More Info:

Only one trail within a CloudTrail multi-region logging configuration should have Include Global Services feature enabled in order to avoid duplicate log events being recorded for the AWS global services such as IAM, STS or Cloudfront.

Risk Level

Medium

Address

Security

Compliance Standards

HIPAA

Triage and Remediation

Remediation

To remediate the duplicate entries issue in CloudTrail Logs in AWS using AWS Console, follow the below steps:

  1. Open the AWS Management Console and navigate to the CloudTrail service.

  2. In the CloudTrail dashboard, click on the Trails link on the left-hand side of the page.

  3. Select the trail that you want to remediate and click on the Edit button.

  4. Scroll down to the Event selectors section and click on the Edit button.

  5. In the Edit event selector dialog box, you will see a list of all the AWS services that are being logged by CloudTrail.

  6. To avoid duplicate entries, you need to ensure that the same events are not being logged twice.

  7. For example, if you see that the “S3” service is being logged twice, you can uncheck one of the checkboxes to avoid duplicate entries.

  8. Once you have made the necessary changes, click on the Save button to save the changes.

  9. Verify that the duplicate entries have been remediated by checking the CloudTrail logs for the selected trail.

By following these steps, you will be able to remediate the duplicate entries issue in CloudTrail Logs in AWS using AWS Console.

Additional Reading: