Selectively log network activity events by identity in AWS CloudTrail

AWS CloudTrail Network Activity Event Filtering Enhancements
AWS has introduced enhanced event filtering for network activity events for VPC endpoints, allowing customers to control which network activity events are logged based on the IAM user identity making the API call. This feature helps in reducing logging costs and noise by capturing only unauthorized access attempts.
What to do
- Configure selectors to log only access denied events from untrusted identities.
- Combine UserIdentity conditions with other fields for fine-grained control.
This feature is available via the AWS Management Console, AWS CLI, and AWS SDKs in all AWS Regions where CloudTrail network activity events are supported.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



