How to prevent cloudtrail log being modified and deleted? AWS CloudTrail provides a feature to validate the integrity of the CloudTrail log files stored in your S3 bucket. Does it help protect the logs from being modified an deleted as well?

asked 21 days ago
1 Answer
It doesn't prevent logs from being modified or deleted. You should implement least privilege access and enable MFA delete on the S3 bucket. Please refer to CloudTrail preventative security best practices.

answered 21 days ago
reviewed 21 days ago

