Try our new research platform with insights from 80,000+ expert users

AWS CloudTrail vs CyberArk Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS CloudTrail
Ranking in User Activity Monitoring
2nd
Average Rating
8.8
Number of Reviews
11
Ranking in other categories
No ranking in other categories
CyberArk Privileged Access ...
Ranking in User Activity Monitoring
1st
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Mainframe Security (2nd), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of February 2025, in the User Activity Monitoring category, the mindshare of AWS CloudTrail is 7.2%, down from 13.1% compared to the previous year. The mindshare of CyberArk Privileged Access Manager is 20.7%, down from 21.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Activity Monitoring
 

Featured Reviews

MuhammadMuhammad - PeerSpot reviewer
There is no downtime and administration is very simple
The setup experience was very bad. Initially, when we began migrating our teams and configuring systems like AWS CloudTrail, we encountered some complications. Understanding the administration and navigating access loops resulted in numerous emails. However, after three or four years of experience, we understand the platform. Five to seven people including support are required for deployment. I rate the initial setup a six out of ten, where one is difficult, and ten is easy.
Lasantha Wijesinghe - PeerSpot reviewer
We have visibility and control through real-time user behavior analytics
It took us some time to realize its benefits because there was a learning curve for us. It took us about a year to get our heads around this product and start effectively using it. It is a journey. It takes at least five years for any company to make this product very useful and reach maturity. It is not only the product's fault. The company needs to have a vision, and the company culture needs to go with it. Senior leadership needs to support the vision. You need to have lots of ingredients for success. If everything is in place, you will see success after one year. In the first year, it is a struggle for everybody. My company was bought by a bigger company, and they were very new to privileged access management. Everybody was struggling. The advice I would give is to have a good vision for privileged access management. You need dedicated teams, senior management support, and proper company policies and standards before implementing the solution. Start building knowledge slowly and avoid jumping into the deep end without preparation. I would rate CyberArk Privileged Access Manager a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the employees' activities, revealing that they were downloading specific files from our customer's environment. Without it enabled, we wouldn't have been aware of this."
"The product’s most valuable feature is monitoring. It helps us audit the changes in AWS account at the application and resource level."
"One of the most valuable features of AWS CloudTrail is its ability to track and monitor API calls detailedly."
"AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana."
"The solution is good as a central logging platform for showing all cloud events."
"What I found most valuable in AWS CloudTrail is that it provides a good context of what's happening in the environment, so it's an excellent way to baseline what's occurring. I also like that AWS CloudTrail helps with audits."
"It is a stable solution. AWS handles it well."
"AWS CloudTrail integrates with AWS Config and provides custom event, security, and compliance auditing."
"It supports lots of requirements in the privileged access management area."
"The implementation of the PSM proxy has reduced the specific risk of "insider attacks" on our domain controllers and SLDAP servers by eliminating direct user login by an open secure connection on the user's behalf without ever revealing the privileged credentials."
"Password rotation, session recording & isolation and on-demand privileges."
"The logs and reporting features are impressive."
"The solution is stable and reliable."
"Every aspect of the solution is very well integrated, and even that gives comfort. It is a fail-safe kind of environment."
"Within the solution, I love the fact that everything is recorded. The configuration capabilities are great, too."
"We have demoted a lot of domain admins and taken a lot of that away from people, giving it a shared account structure."
 

Cons

"The solution's operation visibility could be improved."
"The solution should incorporate visibility for CloudWatch events."
"Filtering multiple values within the console is a feature that has yet to exist in AWS CloudTrail. You can look up a user identity, service, or action, but you can't search for multiple dimensions."
"Maybe if we could do direct queries on CloudTrail without needing to export it to Athena, that'd be great."
"The product's initial setup phase is not pretty straightforward."
"More controls should be introduced in CloudTrail, especially to see the logs in CloudTrail itself without saving them in S3, as S3 starts to incur charges."
"Once the organization defines its policies, it must immediately enable AWS CloudTrail and integrate it with auto-remediation procedures using Lambda functions. This ensures that the main administrator can receive information quickly and on time without delay."
"I have not experienced any challenges while using it."
"CyberArk Privileged Access Manager is more expensive than its competitors, such as BeyondTrust, Delinea, and ManageEngine PAM360."
"I would like to see is the policy export and import. When we expend, we do not want to just hand do a policy."
"I'm not a fan of technical support with CyberArk. It's like jumping through red tape and hoops. Quite frankly, it's almost like when you call CyberArk you get the Help Desk or the level-one. I'm a level-one. I got the CCD, I know how to do the initial troubleshooting. When I call CyberArk it's because I can't figure the problem out. So I need a level-two, three, four. I don't need you to tell me, "Hey, open a ticket and then give me logs.""
"This is probably a common thing, but they do ask for a lot of log files, a lot of information. They ask you to provide a lot of information to them before they're willing to give you anything at all upfront. It would be better if they were a little more give-and-take upfront: "Why don't you try these couple of things while we take your log files and stuff and go research them?" A little bit of that might be more helpful."
"I would prefer that this is a fully-managed service, rather than have to manage the software ourselves and keep it up to date."
"The product is complex and requires extensive configuration."
"We found a lot of errors during the initial setup. They should work to improve the implementation experience and to remove errors from the process."
"The authentication port is available in CyberArk Alero but not Fortinet products."
 

Pricing and Cost Advice

"AWS CloudTrail is a cheap solution."
"AWS CloudTrail is pretty affordable, and I have to double-check, but the service is free to use. I can add logs on the console, but if I want to store logs long-term, then I have to pay a storage fee, but it's relatively inexpensive."
"It is a very cheap service because management is a SaaS offering from AWS."
"CloudTrail itself is free of cost."
"AWS CloudTrail is free."
"The solution is free if you don't need customizations but is not expensive otherwise."
"The product's licensing is yearly. I would rate the solution's pricing a six out of ten."
"There are no additional costs other than the standard licensing fees."
"It can be an expensive product."
"Overall, its pricing is really good. The main difference from all the other vendors is that they have one package that covers all the functionality and modules of the basic PAM, except the add-on modules like adware and server protection. It also doesn't include the licenses for domain controller protection or maybe an API call-related feature. For the basic privileged access management, the bundle pricing is really good, but when it comes to an agent-based solution for advanced cyber protection or application identity managers, it is expensive. Services are also very expensive if you hire the services team from CyberArk, but these guys are really good. For a couple of large banking projects, we had an experience with them. The banks wanted to have things quickly and efficiently, so we had to hire them. If we take four weeks, these guys can do everything on a weekend. They charge quite a big sum of money, but they know the system well."
"Before we bought it, they were licensing each function individually, which got complicated and very expensive. When we decided to buy it, it was much more straightforward and still quite expensive, but it brings a lot of value and risk reduction to the organization."
"CyberArk Enterprise Password Vault is a very expensive product."
"CyberArk Enterprise Password Vault's pricing is reasonable."
"I focus more on the technical side, but I hear customers say that if CyberArk was more affordable, they might have acquired more licenses. Some clients consider alternative solutions due to pricing concerns."
report
Use our free recommendation engine to learn which User Activity Monitoring solutions are best for your needs.
832,138 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Educational Organization
34%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about AWS CloudTrail?
In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the emplo...
What is your experience regarding pricing and costs for AWS CloudTrail?
The cost depends on the volume of logs generated from various services. So, depending on how many logs are gathered, it could vary from being cheap to expensive.
What needs improvement with AWS CloudTrail?
Right now, AWS CloudTrail is perfect. I have not experienced any challenges while using it.
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
CyberArk Privileged Access Manager is more expensive than its competitors, such as BeyondTrust, Delinea, and ManageEngine PAM360. While ManageEngine PAM360 offers similar flexibility and support at...
 

Also Known As

CloudTrail
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

HTC, British Gas, Solinor, 2C2P
Rockwell Automation
Find out what your peers are saying about AWS CloudTrail vs. CyberArk Privileged Access Manager and other solutions. Updated: January 2025.
832,138 professionals have used our research since 2012.