AWS CloudTrail

Hands-On

Demo

In this demo, we will:

  1. Create an S3 bucket for CloudTrail logs
  2. Set up a CloudTrail trail
  3. Configure CloudWatch Logs integration
  4. Generate sample API activity
  5. Analyze CloudTrail logs
  6. Test the setup
  7. Clean up resources

Agenda

Demo Overview

my-cloudtrail-logs-456444

Create S3 bucket

Create CloudTrail trail 

my-first-trail
my-aws-kms-key

Choose log events

Management events

Review and create

Create trail

Edit CloudWatch Logs

Test

Create test bucket

test-bucket-987928

Create Test User 

test-user

Create user

CloudTrail Event history

Open S3 Log

Search 

test-user

Check CloudWatch Logs

{$.userIdentity.userName = "test-user"}

Search for the Test User

Clean Up

Delete trail

Delete Test Bucket

Empty CloudTrail B ucket

permanently delete

Delete CloudTrail Bucket 

Empty CloudWatch Bucket 

permanently delete

Delete the Bucket 

Delete CloudWatch Log Group

Delete Test User

test-user

Delete IAM Role 

CloudTrail_CloudWatchLogs_Role

Delete KMS Key 

7

🙏

Thanks

for

Watching