CloudTrail works

When you create an AWS account, the account will be enabled CloudTrail. When events occurred your AWS account, the event will be recorded in CloudTrail event. You can go to  Event history (event history)  to easily see CloudTrail console events.

Use Event History, you can view, search and download AWS account in the past 90 days of activity. In addition, you can also create a CloudTrail tracking to archive, analyze and respond to changes in your AWS resources. Tracking is a configuration that can be used to transfer the event to your specified Amazon S3 bucket. Event delivery tracking and analysis of Amazon CloudWatch Logs and Amazon CloudWatch Events can also be used. You can use CloudTrail console, create tracking AWS CLI or CloudTrail API.

It applies to all areas of the track

When you create a tracking applied to all regions, CloudTrail records every event in the area and transfers CloudTrail event log file to your designated S3 bucket. If you create an application to keep track of all regions and then add a region, the new region will be automatically included in the area of the event will also be recorded. When you create a tracking CloudTrail console, which is the default option. For more information, see Create a tracking console .

Used in tracking a region

When you create a tracking applies only to a region, CloudTrail in the area of event records only. It then CloudTrail event log files to your specified Amazon S3 bucket. If you create another single track, you can make these transfers CloudTrail track event log files to the same Amazon S3 bucket or a separate bucket. This is done using AWS CLI or CloudTrail API creates the default option when tracking. For more information, see Create and update tracking the Command Line Interface using AWS .

note

For both types of tracking, you can specify the Amazon S3 bucket from any region.

 

From April 12, 2019 start, tracking can only be viewed in the AWS region recorded event. If you create a record of all trace AWS events in the region, it will show the console in all AWS regions. If you create only a single logging area in the event of AWS, you can view and manage it in the AWS region.

Guess you like

Origin www.cnblogs.com/cloudrivers/p/11258462.html