setting-up-cloudtrail-multi-region

oleh aws

Mengaktifkan jejak AWS CloudTrail multi-region dengan penyimpanan log S3, integrasi CloudWatch Logs, dan kueri CloudWatch Logs Insights untuk pemantauan keamanan dan…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill setting-up-cloudtrail-multi-region

Setting Up CloudTrail Multi-Region

Overview

Domain expertise for enabling AWS CloudTrail across all regions to capture comprehensive API activity logs and configuring CloudWatch Logs Insights for security monitoring, compliance auditing, and operational analysis.

Set up a multi-region trail

To create a centralized multi-region CloudTrail trail with S3 storage, CloudWatch Logs integration, and log analysis, follow the procedure exactly. See CloudTrail multi-region setup procedure.

Troubleshooting

S3 bucket already exists

Choose a different globally unique name, or add a timestamp or organization identifier.

Permission denied errors

Verify your identity with aws sts get-caller-identity. Ensure your user/role has required actions attached. Do NOT use *FullAccess managed policies.

Trail not logging

Verify IAM role permissions, check S3 bucket policy allows CloudTrail access, and ensure the trail is started with start-logging.

Missing events in CloudWatch

Allow 5-15 minutes for initial log delivery. Verify the CloudWatch Logs role ARN is correct and the log group exists in the same region as the trail.

Opt-in region events not appearing

This is normal — events from opt-in regions may take several hours. Wait up to 24 hours before investigating further.

Lebih banyak skill dari aws

agents-build
aws
Digunakan untuk memperluas proyek agen yang ada dengan memori, integrasi aplikasi, VPC, multi-agen, migrasi, model, browser, interpreter kode, pembayaran, atau sumber daya…
official
agents-connect
aws
Gunakan saat menghubungkan agen Anda ke API, alat, atau layanan eksternal melalui Gateway, atau membatasi akses alat dengan kebijakan Cedar. Menangani penyiapan gateway, target…
official
agents-debug
aws
Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes.…
official
agents-deploy
aws
Gunakan saat men-deploy agen Anda ke AWS, atau saat deploy gagal. Menangani validasi pra-penerbangan, diagnosis error CDK/IAM/kuota, manajemen versi, rollback,…
official
agents-get-started
aws
Gunakan saat pengembang ingin membuat proyek agen baru atau memulai dengan AgentCore. Menangani pemilihan framework, pembuatan kerangka proyek, deploy pertama, dan…
official
agents-harden
aws
Gunakan saat menyiapkan agen Anda untuk produksi — pembatasan IAM, autentikasi masuk (JWT, SigV4), manajemen rahasia, optimasi cold start, siklus hidup sesi, tingkat…
official
agents-pay
aws
Gunakan saat agent ini perlu membayar konten yang dilindungi x402 saat runtime: menemui paywall di tengah tugas, menyelesaikannya melalui AgentCore Payments, dan menerapkan…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — membuat, memodifikasi, dan memberikan saran pada klaster Aurora MySQL secara khusus (mesin yang kompatibel dengan MySQL, Aurora serverless, parallel query).…
official