CloudTrail - Setting bucket policy for multiple accounts

0

Hello AWS community, from the page "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-set-bucket-policy-for-multiple-accounts.html", can you please clarify on how to modify the existing policy. Just need someone to confirm if I have 4-5 accounts, I will add a line for each additional account whose log files you want delivered to this bucket. What about the SourceArn in the Condition? You are showing there primary and secondary trail, do I also have to add third, fourth and fifth trail - depending how many additional accounts I have? Hoping someone can also add a condition key for PrincipalOrgId to restrict access to the S3 bucket in this example as well. Please don't advise using Control Tower, as I am hoping to do this without. Is there perhaps a video someone creating this step by step - it would help a lot. Many thanks, Oisin

Oisin
demandé il y a un mois99 vues
1 réponse
0
profile picture
EXPERT
répondu il y a un mois

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions