Fortinet white logo
Fortinet white logo

Alerts Reference

CloudTrail Stopped

CloudTrail Stopped

Note

This alert is disabled by default. You still retain full visibility through the AWS CloudTrail log CloudTrail Changed. You can also re-enable the alert manually if needed.

This alert occurs when Lacework FortiCNAPP detects AWS CloudTrail logging has been stopped.

Why this alert is important

CloudTrail is one of the important logging sources available in AWS. CloudTrail changes can significantly impact the logs received. Any unauthorized change to CloudTrail can limit the logging capability across the AWS account, thus limiting the visibility across AWS instances. Stopping CloudTrail logging would adversely affect visibility across AWS instances.

Investigation

Search for unauthorized changes to the CloudTrail service on the AWS instance. Revert unauthorized changes.

Resolution

Revert unauthorized changes made to CloudTrail. Restart CloudTrail logging for the selected AWS instances.

Related Information

https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html

CloudTrail Stopped

CloudTrail Stopped

Note

This alert is disabled by default. You still retain full visibility through the AWS CloudTrail log CloudTrail Changed. You can also re-enable the alert manually if needed.

This alert occurs when Lacework FortiCNAPP detects AWS CloudTrail logging has been stopped.

Why this alert is important

CloudTrail is one of the important logging sources available in AWS. CloudTrail changes can significantly impact the logs received. Any unauthorized change to CloudTrail can limit the logging capability across the AWS account, thus limiting the visibility across AWS instances. Stopping CloudTrail logging would adversely affect visibility across AWS instances.

Investigation

Search for unauthorized changes to the CloudTrail service on the AWS instance. Revert unauthorized changes.

Resolution

Revert unauthorized changes made to CloudTrail. Restart CloudTrail logging for the selected AWS instances.

Related Information

https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html