Cloud Trail some events not found

0

I possess an IAM key for which the "last used" date indicates activity 15 hours ago. Yet, upon scrutinizing the CloudTrail logs filtered by the specific AWS access key for all events, there appears to be no record of activity associated with that key over the past few days. Furthermore, an examination of the CloudTrail logs via Athena yielded identical events to those displayed in the UI from a couple of days ago.

In the IAM user's Access Advisor report, one service indicates activity as recent as today. However, upon clicking on the service name, it becomes apparent that none of the permitted actions have been accessed for weeks.

What other entities could potentially be utilizing the AWS access key without leaving a trace in the CloudTrail logs? How can one identify such entities in the absence of CloudTrail logs?

1개 답변
1

By default, CloudTrail only logs management events, not data events. My first suggestion would be to turn on data event logging for the relevant service, and seeing if that leads you anywhere.

https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-concepts.html

or-wwn
답변함 3달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠