Uncover blind spots in AWS data plane operations with CloudTrail Event Coverage

AWS CloudTrail Event Coverage
AWS CloudTrail introduces Event Coverage, a new console experience that provides visibility into data plane operations coverage at the account and organization level. You can now see which AWS services and resource types have data event logging enabled and which do not.
Data events enable tracking of data plane operations in AWS services, such as logging Amazon S3 object-level operations like GetObject and PutObject to detect unauthorized data access or exfiltration attempts. Without comprehensive data events coverage, these activities can go unnoticed, leaving blind spots in your security monitoring.
With Event Coverage, you can view coverage across all supported data event sources in one place and subscribe to data events directly from the dashboard. This feature is available in all commercial AWS Regions where AWS CloudTrail is supported.
What to do
- Access Event Coverage from the AWS CloudTrail console.
- Subscribe to data events directly from the dashboard to close coverage gaps.
- Visit the AWS CloudTrail documentation to learn more about logging Data Events.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



