Try our new research platform with insights from 80,000+ expert users
Binoj BALAN - PeerSpot reviewer
Principal Solution Architect at StarOne IT Solutions
MSP
Top 5
Allows me to easily retrieve necessary details and lot of documentation available on the AWS website
Pros and Cons
  • "AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana."

    What is our primary use case?

    We use it for auditing to ensure secure AWS environments. Most of our customers require FSA compliance, which necessitates proper logging and auditing. We've enabled CloudTrail for most services for this reason.

    AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana. 

    Our software engineer can then visualize and perform a root cause analysis (RCA) of any issues that happen. So, it has accelerated both troubleshooting scenarios and proactive monitoring.

    How has it helped my organization?

    CloudTrail is invaluable for compliance, security, and auditing, especially during audits. It allows me to easily retrieve necessary details for our organization.

    However, it does increase the security and compliance angle. This covers everything. For example, if we take a customer from a healthcare perspective, I have all the HIPAA-related compliance services to ensure I can meet those requirements. It's not a problem.

    What is most valuable?

    I like Active Directory group policy auditing. If enabled, I receive automatic notifications when someone changes a password, eliminating the need to manually check Active Directory for these events.

    What needs improvement?

    It's getting better, but it's not perfect because technology landscapes and use cases constantly evolve. There's a lot happening, so it's not perfect. It's improving.

    Buyer's Guide
    AWS CloudTrail
    December 2024
    Learn what your peers think about AWS CloudTrail. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
    824,053 professionals have used our research since 2012.

    For how long have I used the solution?


    What do I think about the stability of the solution?

    It is a very stable product. I have not faced any issues in the cloud environment. 

    What do I think about the scalability of the solution?

    Anyone in our organization using AWS will be using CloudTrail. Security is built into our DNS, it doesn't separate.

    So, there are about 40 to 45 end users. 

    How are customer service and support?

    In the initial stages, when I faced challenges, I used to contact support very frequently. 

    However, once I started using CloudTrail for all accounts and became familiar with it, I was able to handle most configuration aspects from a CloudTrail standpoint without needing much assistance from AWS support.

    How was the initial setup?

    The initial setu is easy. There is a lot of documentation available on the AWS website. I can easily refer to that if I get stuck anywhere. 

    Plus, there's a great community available. If I just post a question there, I'm happy to get all the details. 

    Whether I was stuck, the community, all the documentation, or white papers provided me with the right solutions and answers. So there were no deployment roadblocks for me.

    CloudTrail is a native AWS service, so on-premises deployment isn't possible.

    What's my experience with pricing, setup cost, and licensing?

    It is a very cheap service because management is a SaaS offering from AWS.

    The cost depends on how many files you enable, but it's very compatible with other AWS tools.

    What other advice do I have?

    My advice depends on whether you're a BFSA customer or a healthcare customer. Specific parameters need to be enabled based on your industry. With that configuration, you'll be able to trigger notifications and pull out data.  

    Overall, I would rate the solution an eight out of ten because when you consider all business sectors like healthcare, shipping, retail, manufacturing, and research & development, each generates different types of files and events.  

    Disclosure: My company has a business relationship with this vendor other than being a customer:
    PeerSpot user
    Shashank N - PeerSpot reviewer
    Security Engineer-DevSecOps at a computer software company with 51-200 employees
    Real User
    Top 5Leaderboard
    Simplifies security monitoring and troubleshooting by making it easy to identify suspicious activity
    Pros and Cons
    • "It is a stable solution. AWS handles it well."
    • "Maybe if we could do direct queries on CloudTrail without needing to export it to Athena, that'd be great."

    What is our primary use case?

    It's like a native feature. It's like a single audit point for everything AWS. Any changes made by users or roles get saved in CloudTrail. It's gotta be enabled; it's the most important security feature on AWS.

    What needs improvement?

    Maybe if we could do direct queries on CloudTrail without needing to export it to Athena, that'd be great. 

    For how long have I used the solution?

    I have been using it for three years now. 

    What do I think about the stability of the solution?

    It is a stable solution. AWS handles it well.

    What do I think about the scalability of the solution?

    There are five to six admins using this solution, we don't have separate user groups.

    How was the initial setup?

    It is a one-click deployment.

    What's my experience with pricing, setup cost, and licensing?

    CloudTrail itself is free of cost. 

    What other advice do I have?

    I'd advise to integrate it with your security solution and correlate logs across AWS. That's the single point to start understanding if your account is compromised. And always keep a backup of the logs.

    And make sure those logs are kept in a separate AWS account from the main one. First thing any attacker would do is delete those logs to cover their tracks. Forensics becomes very tough without them.

    Overall, I would rate the solution a ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    AWS CloudTrail
    December 2024
    Learn what your peers think about AWS CloudTrail. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
    824,053 professionals have used our research since 2012.
    Olhbe456 - PeerSpot reviewer
    IT Infrastructure/Systems Admin at a financial services firm with 201-500 employees
    Real User
    Top 5Leaderboard
    Has a valuable feature for monitoring and a simple setup process
    Pros and Cons
    • "The product’s most valuable feature is monitoring. It helps us audit the changes in AWS account at the application and resource level."
    • "The platform’s reporting log sheet feature could be more user-friendly."

    What is our primary use case?

    We use the product for monitoring activities of AWS accounts in terms of operational review, governance, and compliance.

    What is most valuable?

    The product’s most valuable feature is monitoring. Changes in AWS account at the application and resource level are easily audited with cloudtrail.

    What needs improvement?

    The platform’s reporting log sheet feature could be more user-friendly.

    For how long have I used the solution?

    We have been using AWS CloudTrail for three years now.

    What do I think about the stability of the solution?

    It is a stable product.

    What do I think about the scalability of the solution?

    We have three administrators using AWS CloudTrail in our organization.

    How was the initial setup?

    The initial setup is easy. It has default functionality for application and resource-level monitoring of databases.

    What other advice do I have?

    I rate AWS CloudTrail an eight out of ten. I recommend the solution if you are auditing compliance and security for data usage.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user