should Be Monitored By CloudWatch Logs
    • File Integrity Validation Feature Should Be Enabled For Trails
    • CloudTrail Logs Should Be Encrypted
    • CloudTrails Must Log Management Events
    • CloudTrail Logging Bucket Should Use MFA Delete Feature
    • Object Lock Feature Should Be Enabled
    • CloudTrail Logging Buckets Should Not Be Publicly Accessible
    • Server Access Logging Feature Should Be Enabled
    • CloudTrails Must Log Management Events
    CloudFront AuditCloudwatch Audit
    githubtwitter
    Powered by Mintlify
    Assistant
    Responses are generated using AI and may contain mistakes.