How to use CloudWatch after Control Tower version 3.0 update

0

We have a multi-account setup where we deployed an organizational-level CloudTrail in our root account's Control Tower.

For the newest version of the Control Tower (3.0), AWS introduced Organizational-level CloudTrail, this service deploys a baseline CloudTrail in each of our respective accounts and provides them the ability to send logs to a central CloudWatch location in our Root account and to a central S3 location in our logging account.

We have concerns regarding providing access to the root account just to be able to view the centralized CloudWatch logs.

I have tried setting up Athena in our Logging account so that our team can view the logs in our logging bucket, but that feels like I'm taking an unnecessary detour.

What is the best way to still be able to access the root account's CloudWatch logs without having to be in the root account?

Any advice would be appreciated!

Thanks in advance!

1 Risposta
0

Instead of using the root account (management account), you can add a delegated administrator to manage an organization's CloudTrail resources.

For more details, please refers to the documentation at: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-add-delegated-administrator.html

AWS
con risposta un anno fa

Accesso non effettuato. Accedi per postare una risposta.

Una buona risposta soddisfa chiaramente la domanda, fornisce un feedback costruttivo e incoraggia la crescita professionale del richiedente.

Linee guida per rispondere alle domande