Selectively log network activity events by identity in AWS CloudTrail

AWS CloudTrail ยท 2026-07-20

Actions

Rate this issue

Technical Details

Regions all
Cost Impact Decrease
IaC Impact High

What This Means

For DevOps Teams

Configure CloudTrail to use UserIdentity filtering for network activity events to log only relevant events, such as access denied events from untrusted identities, thereby reducing logging costs and improving security monitoring efficiency.

For Platform Teams

Adopt UserIdentity filtering in CloudTrail to provide fine-grained control over network activity event logging, enabling better security posture and cost optimization for the platform.

For Executives

Evaluate implementing UserIdentity filtering in CloudTrail to enhance security by selectively logging network activity events, reducing logging costs, and minimizing operational noise, leading to improved data perimeter strategies and better detection of unauthorized access attempts.

Source

View original AWS announcement โ†’

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.