setting-up-cloudtrail-multi-region

โดย aws

เปิดใช้งาน multi-region AWS CloudTrail trail พร้อมการจัดเก็บล็อกใน S3 การเชื่อมต่อ CloudWatch Logs และคิวรี CloudWatch Logs Insights สำหรับการตรวจสอบความปลอดภัยและ…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill setting-up-cloudtrail-multi-region

Setting Up CloudTrail Multi-Region

Overview

Domain expertise for enabling AWS CloudTrail across all regions to capture comprehensive API activity logs and configuring CloudWatch Logs Insights for security monitoring, compliance auditing, and operational analysis.

Set up a multi-region trail

To create a centralized multi-region CloudTrail trail with S3 storage, CloudWatch Logs integration, and log analysis, follow the procedure exactly. See CloudTrail multi-region setup procedure.

Troubleshooting

S3 bucket already exists

Choose a different globally unique name, or add a timestamp or organization identifier.

Permission denied errors

Verify your identity with aws sts get-caller-identity. Ensure your user/role has required actions attached. Do NOT use *FullAccess managed policies.

Trail not logging

Verify IAM role permissions, check S3 bucket policy allows CloudTrail access, and ensure the trail is started with start-logging.

Missing events in CloudWatch

Allow 5-15 minutes for initial log delivery. Verify the CloudWatch Logs role ARN is correct and the log group exists in the same region as the trail.

Opt-in region events not appearing

This is normal — events from opt-in regions may take several hours. Wait up to 24 hours before investigating further.

Skills เพิ่มเติมจาก aws

agents-build
aws
ใช้เพื่อขยายโปรเจกต์ agent ที่มีอยู่ด้วย memory, การผสานรวมแอป, VPC, multi-agent, การย้ายระบบ, โมเดล, เบราว์เซอร์, code interpreter, การชำระเงิน หรือทรัพยากร…
official
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
official
agents-debug
aws
ใช้เมื่อเอเจนต์หรือสภาพแวดล้อมของคุณมีปัญหา เช่น คำตอบที่ผิด ข้อผิดพลาด หมดเวลา เครื่องมือล้มเหลว หรือปัญหา CLI อ่านเทรซและล็อกเพื่อวินิจฉัยสาเหตุต้นตอ…
official
agents-deploy
aws
ใช้เมื่อกำลัง部署เอเจนต์ของคุณไปยัง AWS หรือเมื่อการ部署ล้มเหลว จัดการการตรวจสอบก่อน部署 การวินิจฉัยข้อผิดพลาด CDK/IAM/โควตา การจัดการเวอร์ชัน การย้อนกลับ…
official
agents-get-started
aws
ใช้เมื่อนักพัฒนาต้องการสร้างโปรเจกต์เอเจนต์ใหม่หรือเริ่มต้นใช้งาน AgentCore จัดการเกี่ยวกับการเลือกเฟรมเวิร์ก การสร้างโครงโปรเจกต์ การดีพลอยครั้งแรก และ…
official
agents-harden
aws
Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate…
official
agents-pay
aws
Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official