24/02/2026
βοΈ AWS CloudTrail β Simple + Complete (Features, Benefits, Pricing)
Iβll keep it clear, structured, and exam-ready.
π What is CloudTrail?
π It records everything happening in your AWS account
(Who did what, when, from where)
βοΈ Main Features (Very Important)
1. π§Ύ Management Events (IMPORTANT)
π Track account-level actions
Examples:
Create/Delete EC2
Create IAM user
Modify S3 bucket
π° Pricing:
β
FREE (by default in Event History β last 90 days)
β οΈ If you store in S3 via trail β small cost
2. π Data Events (IMPORTANT)
π Track actual data access (more detailed)
Examples:
File upload/download in Amazon S3
Running functions in AWS Lambda
π° Pricing:
β NOT FREE (paid)
Charged per event
More expensive because of high volume
3. π€οΈ Trails
π Used to save logs to S3
Single-region OR multi-region
π° Pricing:
β οΈ S3 storage cost applies
4. π Event History
π Shows last 90 days activity
π° Pricing:
β
FREE
5. π Log File Integrity Validation
π Detects if logs are changed
π° Pricing:
β
FREE feature
6. π CloudTrail Insights
π Detects unusual activity
Example:
Sudden spike in API calls
π° Pricing:
β PAID
7. π Integration with Amazon CloudWatch
π Real-time alerts & monitoring
π° Pricing:
β οΈ CloudWatch charges apply
π― Benefits of CloudTrail
π 1. Security
Track suspicious activity
Detect unauthorized access
π 2. Compliance
Helps in audits (GDPR, ISO, etc.)
Keeps activity records
π 3. Troubleshooting
Find who deleted/changed resources
ποΈ 4. Visibility
Full visibility of user actions
π‘οΈ 5. Tamper Detection
With integrity validation
π Know if logs are modified