Whenever we need to find out who made the API call or who terminated the instance or service. AWS CloudTrail was really helpful for me to figure out who the user is and who has triggered the action or made the API call. It helps find who terminated an instance or service. The tool was very helpful for me. I always check my CloudTrail logs and by username, and I could find a lot of helpful information.
Cloud - Solution Architect at a tech vendor with 1,001-5,000 employees
Offers users the ability to search for users who have made different API calls
Pros and Cons
- "From a scalability point of view, the tool has no issue, and it is completely fine."
- "The product's initial setup phase is not pretty straightforward."
What is our primary use case?
What needs improvement?
It would be good if we were able to integrate with other services as well. From what I am aware of, we do the monitoring. We can integrate AWS CloudTrail with CloudWatch, Amazon Athena, and EventBridge. If we can integrate AWS CloudTrail with more services, then it can be a more helpful product for the organization.
For how long have I used the solution?
I have been using AWS CloudTrail for years. I am a customer and user of Amazon tools.
What do I think about the scalability of the solution?
From a scalability point of view, the tool has no issue, and it is completely fine. Scalability-wise, I rate the solution a nine out of ten.
The tool has been set up and integrated with our company's services, so it exists in the cloud environment. Whoever has access to the cloud, mainly the DevOps team uses AWS CloudTrail to identify or zero down the event or the user who made the API call. The DevOps team mostly uses the tool to manage the cloud environment.
Buyer's Guide
AWS CloudTrail
February 2025
![PeerSpot Buyer's Guide](https://www.peerspot.com/images/peerspot_logo_lt.png)
Learn what your peers think about AWS CloudTrail. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
837,501 professionals have used our research since 2012.
Which solution did I use previously and why did I switch?
I have used AWS CloudFormation.
How was the initial setup?
The product's initial setup phase is not pretty straightforward. I will say that the setup phase is a little bit complex. You should have some knowledge when you are setting up AWS CloudTrail. On a scale of one to ten, I would rate the setup phase a six for the visibility.
From the time perspective, it doesn't take much time if you are aware of how to set up the tool, as it is quite a fast process and can be done in very less time.
What other advice do I have?
AWS CloudTrail's most valuable feature in enhancing your compliance audit is that it gives me the ability to search for users who have made different API calls, which is something I find really helpful in AWS in most cases. I searched for the user who made that API call or identified it easily by using the search feature in AWS CloudTrail.
My company has integrated AWS CloudTrail with Amazon EventBridge and Amazon Athena. When we integrated AWS CloudTrail with Amazon Athena, we could easily enhance our analysis. For example, if I want to identify the trend and isolate some activity by attribute or source IP address, then I will use CloudTrail logs integrated with Amazon Athena. I could easily isolate activities associated with the source IP address.
The tool is easy to use, and I rate it seven out of ten. You need to have some knowledge of AWS CloudTrail because you have to run some queries or filter the source IP address. You should have some knowledge about the tool.
I recommend the tool to others.
I have not used the tool's AI capabilities.
I rate the tool a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Aug 30, 2024
Flag as inappropriate![PeerSpot user](https://www.peerspot.com/assets/media/images/anonymous_avatar-ddad8308.png)
Security Engineer-DevSecOps at a computer software company with 51-200 employees
Simplifies security monitoring and troubleshooting by making it easy to identify suspicious activity
Pros and Cons
- "It is a stable solution. AWS handles it well."
- "Maybe if we could do direct queries on CloudTrail without needing to export it to Athena, that'd be great."
What is our primary use case?
It's like a native feature. It's like a single audit point for everything AWS. Any changes made by users or roles get saved in CloudTrail. It's gotta be enabled; it's the most important security feature on AWS.
What needs improvement?
Maybe if we could do direct queries on CloudTrail without needing to export it to Athena, that'd be great.
For how long have I used the solution?
I have been using it for three years now.
What do I think about the stability of the solution?
It is a stable solution. AWS handles it well.
What do I think about the scalability of the solution?
There are five to six admins using this solution, we don't have separate user groups.
How was the initial setup?
It is a one-click deployment.
What's my experience with pricing, setup cost, and licensing?
CloudTrail itself is free of cost.
What other advice do I have?
I'd advise to integrate it with your security solution and correlate logs across AWS. That's the single point to start understanding if your account is compromised. And always keep a backup of the logs.
And make sure those logs are kept in a separate AWS account from the main one. First thing any attacker would do is delete those logs to cover their tracks. Forensics becomes very tough without them.
Overall, I would rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
AWS CloudTrail
February 2025
![PeerSpot Buyer's Guide](https://www.peerspot.com/images/peerspot_logo_lt.png)
Learn what your peers think about AWS CloudTrail. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
837,501 professionals have used our research since 2012.
IT Infrastructure/Systems Admin at a financial services firm with 201-500 employees
Has a valuable feature for monitoring and a simple setup process
Pros and Cons
- "The product’s most valuable feature is monitoring. It helps us audit the changes in AWS account at the application and resource level."
- "The platform’s reporting log sheet feature could be more user-friendly."
What is our primary use case?
We use the product for monitoring activities of AWS accounts in terms of operational review, governance, and compliance.
What is most valuable?
The product’s most valuable feature is monitoring. Changes in AWS account at the application and resource level are easily audited with cloudtrail.
What needs improvement?
The platform’s reporting log sheet feature could be more user-friendly.
For how long have I used the solution?
We have been using AWS CloudTrail for three years now.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
We have three administrators using AWS CloudTrail in our organization.
How was the initial setup?
The initial setup is easy. It has default functionality for application and resource-level monitoring of databases.
What other advice do I have?
I rate AWS CloudTrail an eight out of ten. I recommend the solution if you are auditing compliance and security for data usage.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
![PeerSpot user](https://www.peerspot.com/assets/media/images/anonymous_avatar-ddad8308.png)
Buyer's Guide
Download our free AWS CloudTrail Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
User Activity MonitoringPopular Comparisons
CyberArk Privileged Access Manager
Ekran System
Buyer's Guide
Download our free AWS CloudTrail Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating User Activity Monitoring, what aspect do you think is the most important to look for?
- Looking for recommendations and a pros/cons template for software to detect insider threats
- What insider threat detection tool do you recommend to a company with a modest budget?
- What is your recommended software product to secure your LAN?
- What features are important in user activity monitoring software?
- What user activity monitoring software do you recommend?