Understanding organization event data stores
If you have created an organization in AWS Organizations, you can create an organization event data store that logs all events for all AWS accounts in that organization. Organization event data stores can apply to all AWS Regions, or the current Region. You can't use an organization event data store to collect events from outside of AWS.
You can create an organization event data store by using either the management account or the delegated administrator account. When a delegated administrator creates an organization event data store, the organization event data store exists in the management account for the organization. This approach is because the management account maintains ownership of all organization resources.
The management account for an organization can update an account-level event data store to apply it to an organization.
When the organization event data store is specified as applying to an organization, it's automatically applied to all member accounts in the organization. Member accounts can't see the organization event data store, nor can they modify or delete it. By default, member accounts don't have access to the organization event data store, nor can they run queries on organization event data stores.
The following table shows the capabilities of the management account and delegated administrator accounts within the AWS Organizations organization.
Capabilities | Management account | Delegated administrator account |
---|---|---|
Register or remove delegated administrator accounts. |
|
|
Create an organization event data store for AWS CloudTrail events or AWS Config configuration items. |
|
|
Enable Insights on an organization event data store. |
|
|
Update an organization event data store. |
|
|
Enable Lake query federation on an organization event data store.2 |
|
|
Disable Lake query federation on an organization event data store. |
|
|
Delete an organization event data store. |
|
|
Copy trail events to an event data store. |
|
|
Run queries on organization event data stores. |
|
|
View the CloudTrail Lake dashboard for an organization event data store. |
|
|
1Only the management account can convert an organization event data store to an account-level event data store, or convert an account-level event data store to an organization event data store. These actions are not allowed for the delegated administrator because organization event data stores only exist in the management account. When an organization event data store is converted to an account-level event data store, only the management account has access to the event data store. Likewise, only an account-level event data store in the management account can be converted to an organization event data store.
2Only a single delegated administrator account or the management account can enable federation on an organization event data store. Other delegated administrator accounts can query and share information using the Lake Formation data sharing feature. Any delegated administrator account as well as the organization's management account can disable federation.
Create an organization event data store
The management account or delegated administrator account for an organization can create an organization event data store to collect either CloudTrail events (management events, data events) or AWS Config configuration items.
Note
Only the organization's management account can copy trail events to an event data store.
Apply an account-level event data store to an organization
The organization's management account can convert an account-level event data store to apply it to an organization.