Selectively log network activity events by identity in AWS CloudTrail

Published
July 20, 2026
https://aws.amazon.com/about-aws/whats-new/2026/07/aws-cloudtrail-filter-useridentity-advance-selectors/

AWS CloudTrail Network Activity Event Filtering Enhancements

AWS has introduced enhanced event filtering for network activity events for VPC endpoints, allowing customers to control which network activity events are logged based on the IAM user identity making the API call. This feature helps in reducing logging costs and noise by capturing only unauthorized access attempts.

What to do

  • Configure selectors to log only access denied events from untrusted identities.
  • Combine UserIdentity conditions with other fields for fine-grained control.

This feature is available via the AWS Management Console, AWS CLI, and AWS SDKs in all AWS Regions where CloudTrail network activity events are supported.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.