Asterrr's Handbook

Logging strategy

Choosing log sources for a security question, CloudTrail trails and organization trails, data and network activity events, VPC and transit gateway flow logs, Resolver query logs, service access logs, and a protected log archive account.

Exam tasks: 1.2 (skills 1.2.1, 1.2.2, 1.2.3 and 1.2.6: choosing log sources, configuring logging org-wide, log storage, network log sources)

The decision: which log actually records the evidence the question asks for, how do you collect it from every account and Region without trusting account owners, and how do you make sure nobody can alter it?

Which log answers which question

QuestionLog sourceOn by default?
Who called which AWS API, from where, with which role?CloudTrail management events90 days in Event history. A trail is needed to keep them
Who read or deleted this S3 object, or invoked this Lambda function?CloudTrail data eventsNo, and they cost per event
Which API calls went through my VPC endpoints, including denied ones from outside principals?CloudTrail network activity eventsNo
Is someone calling an API at an unusual rate or error rate?CloudTrail InsightsNo
Which IPs and ports talked, and was it accepted or rejected?VPC Flow Logs, transit gateway flow logsNo
Which domain names did this instance resolve?Route 53 Resolver query logsNo
Which HTTP requests hit the site, with path, status and client IP?ALB, CloudFront or API Gateway access logsNo
Which web requests did the firewall block, and by which rule?AWS WAF logsNo
What happened inside the operating system?CloudWatch agent shipping OS and application logsNo
Who did what inside the Kubernetes cluster?EKS control plane logs (audit, authenticator, api)No
What did this resource's configuration look like last Tuesday?AWS Config configuration historyWhen the recorder is on

Exam signal

Flow logs never contain domain names or payloads, and CloudTrail never contains network traffic. When a question asks "which domain" pick Resolver query logs, when it asks "which packets" pick flow logs (or Traffic Mirroring for payloads), and when it asks "who" pick CloudTrail.

CloudTrail

Event types

  • Management events: control plane calls such as RunInstances, PutBucketPolicy, ConsoleLogin. Split into read and write. The first copy of management events in each Region is free.
  • Data events: resource operations such as S3 GetObject, Lambda Invoke, DynamoDB item calls. High volume, so scope them with advanced event selectors (by bucket ARN prefix, readOnly, event name).
  • Network activity events: calls made through a VPC endpoint, useful to spot data leaving through an endpoint to someone else's bucket.
  • Insights events: CloudTrail learns the normal rate of write API calls and errors and records spikes.

Trails

  • A trail copies events to an S3 bucket, optionally to CloudWatch Logs (through an IAM role) and to SNS when a log file is delivered. Delivery to S3 typically happens within about 5 minutes.
  • Make trails multi-Region. Global service events (IAM, STS, CloudFront) are recorded in us-east-1 and included by multi-Region trails.
  • Turn on log file integrity validation. CloudTrail writes an hourly signed digest file with a SHA-256 hash of each log file, so aws cloudtrail validate-logs can prove files weren't changed or deleted.
  • Encrypt with SSE-KMS using a customer managed key. The key policy must let CloudTrail generate data keys, and readers need kms:Decrypt. See Troubleshooting monitoring.

Organization trail

  • Created by the management account or a CloudTrail delegated administrator. It logs every account, including accounts added later, and appears in every member account.
  • Members can see it but can't stop, change or delete it. That's the property the exam wants when it says "account administrators must not be able to disable logging".
  • Logs land under AWSLogs/<org-id>/<account-id>/ in one bucket. Event history in each account still shows only that account's events.

An SCP instead of an organization trail

An SCP that denies cloudtrail:StopLogging protects trails that already exist, but it doesn't create a trail in new accounts and doesn't centralize anything. The organization trail is the primary control. Add the SCP as defence in depth, for example to stop anyone deleting the log archive bucket.

Legacy: use Amazon CloudWatch (CloudTrail ingestion and pipelines) instead

CloudTrail Lake closed to new customers on 31 May 2026. Existing event data stores keep working with only critical fixes, and AWS recommends moving to CloudWatch, which can ingest CloudTrail events, normalize to OCSF and query them. Trails, Insights and Event history are unaffected. Older material may still offer CloudTrail Lake as the answer for "SQL over CloudTrail across the organization". Today, prefer Athena over the trail bucket, CloudWatch, or Security Lake.

Network log sources

VPC Flow Logs

  • Create them on a VPC, subnet or network interface. Choose ACCEPT, REJECT or ALL.
  • Destinations: CloudWatch Logs, S3 (Parquet optional, Hive-style partitions) or Amazon Data Firehose.
  • The default format has addresses, ports, protocol, packets, bytes and action. A custom format adds fields such as pkt-srcaddr and pkt-dstaddr (the real source behind a NAT gateway), tcp-flags, flow-direction, traffic-path, vpc-id and instance-id.
  • Aggregation interval is 10 minutes by default or 1 minute. You can't edit a flow log; delete it and create a new one to change format or destination.
  • Not captured: traffic to the Amazon DNS server, the instance metadata service (169.254.169.254), Amazon Time Sync, DHCP, Windows license activation and the default VPC router reserved address.

Transit gateway flow logs record traffic crossing a transit gateway, across attached VPCs, VPNs and Direct Connect. Use them when the question is about east-west traffic between many VPCs or hybrid traffic, where per-VPC flow logs would miss the hop.

Route 53 Resolver query logs

  • Record DNS queries from resources in associated VPCs, queries arriving through inbound endpoints, and the action taken by Route 53 Resolver DNS Firewall.
  • Destinations: CloudWatch Logs, S3 or Firehose. Share one configuration with other accounts through AWS RAM so every VPC logs to the same central destination.
  • Separate from public DNS query logging for a public hosted zone, which only goes to CloudWatch Logs in us-east-1 and records queries from the internet to your domain.

For how these network logs support segmentation analysis, see Network segmentation and analysis.

Service access logs

LogDestinationsNotes worth knowing
S3 server access logsS3 bucket in the same Region and accountBest effort, delivered in hours. Target bucket must use SSE-S3 default encryption
ALB access logsS3 in the same RegionWritten every 5 minutes. Bucket policy must allow the ELB log delivery principal. SSE-S3 only
CloudFront standard logsCloudWatch Logs, Firehose or S3The legacy S3 delivery needs bucket ACLs enabled. Real-time logs go to Kinesis Data Streams
API Gateway logsCloudWatch LogsExecution logs need the account-level CloudWatch role set in API Gateway settings. Access logs use your own format
AWS WAF logsCloudWatch Logs, S3 or FirehoseDestination name must start with aws-waf-logs-. Supports redacting fields and filtering which requests are kept
Lambda logsCloudWatch Logs (/aws/lambda/<function> or a custom group)Execution role needs logs:CreateLogStream and logs:PutLogEvents
S3 server access logsCloudTrail S3 data events
DeliveryBest effort, can be hoursMinutes, guaranteed
IdentityRequester canonical ID or ARNFull userIdentity, session context, source IP
ScopeWhole bucketFilter by bucket, prefix, read or write
CostStorage onlyPer event
Pick it whenCheap, bulk access analyticsSecurity investigation and alerting

The log archive account

  • A dedicated log archive account (Control Tower creates one) holds the buckets. Workload account admins have no write or delete access there.
  • Bucket settings: versioning, S3 Object Lock in compliance mode with a retention period for immutability, Block Public Access, SSE-KMS with a key in the archive account, and lifecycle rules to cheaper storage classes.
  • Bucket policy allows the service principals to write (for CloudTrail, cloudtrail.amazonaws.com with an aws:SourceArn condition naming the trail) and denies anything without TLS.
  • For a dedicated CloudWatch logging account, use CloudWatch Logs centralization rules (organization-wide copies of log groups into one account and Region, with an optional backup Region), or subscription filters to a cross-account destination. Cross-account observability instead lets a monitoring account query logs where they are, without copying.
  • Centralization only copies new log data. Historical data stays in the source account.

Exam signal

"Logs must be immutable for 7 years, even the root user can't delete them" means Object Lock compliance mode. Governance mode can be bypassed by users with s3:BypassGovernanceRetention. See S3 data protection.

90 days
Management events visible in CloudTrail Event history without a trail.
1 hour
Interval at which CloudTrail writes signed digest files for integrity validation.
10 or 1 min
VPC flow log aggregation intervals.
5 minutes
ALB access log delivery interval.
aws-waf-logs-
Required name prefix for WAF log destinations.
us-east-1
Where public hosted zone query logs and global service events are recorded.

Scenarios

Scenario
A bank with 150 accounts in AWS Organizations must retain a record of every API call in every account and Region for 7 years. Account administrators, including those with AdministratorAccess, must not be able to stop the logging or alter the records. Which solution meets these requirements?
Scenario
GuardDuty is not enabled yet in a new account. The security team suspects that an EC2 instance in a private subnet is beaconing to a command-and-control domain through a NAT gateway, and wants to identify the domain names the instance has looked up from now on. The VPC uses the Amazon-provided DNS resolver. Which log source should the team enable?
Scenario
A pharmaceutical company must record, within minutes and with the full IAM identity of the caller, every read and delete of objects in one bucket that holds trial results. The company has 400 other buckets with heavy traffic and wants to control cost. What should the security engineer configure?

Further reading

On this page