Control Tower and Baseline CloudTrail versus Organizational Trail

0

Can someone please explain what the difference is between the Trail that is created when you create Control Tower versus an Organizational Trail? I created an Org Trail and when i create a new OU, i dont see that action in the cloudwatch logs that is being fed by the baseline trail, but i do see it in my manually created Org Trail and cloudwatch logs. What am i missing? What does the Control Tower Baseline Trail log?

질문됨 2년 전2045회 조회
2개 답변
0

Control Tower generated CloudTrail by default logs management events and pushes logs to CloudWatch logs and S3 bucket.

AWS Control Tower is integrated with AWS CloudTrail, a service that provides a record of actions taken by a user, role, or an AWS service in AWS Control Tower. CloudTrail captures actions for AWS Control Tower as events. If you create a trail, you can enable continuous delivery of CloudTrail events to an Amazon S3 bucket, including events for AWS Control Tower.

CloudTrail is enabled on your AWS account when you create the account.

For organizations trail, it depends on what you enable on the trail but the trail is created in linked accounts in the organization as well. Unless you have any specific use case for having two same trails, it is best to keep the control tower trail to optimize cost. When you have multiple trails on an account, you incur costs for any additional copies of events delivered. This blog post talks about integrating existing CloudTrail configurations with control tower.

AWS
Taka_M
답변함 2년 전
0

Just side note: since Control Tower v3 (July 2022) Organizational Trail is and option for Control Tower https://aws.amazon.com/about-aws/whats-new/2022/07/aws-control-tower-adopts-aws-cloudtrail-organization-logging/

aortega
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠