AWS CloudTrail
User Guide (Version 1.0)

Stopping CloudTrail from Sending Events to CloudWatch Logs

You can stop sending events to CloudWatch Logs by deleting the delivery endpoint.

AWS Management Console

To remove the CloudWatch Logs delivery endpoint using the AWS Management Console

  1. Sign in to the AWS Management Console.

  2. Navigate to the CloudTrail console.

  3. In the navigation pane, click Configuration.

  4. In the CloudWatch Logs (optional) section, click the Delete (trash can) icon.

  5. Click Continue to confirm.

AWS Command Line Interface (CLI)

You can remove the CloudWatch Logs log group as a delivery endpoint using the update-trail command. The following command clears the log group and role from the trail configuration.

aws cloudtrail update-trail --name trailname --cloud-watch-logs-log-group-arn="" --cloud-watch-logs-role-arn=""