More Info:

Your CloudTrail trails should be recording both regional and global events in order to increase the visibility of the API activity in your AWS account for security and management purposes.

Risk Level

Medium

Address

Security

Compliance Standards

AWSWAF, GDPR, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Trails Should Record Both Regional And Global Events” for AWS using AWS console, you can follow these steps:

  1. Open the AWS Management Console and navigate to the CloudTrail service.

  2. Select the trail that you want to update.

  3. Click on the “Edit” button.

  4. In the “Event selectors” section, make sure that “All” is selected under “Data events”.

  5. Under “Management events”, select “Global services” and “Regional services”.

  6. Click on the “Save” button to save the changes.

  7. Verify that the trail is now recording both regional and global events by checking the “Event history” tab for the trail.

By following these steps, you can remediate the misconfiguration “Trails Should Record Both Regional And Global Events” for AWS using AWS console.

Additional Reading: