Selectively log network activity events by identity in AWS CloudTrail
AWS CloudTrail ยท 2026-07-20
Actions
Technical Details
| Regions | all |
|---|---|
| Cost Impact | Decrease |
| IaC Impact | High |
What This Means
For DevOps Teams
Configure CloudTrail to use UserIdentity filtering for network activity events to log only relevant events, such as access denied events from untrusted identities, thereby reducing logging costs and improving security monitoring efficiency.
For Platform Teams
Adopt UserIdentity filtering in CloudTrail to provide fine-grained control over network activity event logging, enabling better security posture and cost optimization for the platform.
For Executives
Evaluate implementing UserIdentity filtering in CloudTrail to enhance security by selectively logging network activity events, reducing logging costs, and minimizing operational noise, leading to improved data perimeter strategies and better detection of unauthorized access attempts.