Monitoring CloudTrail Log Files with Amazon CloudWatch Logs
You can configure CloudTrail with CloudWatch Logs to monitor your logs and be notified when specific activity occurs.
Configure your trail to send log events to CloudWatch Logs.
Define CloudWatch Logs metric filters to evaluate log events for matches in terms, phrases, or values. For example, you can monitor for
Assign CloudWatch metrics to the metric filters.
Create CloudWatch alarms that are triggered according to thresholds and time periods that you specify. You can configure alarms to send notifications when alarms are triggered, so that you can take action.
You can also configure CloudWatch to automatically perform an action in response to an alarm.
Standard pricing for Amazon CloudWatch and Amazon CloudWatch Logs apply. For more information, see Amazon CloudWatch Pricing.
CloudWatch Logs is supported in the following regions:
|US East (N. Virginia)||us-east-1|
|US East (Ohio)||us-east-2|
|US West (N. California)||us-west-1|
|US West (Oregon)||us-west-2|
|Asia Pacific (Mumbai)||ap-south-1|
|Asia Pacific (Seoul)||ap-northeast-2|
|Asia Pacific (Singapore)||ap-southeast-1|
|Asia Pacific (Sydney)||ap-southeast-2|
|Asia Pacific (Tokyo)||ap-northeast-1|
|South America (São Paulo)||sa-east-1|
- Sending Events to CloudWatch Logs
- Using an AWS CloudFormation Template to Create CloudWatch Alarms
- Creating CloudWatch Alarms for CloudTrail Events: Examples
- Creating CloudWatch Alarms for CloudTrail Events: Additional Examples
- Configuring Notifications for CloudWatch Logs Alarms
- Stopping CloudTrail from Sending Events to CloudWatch Logs
- CloudWatch Log Group and Log Stream Naming for CloudTrail
- Role Policy Document for CloudTrail to Use CloudWatch Logs for Monitoring