All Services

Mgmt & Governance

AWS CloudTrail

AWS CloudTrail records supported AWS API, console, service and account activity as management, data, Insights and network-activity events, delivering trails to S3 and CloudWatch Logs; CloudTrail Lake closed to new customers on May 31, 2026 while trails and other CloudTrail capabilities remain supported.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS CloudTrail.

Audit logging scope and event cost

AWS CloudTrail Pricing, Trails & CloudTrail Lake

CloudTrail records management events by default and keeps a searchable 90-day event history at no charge. Spending starts with the second copy of management events, with opt-in data events, and with CloudTrail Lake ingestion and retention.

Official AWS sources reviewed 2026-08-29.

What does AWS CloudTrail record?

CloudTrail captures account activity as events for AWS API calls and console actions. Management events are logged by default and the console keeps 90 days of control-plane history at no cost. Data events and network activity events are opt-in and selected per resource.

AWS CloudTrail user guide

What drives AWS CloudTrail pricing?

The first copy of management events delivered to a trail is free; additional copies bill per hundred thousand events. Data events and network activity events bill per event delivered, Insights bills per event analyzed, and the S3 bucket holding the logs is charged on its own.

Official AWS CloudTrail pricing

When is CloudTrail Lake worth the cost?

CloudTrail Lake stores events in a managed, queryable event data store with a chosen retention period, replacing a hand-built S3 and Athena query path. Ingestion is billed on uncompressed data while retention and queries are billed on compressed data, so scope each event data store narrowly.

Working with AWS CloudTrail Lake

Related AWS services for this plan

  • Amazon Simple Storage Service — Trails deliver logs to Amazon S3, so lifecycle rules and storage class drive the retention bill.
  • Amazon Athena — Query trail logs in S3 with Athena when a full CloudTrail Lake event data store is not justified.
  • AWS Organizations — Use an organization trail to capture member-account activity under one management-account configuration.
  • Amazon CloudWatch — Send trail events to CloudWatch Logs for metric filters and alarms on specific API activity.

AWS CloudTrail pricing and cost programs

Pricing model: Audit event and query usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Trail events · Lake ingestion and retention · Queries · Insights events

Programs and modes: Event history · Trails · CloudTrail Lake · Insights

Event history, trails, Lake, and Insights have distinct included usage and pricing.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS CloudTrail?

  • Creates an authoritative history of supported control-plane activity and selected high-volume data-plane or network events across accounts and Regions.
  • Delivers durable logs to customer-owned S3 and optional CloudWatch Logs for detection, retention, query and incident-response workflows.
  • Supports organization trails, event history, Insights, digest-file validation, EventBridge integration, advanced selectors and service integrations.

How to implement AWS CloudTrail

  1. Define accounts, Regions, management, data, Insights and network events, exclusion rules, retention, immutable-copy, encryption, access, query, detection, legal hold and cost requirements.
  2. Create a multi-Region organization trail from a delegated logging design, send it to a dedicated encrypted and versioned S3 bucket with restrictive policies and log-file validation, optionally stream to CloudWatch Logs, and select high-value data events precisely.
  3. Validate representative events and digest chains, alert on trail deletion or mutation and privileged actions, regularly test queries and incident access, monitor delivery errors and spend, and maintain an independent protected copy when required.

AWS CloudTrail best practices

  • Use an organization, multi-Region trail and protect its S3 bucket and KMS key from workload administrators; enable log-file validation and alert on any attempt to stop, delete or alter audit controls.
  • Capture management events broadly but scope high-volume data and network activity events to risk and investigation needs, document exclusions, and validate that assumed-role and service events answer attribution questions.
  • Do not design a new solution around CloudTrail Lake: it is no longer open to new customers as of May 31, 2026; existing users should review the AWS support and migration guidance while ordinary CloudTrail trails remain fully supported.

AWS CloudTrail use cases and server impact

  • Security investigations and accountability
  • Organization-wide control-plane audit
  • Detection of privileged or anomalous AWS activity

Replaces custom API-audit collectors and much durable delivery plumbing, while event selection, protected retention, data-event cost, detection logic, attribution, investigation, and independent evidence governance remain yours.

Official implementation resources

How AWS CloudTrail works with other AWS services

Arrows show the documented technical direction. Reciprocal navigation does not imply a reverse technical dependency.

Official AWS sources reviewed 2026-07-25.

AWS CloudTrail → Amazon Simple Storage Service

AWS CloudTrail delivers audit logs to Amazon Simple Storage Service

A CloudTrail trail delivers signed event log files to an S3 bucket for durable retention.

Why teams use it
Central storage supports audit, investigation, and longer retention beyond event history.
Permissions and networking
Use a dedicated, tightly controlled bucket, validate the required bucket policy, enable encryption and log-file validation, and prevent untrusted deletion.
Pricing and security caveats
S3 storage, requests, replication, and retrieval add cost; a trail must be configured for the events and Regions the organization needs.

AWS CloudTrail → Amazon CloudWatch

AWS CloudTrail delivers selected audit events to Amazon CloudWatch

CloudTrail can send trail events to a CloudWatch Logs log group, where metric filters and alarms detect selected API activity.

Why teams use it
The pairing turns audit events into near-real-time operational alerts without replacing the durable trail archive.
Permissions and networking
Create the delivery role and log group deliberately, limit access to audit data, set retention, and design filters to avoid noisy or bypassable alerts.
Pricing and security caveats
CloudWatch Logs ingestion, storage, queries, metrics, and alarms add charges, and delivery latency means this is not an inline authorization control.

AWS Identity and Access Management → AWS CloudTrail

AWS Identity and Access Management produces identity activity recorded by AWS CloudTrail

CloudTrail records supported IAM and AWS STS API activity with caller identity and request context.

Why teams use it
Teams use those events to investigate permission changes, role assumptions, and access-key activity.
Permissions and networking
Create organization-wide trails where appropriate, protect logs from modification, and alert on high-risk identity changes without logging secrets elsewhere.
Pricing and security caveats
CloudTrail records activity after authorization decisions; it does not enforce IAM policy. Data-event and Insights coverage can add cost.

Planning guides that use AWS CloudTrail