Table of Contents

  1. AWS CloudTrail Overview
  2. CloudTrail Trails
  3. Event Types (Management vs. Data)
  4. Log File Storage & Encryption
  5. Log Consolidation (Multiple Accounts)
  6. Integration with CloudWatch Logs
  7. Log File Integrity Validation
  8. CloudWatch vs. CloudTrail Comparison
  9. Important Exam Tips & Tricks

AWS CloudTrail Overview


CloudTrail Trails


Event Types (Management vs. Data)


Log File Storage & Encryption


Log Consolidation (Multiple Accounts)


Integration with CloudWatch Logs


Log File Integrity Validation


CloudWatch vs. CloudTrail Comparison

Characteristic AWS CloudWatch AWS CloudTrail
Primary Focus Performance monitoring, operational health, resource utilization. Auditing, governance, compliance, security analysis.
What it Logs Logs events across AWS services (operational data, application logs, metrics). Logs API activity across AWS services (actions, events).
Level of Detail Higher-level comprehensive monitoring and events. More low-level, granular API activity.
Data Origin Metrics from services, custom metrics, application logs. API calls made by users, roles, or AWS services.
Storage Logs stored to CloudWatch Logs (configurable retention). Metrics stored for 15 months. Logs delivered to S3 (indefinite storage). Event History (console) for 90 days.
Alarms Native alarming capabilities based on metrics and log patterns. No native alarming; integrates with CloudWatch Logs to create alarms.
Cost Charges for metrics, logs ingestion/storage, alarms. Charges for management events (after free tier) and data events. S3 storage costs.

Important Exam Tips & Tricks