Ensure that your AWS CloudTrail trails are referencing active Simple Notification Service (SNS) topics in order to receive a notification for every log file delivery made to your S3 bucket.
excellence
When your trails are not referencing active SNS topics anymore, Amazon cannot send notifications each time CloudTrail publishes new log files to your S3 bucket, therefore you lose the ability to take immediate actions based on the logging information received from CloudTrail.
Audit
To identify any trails that are missing the capability to send notifications on log file delivery due to inactive SNS topics, perform the following actions:
Remediation / Resolution
To update any Amazon CloudTrail trails associated with missing SNS topics, perform the following:
References
- AWS Documentation
- AWS CloudTrail FAQs
- Configuring Amazon SNS Notifications for CloudTrail
- Configuring CloudTrail to Send Notifications
- Updating a Trail
- AWS Command Line Interface (CLI) Documentation
- cloudtrail
- describe-trails
- update-trail
- sns
- get-topic-attributes
- create-topic
- subscribe
- confirm-subscription
Unlock the Remediation Steps
Gain free unlimited access
to our full Knowledge Base
Over 750 rules & best practices
for and
Get started for FREE
You are auditing:
AWS CloudTrail Referencing Missing SNS Topic
Risk level: Medium