Logging strategy
Choosing log sources for a security question, CloudTrail trails and organization trails, data and network activity events, VPC and transit gateway flow logs, Resolver query logs, service access logs, and a protected log archive account.
Exam tasks: 1.2 (skills 1.2.1, 1.2.2, 1.2.3 and 1.2.6: choosing log sources, configuring logging org-wide, log storage, network log sources)
The decision: which log actually records the evidence the question asks for, how do you collect it from every account and Region without trusting account owners, and how do you make sure nobody can alter it?
Which log answers which question
| Question | Log source | On by default? |
|---|---|---|
| Who called which AWS API, from where, with which role? | CloudTrail management events | 90 days in Event history. A trail is needed to keep them |
| Who read or deleted this S3 object, or invoked this Lambda function? | CloudTrail data events | No, and they cost per event |
| Which API calls went through my VPC endpoints, including denied ones from outside principals? | CloudTrail network activity events | No |
| Is someone calling an API at an unusual rate or error rate? | CloudTrail Insights | No |
| Which IPs and ports talked, and was it accepted or rejected? | VPC Flow Logs, transit gateway flow logs | No |
| Which domain names did this instance resolve? | Route 53 Resolver query logs | No |
| Which HTTP requests hit the site, with path, status and client IP? | ALB, CloudFront or API Gateway access logs | No |
| Which web requests did the firewall block, and by which rule? | AWS WAF logs | No |
| What happened inside the operating system? | CloudWatch agent shipping OS and application logs | No |
| Who did what inside the Kubernetes cluster? | EKS control plane logs (audit, authenticator, api) | No |
| What did this resource's configuration look like last Tuesday? | AWS Config configuration history | When the recorder is on |
Exam signal
Flow logs never contain domain names or payloads, and CloudTrail never contains network traffic. When a question asks "which domain" pick Resolver query logs, when it asks "which packets" pick flow logs (or Traffic Mirroring for payloads), and when it asks "who" pick CloudTrail.
CloudTrail
Event types
- Management events: control plane calls such as
RunInstances,PutBucketPolicy,ConsoleLogin. Split into read and write. The first copy of management events in each Region is free. - Data events: resource operations such as S3
GetObject, LambdaInvoke, DynamoDB item calls. High volume, so scope them with advanced event selectors (by bucket ARN prefix,readOnly, event name). - Network activity events: calls made through a VPC endpoint, useful to spot data leaving through an endpoint to someone else's bucket.
- Insights events: CloudTrail learns the normal rate of write API calls and errors and records spikes.
Trails
- A trail copies events to an S3 bucket, optionally to CloudWatch Logs (through an IAM role) and to SNS when a log file is delivered. Delivery to S3 typically happens within about 5 minutes.
- Make trails multi-Region. Global service events (IAM, STS, CloudFront) are recorded in us-east-1 and included by multi-Region trails.
- Turn on log file integrity validation. CloudTrail writes an hourly signed digest file with a SHA-256 hash
of each log file, so
aws cloudtrail validate-logscan prove files weren't changed or deleted. - Encrypt with SSE-KMS using a customer managed key. The key policy must let CloudTrail generate data keys,
and readers need
kms:Decrypt. See Troubleshooting monitoring.
Organization trail
- Created by the management account or a CloudTrail delegated administrator. It logs every account, including accounts added later, and appears in every member account.
- Members can see it but can't stop, change or delete it. That's the property the exam wants when it says "account administrators must not be able to disable logging".
- Logs land under
AWSLogs/<org-id>/<account-id>/in one bucket. Event history in each account still shows only that account's events.
An SCP instead of an organization trail
An SCP that denies cloudtrail:StopLogging protects trails that already exist, but it doesn't create a trail in
new accounts and doesn't centralize anything. The organization trail is the primary control. Add the SCP as
defence in depth, for example to stop anyone deleting the log archive bucket.
Legacy: use Amazon CloudWatch (CloudTrail ingestion and pipelines) instead
CloudTrail Lake closed to new customers on 31 May 2026. Existing event data stores keep working with only critical fixes, and AWS recommends moving to CloudWatch, which can ingest CloudTrail events, normalize to OCSF and query them. Trails, Insights and Event history are unaffected. Older material may still offer CloudTrail Lake as the answer for "SQL over CloudTrail across the organization". Today, prefer Athena over the trail bucket, CloudWatch, or Security Lake.
Network log sources
VPC Flow Logs
- Create them on a VPC, subnet or network interface. Choose
ACCEPT,REJECTorALL. - Destinations: CloudWatch Logs, S3 (Parquet optional, Hive-style partitions) or Amazon Data Firehose.
- The default format has addresses, ports, protocol, packets, bytes and action. A custom format adds fields
such as
pkt-srcaddrandpkt-dstaddr(the real source behind a NAT gateway),tcp-flags,flow-direction,traffic-path,vpc-idandinstance-id. - Aggregation interval is 10 minutes by default or 1 minute. You can't edit a flow log; delete it and create a new one to change format or destination.
- Not captured: traffic to the Amazon DNS server, the instance metadata service (169.254.169.254), Amazon Time Sync, DHCP, Windows license activation and the default VPC router reserved address.
Transit gateway flow logs record traffic crossing a transit gateway, across attached VPCs, VPNs and Direct Connect. Use them when the question is about east-west traffic between many VPCs or hybrid traffic, where per-VPC flow logs would miss the hop.
Route 53 Resolver query logs
- Record DNS queries from resources in associated VPCs, queries arriving through inbound endpoints, and the action taken by Route 53 Resolver DNS Firewall.
- Destinations: CloudWatch Logs, S3 or Firehose. Share one configuration with other accounts through AWS RAM so every VPC logs to the same central destination.
- Separate from public DNS query logging for a public hosted zone, which only goes to CloudWatch Logs in us-east-1 and records queries from the internet to your domain.
For how these network logs support segmentation analysis, see Network segmentation and analysis.
Service access logs
| Log | Destinations | Notes worth knowing |
|---|---|---|
| S3 server access logs | S3 bucket in the same Region and account | Best effort, delivered in hours. Target bucket must use SSE-S3 default encryption |
| ALB access logs | S3 in the same Region | Written every 5 minutes. Bucket policy must allow the ELB log delivery principal. SSE-S3 only |
| CloudFront standard logs | CloudWatch Logs, Firehose or S3 | The legacy S3 delivery needs bucket ACLs enabled. Real-time logs go to Kinesis Data Streams |
| API Gateway logs | CloudWatch Logs | Execution logs need the account-level CloudWatch role set in API Gateway settings. Access logs use your own format |
| AWS WAF logs | CloudWatch Logs, S3 or Firehose | Destination name must start with aws-waf-logs-. Supports redacting fields and filtering which requests are kept |
| Lambda logs | CloudWatch Logs (/aws/lambda/<function> or a custom group) | Execution role needs logs:CreateLogStream and logs:PutLogEvents |
| S3 server access logs | CloudTrail S3 data events | |
|---|---|---|
| Delivery | Best effort, can be hours | Minutes, guaranteed |
| Identity | Requester canonical ID or ARN | Full userIdentity, session context, source IP |
| Scope | Whole bucket | Filter by bucket, prefix, read or write |
| Cost | Storage only | Per event |
| Pick it when | Cheap, bulk access analytics | Security investigation and alerting |
The log archive account
- A dedicated log archive account (Control Tower creates one) holds the buckets. Workload account admins have no write or delete access there.
- Bucket settings: versioning, S3 Object Lock in compliance mode with a retention period for immutability, Block Public Access, SSE-KMS with a key in the archive account, and lifecycle rules to cheaper storage classes.
- Bucket policy allows the service principals to write (for CloudTrail,
cloudtrail.amazonaws.comwith anaws:SourceArncondition naming the trail) and denies anything without TLS. - For a dedicated CloudWatch logging account, use CloudWatch Logs centralization rules (organization-wide copies of log groups into one account and Region, with an optional backup Region), or subscription filters to a cross-account destination. Cross-account observability instead lets a monitoring account query logs where they are, without copying.
- Centralization only copies new log data. Historical data stays in the source account.
Exam signal
"Logs must be immutable for 7 years, even the root user can't delete them" means Object Lock compliance mode.
Governance mode can be bypassed by users with s3:BypassGovernanceRetention. See
S3 data protection.
Scenarios
An organization trail can't be changed by member accounts, covers new accounts automatically, and delivers to a bucket the members don't control. Object Lock compliance mode and digest files make the records immutable and provably complete. StackSet trails are owned by the members, so an admin can still alter settings the SCP doesn't cover. Event history keeps only 90 days. CloudTrail Lake is closed to new customers.
Resolver query logs record every name the instance resolves through the VPC resolver, which is what reveals a C2 domain. Flow logs show IP addresses but never domain names. Public DNS query logging records queries from the internet about the company's own domain, not outbound lookups. CloudTrail has no data events for DNS lookups.
Data events scoped with an advanced event selector capture object reads and deletes with the full identity for just that bucket, keeping cost down. Server access logs are best effort and can arrive hours late. Logging data events for every bucket meets the need but multiplies cost across 400 busy buckets. Macie classifies content and doesn't log access.
Further reading
Alerting and dashboards
Turning logs, metrics and findings into alerts with CloudWatch metric filters and alarms, EventBridge rules and AWS User Notifications, plus health checks, AWS Health, Trusted Advisor and Managed Grafana dashboards.
Log analysis
Querying and correlating security logs with CloudWatch Logs Insights, Athena, OpenSearch Service fed by Amazon Data Firehose, and Security Lake, plus parsing and normalizing logs with Lambda and OCSF.