What is our primary use case?
We use it for auditing to ensure secure AWS environments. Most of our customers require FSA compliance, which necessitates proper logging and auditing. We've enabled CloudTrail for most services for this reason.
AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana.
Our software engineer can then visualize and perform a root cause analysis (RCA) of any issues that happen. So, it has accelerated both troubleshooting scenarios and proactive monitoring.
How has it helped my organization?
CloudTrail is invaluable for compliance, security, and auditing, especially during audits. It allows me to easily retrieve necessary details for our organization.
However, it does increase the security and compliance angle. This covers everything. For example, if we take a customer from a healthcare perspective, I have all the HIPAA-related compliance services to ensure I can meet those requirements. It's not a problem.
What is most valuable?
I like Active Directory group policy auditing. If enabled, I receive automatic notifications when someone changes a password, eliminating the need to manually check Active Directory for these events.
What needs improvement?
It's getting better, but it's not perfect because technology landscapes and use cases constantly evolve. There's a lot happening, so it's not perfect. It's improving.
Buyer's Guide
AWS CloudTrail
December 2024
Learn what your peers think about AWS CloudTrail. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
For how long have I used the solution?
What do I think about the stability of the solution?
It is a very stable product. I have not faced any issues in the cloud environment.
What do I think about the scalability of the solution?
Anyone in our organization using AWS will be using CloudTrail. Security is built into our DNS, it doesn't separate.
So, there are about 40 to 45 end users.
How are customer service and support?
In the initial stages, when I faced challenges, I used to contact support very frequently.
However, once I started using CloudTrail for all accounts and became familiar with it, I was able to handle most configuration aspects from a CloudTrail standpoint without needing much assistance from AWS support.
How was the initial setup?
The initial setu is easy. There is a lot of documentation available on the AWS website. I can easily refer to that if I get stuck anywhere.
Plus, there's a great community available. If I just post a question there, I'm happy to get all the details.
Whether I was stuck, the community, all the documentation, or white papers provided me with the right solutions and answers. So there were no deployment roadblocks for me.
CloudTrail is a native AWS service, so on-premises deployment isn't possible.
What's my experience with pricing, setup cost, and licensing?
It is a very cheap service because management is a SaaS offering from AWS.
The cost depends on how many files you enable, but it's very compatible with other AWS tools.
What other advice do I have?
My advice depends on whether you're a BFSA customer or a healthcare customer. Specific parameters need to be enabled based on your industry. With that configuration, you'll be able to trigger notifications and pull out data.
Overall, I would rate the solution an eight out of ten because when you consider all business sectors like healthcare, shipping, retail, manufacturing, and research & development, each generates different types of files and events.
Disclosure: My company has a business relationship with this vendor other than being a customer: