Tips for managing trails - AWS CloudTrail

Tips for managing trails

  • Beginning on April 12, 2019, trails are viewable only in the AWS Regions where they log events. If you create a trail that logs events in all AWS Regions, it will appear in the console in all AWS Regions in the AWS partition in which you are working. If you create a trail that only logs events in a single AWS Region, you can view and manage it only in that AWS Region.

  • To edit a trail in the list, choose the trail name.

  • Configure at least one trail that applies to all Regions so that you receive log files from all Regions in the AWS partition in which you are working.

  • To log events from a specific Region and deliver log files to an S3 bucket in the same Region, you can update the trail to apply to a single Region. This is useful if you want to keep your log files separate. For example, you may want users to manage their own logs in specific Regions, or you may want to separate CloudWatch Logs alarms by Region.

  • To log events from multiple AWS accounts in one trail, consider creating an organization in AWS Organizations and then creating an organization trail.

  • Creating multiple trails will incur additional costs. For more information about prices, see AWS CloudTrail Pricing.