Uncover blind spots in AWS data plane operations with CloudTrail Event Coverage

AWS CloudTrail introduces Event Coverage, a new console experience that gives customers visibility into their data plane operations coverage at the account and organization level. You can now see which AWS services and resource types in your environment have data event logging enabled and which do not. This helps you quickly identify gaps in your logging posture without manually scanning accounts in your organization.

Data events enable you to track data plane operations in AWS services. For example, you can log Amazon S3 object-level operations like GetObject and PutObject to detect unauthorized data access or exfiltration attempts. Without comprehensive data events coverage, these activities can go unnoticed, leaving blind spots in your security monitoring. With Event Coverage, you can view coverage across all supported data event sources in one place and subscribe to data events directly from the dashboard. This makes it easier to close coverage gaps in a few clicks, especially for organizations managing multiple accounts where tracking coverage across services can be time-consuming.

You can access Event Coverage from the AWS CloudTrail console. This feature is available in all commercial AWS Regions where AWS CloudTrail is supported. To learn more about logging Data Events, visit the AWS CloudTrail documentation.

Categories: general:products/aws-cloudtrail,marketing:marchitecture/management-and-governance,general:use-case/security-and-compliance

Source: Amazon Web Services

Share This Update