CloudTrail - Setting bucket policy for multiple accounts

0

Hello AWS community, from the page "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-set-bucket-policy-for-multiple-accounts.html", can you please clarify on how to modify the existing policy. Just need someone to confirm if I have 4-5 accounts, I will add a line for each additional account whose log files you want delivered to this bucket. What about the SourceArn in the Condition? You are showing there primary and secondary trail, do I also have to add third, fourth and fifth trail - depending how many additional accounts I have? Hoping someone can also add a condition key for PrincipalOrgId to restrict access to the S3 bucket in this example as well. Please don't advise using Control Tower, as I am hoping to do this without. Is there perhaps a video someone creating this step by step - it would help a lot. Many thanks, Oisin

Oisin
질문됨 한 달 전98회 조회
1개 답변
0
profile picture
전문가
답변함 한 달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인