Ensure that only one trail within your Amazon CloudTrail multi-region logging configuration has the capability to record global service events in order to avoid duplicate log events for AWS global services such as Amazon Identity and Access Management (IAM), Security Token Service (STS) or AWS CloudFront.
This rule can help you with the following compliance standards:
- APRA
- MAS
- NIST 800-53 (Rev. 4)
This rule resolution is part of the Cloud Conformity Security & Compliance tool for AWS
When you have multiple single region trails created in your AWS account, the events recorded for certain global services are duplicated in the log files as each region trail writes the same events to the CloudTrail aggregated log. In order to prevent log data duplication, the global service events tracking must be enabled for one trail only and disabled for all other trails, from other regions, that write to the same CloudTrail log.
Note: This conformity rule assumes that you have multiple single region trails (i.e. multi-region configuration) already available within your AWS account.
Audit
To determine if more than one single region trails record global service events, perform the following actions:
Note: Checking Amazon CloudTrail global service events logging configuration using AWS Management Console is not currently supported. The trails created using the AWS Management Console are recording global service events by default.Remediation / Resolution
To disable API tracking/logging for AWS global services in the subsequent single region trails, perform the following actions:
Note: Enabling AWS CloudTrail logging global service events using AWS Management Console is not currently supported. The trails created using the AWS Management Console are recording global service events by default.References
- AWS Documentation:Remediation
- AWS CloudTrail FAQs
- About Global Service Events
- Creating a Trail For Your AWS Account
- Creating, Updating, and Managing Trails with the AWS Command Line Interface
- Using update-trail
- AWS Command Line Interface (CLI) Documentation:
- cloudtrail
- describe-trails
- update-trail
Unlock the Remediation Steps
Gain free unlimited access
to our full Knowledge Base
Over 750 rules & best practices
for and
Get started for FREE
You are auditing:
Avoid Duplicate Entries in Amazon CloudTrail Logs
Risk level: Medium