AWS CloudTrail (original) (raw)

Last Updated : 4 Feb, 2026

AWS CloudTrail records and tracks all activities within your AWS account, providing a complete history of user, service, and resource actions. It helps improve security, compliance, auditing, and troubleshooting without requiring manual setup.

AWS CloudTrail

AWS CloudTrail enables governance, compliance, and security auditing by recording all API calls made in an AWS account. It logs details such as the caller identity, time, source IP, request parameters, and responses. This detailed tracking helps monitor activity, analyze security events, troubleshoot issues, and meet compliance requirements across your AWS infrastructure.

CloudTrail provides three ways to record events:

**AWS CloudTrail Architecture

The AWS account activity we perform lasts for 90 days in the same place. It is possible to keep event logs in an S3 bucket for longer than 90 days. SNS notification (Simple Notification Service) configuration is also possible in Cloud Trail.

awscloud_trail

AWS Cloud trail

**Benefits of using AWS CloudTrail in AWS

**AWS CloudTrail Working

Your Amazon Web Services (AWS) account's activity is tracked and recorded by the AWS CloudTrail service. It offers thorough logs of all API calls and operations made on your AWS resources. This is how AWS CloudTrail functions:

AWS CloudTrail features

**Steps to set up AWS CloudTrail

**Step 1: Login to AWS Console

**Step 2: **Access AWS Academy Learner Lab

**Step 3: Launch AWS Academy Learner Lab

Login

**Step 4: Open CloudTrail Service

Open CloudTrail Service

**Step 5: **Create CloudTrail

Cloud trail

**Step 6: **Edit Storage Location

General details

**Step 7: **Save Changes

My Trail

**Step 8: **Confirm Settings

Cloud trail **Step 9: **Monitor Data Events

Upload Object

Amazon S3 Objects

**Step 10: Access and Review Event Data

Accessing CloudTrail

Accessing AWS CloudTrail Using These Methods:

AWS CloudTrail Use cases