AWS CloudTrail
User Guide (Version 1.0)

The AWS Documentation website is getting a new look!
Try it now and let us know what you think. Switch to the new look >>

You can return to the original look by selecting English in the language selector above.

CloudTrail Supported Services and Integrations

CloudTrail supports logging events for many AWS services. You can find the specifics for each supported service in that service's guide. Links to those service-specific topics are provided below. In addition, some AWS services can be used to analyze and act upon data collected in CloudTrail logs. You can browse an overview of those service integrations here.

Note

To see the list of supported regions for each service, see Regions and Endpoints in the Amazon Web Services General Reference.

AWS Service Integrations With CloudTrail Logs

You can configure other AWS services to further analyze and act upon the event data collected in CloudTrail logs. For more information, see the following topics.

AWS Service Topic Description
Amazon Athena Querying AWS CloudTrail Logs

Using Athena with CloudTrail logs is a powerful way to enhance your analysis of AWS service activity. For example, you can use queries to identify trends and further isolate activity by attribute, such as source IP address or user.

You can automatically create tables for querying logs directly from the CloudTrail console, and use those tables to run queries in Athena. For more information, see Creating a Table for CloudTrail Logs in the CloudTrail Console in the Amazon Athena User Guide.

Note

Running queries in Amazon Athena incurs additional costs. For more information, see Amazon Athena Pricing.

Amazon CloudWatch Logs Monitoring CloudTrail Log Files with Amazon CloudWatch Logs

You can configure CloudTrail with CloudWatch Logs to monitor your trail logs and be notified when specific activity occurs. For example, you can define CloudWatch Logs metric filters that will trigger CloudWatch alarms and send notifications to you when those alarms are triggered.

Note

Standard pricing for Amazon CloudWatch and Amazon CloudWatch Logs applies. For more information, see Amazon CloudWatch Pricing.

CloudTrail Integration with AWS Organizations

You can create a trail in the master account for an organization that collects all event data for all AWS accounts in an organization in AWS Organizations. This is called an organization trail. Creating an organization trail helps you define a uniform event logging strategy for your organization. An organization trail is applied automatically to each AWS account in your organization. Users in member accounts can see these trails but cannot modify them, and by default cannot see the log files created for the organization trail. For more information, see Creating a Trail for an Organization.

AWS Service Topics for CloudTrail

You can learn more about how the events for individual AWS services are recorded in CloudTrail logs, including example events for that service in log files. For more information about how specific AWS services integrate with CloudTrail, see the topic about integration in the individual guide for that service.

AWS Service CloudTrail Topics Support began
Alexa for Business Logging Alexa for Business Administration Calls Using AWS CloudTrail 11/29/2017
Amazon API Gateway Log API management calls to Amazon API Gateway Using AWS CloudTrail 07/09/2015
Application Auto Scaling Logging Application Auto Scaling API calls with AWS CloudTrail 10/31/2016
AWS Application Discovery Service Application Discovery Service API Reference 05/12/2016
Amazon AppStream 2.0 Logging Amazon AppStream 2.0 API Calls with AWS CloudTrail 04/25/2019
AWS AppSync Logging AWS AppSync API Calls with AWS CloudTrail 02/13/2018
Amazon Athena Logging Amazon Athena API Calls with AWS CloudTrail 05/19/2017
AWS Auto Scaling Logging AWS Auto Scaling API Calls By Using CloudTrail 08/15/2018
AWS Backup Logging AWS Backup API Calls with AWS CloudTrail 02/04/2019
AWS Batch Logging AWS Batch API Calls with AWS CloudTrail 1/10/2018
AWS Billing and Cost Management Logging AWS Billing and Cost Management API Calls with AWS CloudTrail 06/07/2018
AWS Certificate Manager Using AWS CloudTrail 03/25/2016
AWS Certificate Manager Private Certificate Authority Using CloudTrail 06/06/2019
Amazon Chime Log Amazon Chime Administration Calls Using AWS CloudTrail 09/27/2017
Amazon Cloud Directory Logging Amazon Cloud Directory API Calls Using AWS CloudTrail 01/26/2017
AWS Cloud9 Logging AWS Cloud9 API Calls with AWS CloudTrail 01/21/2019
AWS CloudFormation Logging AWS CloudFormation API Calls in AWS CloudTrail 04/02/2014
Amazon CloudFront Using AWS CloudTrail to Capture Requests Sent to the CloudFront API 05/28/2014
AWS CloudHSM Logging AWS CloudHSM API Calls By Using AWS CloudTrail 01/08/2015
AWS Cloud Map Logging AWS Cloud Map API Calls with AWS CloudTrail 11/28/2018
Amazon CloudSearch Logging Amazon CloudSearch Configuration Service Calls Using AWS CloudTrail 10/16/2014
AWS CloudTrail AWS CloudTrail API Reference (All CloudTrail API calls are logged by CloudTrail.) 11/13/2013
Amazon CloudWatch Logging Amazon CloudWatch API Calls in AWS CloudTrail 04/30/2014
CloudWatch Events Logging Amazon CloudWatch Events API Calls in AWS CloudTrail 01/16/2016
CloudWatch Logs Logging Amazon CloudWatch Logs API Calls in AWS CloudTrail 03/10/2016
AWS CodeBuild Logging AWS CodeBuild API Calls with AWS CloudTrail 12/01/2016
AWS CodeCommit Logging AWS CodeCommit API Calls with AWS CloudTrail 01/11/2017
AWS CodeDeploy Monitoring Deployments with AWS CloudTrail 12/16/2014
CodePipeline Logging CodePipeline API Calls By Using AWS CloudTrail 07/09/2015
AWS CodeStar Logging AWS CodeStar API Calls with AWS CloudTrail 06/14/2017
Amazon Cognito Logging Amazon Cognito API Calls with AWS CloudTrail 02/18/2016
Amazon Comprehend Logging Amazon Comprehend API Calls with AWS CloudTrail 01/17/2018
AWS Config Logging AWS Config API Calls By with AWS CloudTrail 02/10/2015
AWS Control Tower Logging AWS Control Tower Actions with AWS CloudTrail 08/12/2019
Amazon Data Lifecycle Manager Logging Amazon Data Lifecycle Manager API Calls Using AWS CloudTrail 07/24/2018
AWS Data Pipeline Logging AWS Data Pipeline API Calls by using AWS CloudTrail 12/02/2014
AWS Database Migration Service (AWS DMS) Logging AWS Database Migration Service API Calls Using AWS CloudTrail 02/04/2016
AWS DataSync Logging AWS DataSync API Calls with AWS CloudTrail 11/26/2018
AWS Device Farm Logging AWS Device Farm API Calls By Using AWS CloudTrail 07/13/2015
AWS Direct Connect Logging AWS Direct Connect API Calls in AWS CloudTrail 03/08/2014
AWS Directory Service Logging AWS Directory Service API Calls by Using CloudTrail 05/14/2015
Amazon DocumentDB (with MongoDB compatibility) Logging Amazon DocumentDB API Calls with AWS CloudTrail 01/09/2019
Amazon DynamoDB Logging DynamoDB Operations By Using AWS CloudTrail 05/28/2015
Amazon Elastic Container Registry (Amazon ECR) Logging Amazon ECR API Calls By Using AWS CloudTrail 12/21/2015
Amazon Elastic Container Service (Amazon ECS) Logging Amazon ECS API Calls By Using AWS CloudTrail 04/09/2015
AWS Elastic Beanstalk (Elastic Beanstalk) Using Elastic Beanstalk API Calls with AWS CloudTrail 03/31/2014
Amazon Elastic Block Store (Amazon EBS) Logging API Calls Using AWS CloudTrail 11/13/2013
Amazon Elastic Compute Cloud (Amazon EC2) Logging API Calls Using AWS CloudTrail 11/13/2013
Amazon EC2 Auto Scaling Logging Auto Scaling API Calls By Using CloudTrail 07/16/2014
Amazon Elastic File System (Amazon EFS) Logging Amazon EFS API Calls with AWS CloudTrail 06/28/2016
Amazon Elastic Kubernetes Service (Amazon EKS) Logging Amazon EKS API Calls with AWS CloudTrail 06/05/2018
Elastic Load Balancing AWS CloudTrail Logging for Your Classic Load Balancer and AWS CloudTrail Logging for Your Application Load Balancer 04/04/2014
Amazon Elastic Transcoder Logging Amazon Elastic Transcoder API Calls with AWS CloudTrail 10/27/2014
Amazon ElastiCache Logging Amazon ElastiCache API Calls Using AWS CloudTrail 09/15/2014
Amazon Elasticsearch Service Auditing Amazon Elasticsearch Service Domains with AWS CloudTrail 10/01/2015
AWS Elemental MediaConnect Logging AWS Elemental MediaConnect API Calls with AWS CloudTrail 11/27/2018
AWS Elemental MediaConvert Logging AWS Elemental MediaConvert API Calls with CloudTrail 11/27/2017
AWS Elemental MediaLive Logging MediaLive API Calls with AWS CloudTrail 01/19/2019
AWS Elemental MediaPackage Logging AWS Elemental MediaPackage API Calls with AWS CloudTrail 12/21/2018
AWS Elemental MediaStore Logging AWS Elemental MediaStore API Calls with CloudTrail 11/27/2017
AWS Elemental MediaTailor Logging AWS Elemental MediaTailor API Calls with AWS CloudTrail 02/11/2019
Amazon EMR Logging Amazon EMR API Calls in AWS CloudTrail 04/04/2014
AWS Firewall Manager Logging AWS Firewall Manager API Calls with AWS CloudTrail 04/05/2018
Amazon Forecast Logging Amazon Forecast API Calls with AWS CloudTrail 11/28/2018
Amazon FreeRTOS Over-the-Air Updates (OTA) Logging AWS IoT OTA API Calls with AWS CloudTrail 05/22/2019
Amazon FSx for Lustre Logging Amazon FSx for Lustre API Calls with AWS CloudTrail 01/11/2019
Amazon FSx for Windows File Server Monitoring with AWS CloudTrail 11/28/2018
Amazon GameLift Logging Amazon GameLift API Calls with AWS CloudTrail 01/27/2016
Amazon S3 Glacier Logging Glacier API Calls By Using AWS CloudTrail 12/11/2014
AWS Global Accelerator Logging AWS Global Accelerator API Calls with AWS CloudTrail 11/26/2018
AWS Glue Logging AWS Glue Operations Using AWS CloudTrail 11/07/2017
AWS IoT Greengrass Logging AWS IoT Greengrass API Calls with AWS CloudTrail 10/29/2018
AWS Ground Station Logging AWS Ground Station API Calls with AWS CloudTrail 05/31/2019
AWS IoT Things Graph Logging AWS IoT Things Graph API Calls with AWS CloudTrail 05/31/2019
Amazon GuardDuty Logging Amazon GuardDuty API Calls with AWS CloudTrail 02/12/2018
AWS Health Logging AWS Health API Calls with AWS CloudTrail 11/21/2016
AWS Identity and Access Management (IAM) Logging IAM Events with AWS CloudTrail 11/13/2013
Amazon Inspector Logging Amazon Inspector API calls with AWS CloudTrail 04/20/2016
AWS IoT Logging AWS IoT API Calls with AWS CloudTrail 04/11/2016
AWS IoT Analytics Logging AWS IoT Analytics API calls with AWS CloudTrail 04/23/2018
AWS IoT 1-Click Logging AWS IoT 1-Click API Calls with AWS CloudTrail 05/14/2018
AWS IoT Events Logging AWS IoT Events API Calls with AWS CloudTrail 06/11/2019
AWS Key Management Service (AWS KMS) Logging AWS KMS API Calls using AWS CloudTrail 11/12/2014
Amazon Kinesis Data Analytics Monitoring Amazon Kinesis Data Analytics with AWS CloudTrail (SQL Applications) and Monitoring Amazon Kinesis Data Analytics with AWS CloudTrail (Java Applications) 03/22/2019
Amazon Kinesis Data Firehose Monitoring Amazon Kinesis Data Firehose API Calls with AWS CloudTrail 03/17/2016
Amazon Kinesis Data Streams Logging Amazon Kinesis Data Streams API Calls Using AWS CloudTrail 04/25/2014
Amazon Kinesis Video Streams Logging Kinesis Video Streams API Calls with AWS CloudTrail 05/24/2018
AWS Lambda

Logging AWS Lambda API Calls By Using AWS CloudTrail

Using Lambda with AWS CloudTrail

Management events: 04/09/2015

Data events: 11/30/2017

Amazon Lex Logging Amazon Lex API Calls with CloudTrail 08/15/2017
AWS License Manager Logging AWS License Manager API Calls with AWS CloudTrail 03/01/2019
Amazon Lightsail Logging Lightsail API Calls with AWS CloudTrail 12/23/2016
Amazon Machine Learning

Logging Amazon ML API Calls By Using AWS CloudTrail

12/10/2015
AWS Managed Services AWS Managed Services 12/21/2016
Amazon Managed Streaming for Kafka Logging Amazon MSK API Calls with AWS CloudTrail 12/11/2018
AWS Marketplace Logging AWS Marketplace API Calls with AWS CloudTrail 05/02/2017
AWS Marketplace Metering Service Logging AWS Marketplace API Calls with AWS CloudTrail 08/22/2018
AWS Migration Hub Logging AWS Migration Hub API Calls with AWS CloudTrail 08/14/2017
AWS Mobile Hub Logging AWS Mobile CLI API Calls with AWS CloudTrail 06/29/2018
Amazon MQ Logging Amazon MQ API Calls Using AWS CloudTrail 07/19/2018
Amazon Neptune Logging Amazon Neptune API Calls Using AWS CloudTrail 05/30/2018
AWS OpsWorks Logging AWS OpsWorks API Calls By Using AWS CloudTrail 06/04/2014
AWS OpsWorks for Chef Automate Logging AWS OpsWorks for Chef Automate API Calls with AWS CloudTrail 07/16/2018
AWS OpsWorks for Puppet Enterprise Logging OpsWorks for Puppet Enterprise API Calls with AWS CloudTrail 07/16/2018
AWS OpsWorks Stacks Logging AWS OpsWorks Stacks API Calls with AWS CloudTrail 06/04/2014
AWS Organizations Logging AWS Organizations Events with AWS CloudTrail 02/27/2017
AWS Personal Health Dashboard Logging AWS Health API Calls with AWS CloudTrail 12/01/2016
Amazon Personalize Logging Amazon Personalize API Calls with AWS CloudTrail 11/28/2018
Amazon Pinpoint Logging Amazon Pinpoint API Calls with AWS CloudTrail 02/06/2018
Amazon Pinpoint SMS and Voice API Logging Amazon Pinpoint API Calls with AWS CloudTrail 11/16/2018
Amazon Polly Logging Amazon Polly API Calls with AWS CloudTrail 11/30/2016
Amazon Quantum Ledger Database (Amazon QLDB) Logging Amazon QLDB API Calls with AWS CloudTrail 09/10/2019
AWS Certificate Manager Private Certificate Authority Using CloudTrail 04/04/2018
Amazon QuickSight Logging Operations with CloudTrail 04/28/2017
Amazon Redshift Logging Amazon Redshift API Calls with AWS CloudTrail 06/10/2014
Amazon Rekognition Logging Amazon Rekognition API Calls Using AWS CloudTrail 04/6/2018
Amazon Relational Database Service (Amazon RDS) Logging Amazon RDS API Calls Using AWS CloudTrail 11/13/2013
Amazon RDS Performance Insights Logging Amazon RDS API Calls Using AWS CloudTrail

The Amazon RDS Performance Insights API is a subset of the Amazon RDS API.

06/21/2018
AWS Resource Access Manager (AWS RAM) Logging AWS RAM API Calls with AWS CloudTrail 11/20/2018
AWS Resource Groups Logging AWS Resource Groups API Calls with AWS CloudTrail 06/29/2018
AWS RoboMaker Logging AWS RoboMaker API Calls with AWS CloudTrail 01/16/2019
Amazon Route 53 Using AWS CloudTrail to Capture Requests Sent to the Route 53 API 02/11/2015
Amazon SageMaker

Logging Amazon SageMaker API Calls with AWS CloudTrail

01/11/2018
AWS Secrets Manager Monitor the Use of Your AWS Secrets Manager Secrets 04/05/2018
AWS Security Hub Logging AWS Security Hub API Calls with AWS CloudTrail 11/27/2018
AWS Security Token Service (AWS STS)

Logging IAM Events with AWS CloudTrail

The IAM topic includes information for AWS STS.

11/13/2013
AWS Server Migration Service AWS SMS API Reference 11/14/2016
AWS Serverless Application Repository Logging AWS Serverless Application Repository API Calls with AWS CloudTrail 02/20/2018
AWS Service Catalog Logging AWS Service Catalog API Calls with AWS CloudTrail 07/06/2016
AWS Shield Logging Shield Advanced API Calls with AWS CloudTrail 02/08/2018
Amazon Simple Email Service (Amazon SES) Logging Amazon SES API Calls By Using AWS CloudTrail 05/07/2015
Amazon Simple Notification Service (Amazon SNS) Logging Amazon Simple Notification Service API Calls By Using AWS CloudTrail 10/09/2014
Amazon Simple Queue Service (Amazon SQS) Logging Amazon SQS API Actions Using AWS CloudTrail 07/16/2014
Amazon Simple Storage Service Logging Amazon S3 API Calls By Using AWS CloudTrail

Management events: 09/01/2015

Data events: 11/21/2016

Amazon Simple Workflow Service (Amazon SWF) Logging Amazon Simple Workflow Service API Calls with AWS CloudTrail 05/13/2014
AWS Single Sign-On (AWS SSO) Logging AWS SSO API Calls with AWS CloudTrail 12/07/2017
AWS Snowball Logging AWS Snowball API Calls with AWS CloudTrail 01/25/2019
AWS Snowball Edge Logging AWS Snowball Edge API Calls with AWS CloudTrail 01/25/2019
AWS Step Functions Logging AWS Step Functions API Calls with AWS CloudTrail 12/01/2016
AWS Storage Gateway

Logging AWS Storage Gateway API Calls by Using AWS CloudTrail

12/16/2014
AWS Support

Logging AWS Support API Calls with AWS CloudTrail

04/21/2016
AWS Systems Manager (Systems Manager) Log Systems Manager API Calls with AWS CloudTrail 11/13/2013
Amazon Textract Logging Amazon Textract API Calls with AWS CloudTrail 05/29/2019
Amazon Transcribe Logging Amazon Transcribe API Calls with AWS CloudTrail 06/28/2018
AWS Transfer for SFTP Logging AWS Transfer for SFTP API Calls with AWS CloudTrail 01/08/2019
Amazon Translate Logging Amazon Translate API Calls with AWS CloudTrail 04/04/2018
AWS Transit Gateway Logging API Calls for Your Transit Gateway Using AWS CloudTrail 11/26/2018
Amazon Virtual Private Cloud (Amazon VPC)

Logging API Calls Using AWS CloudTrail

The Amazon VPC API is a subset of the Amazon EC2 API.

11/13/2013
AWS WAF Logging AWS WAF API Calls with AWS CloudTrail 04/28/2016
Amazon WorkDocs Logging Amazon WorkDocs API Calls By Using AWS CloudTrail 08/27/2014
Amazon WorkLink Logging Amazon WorkLink API Calls with AWS CloudTrail 01/23/2019
Amazon WorkMail Logging Amazon WorkMail API Calls Using AWS CloudTrail 12/12/2017
Amazon WorkSpaces Logging Amazon WorkSpaces API Calls by Using CloudTrail 04/09/2015
AWS X-Ray Logging AWS X-Ray API Calls With CloudTrail 04/25/2018