Mondoo Docs

AWS CloudTrail trail

aws.cloudtrail.trail MQL resource for querying AWS infrastructure with cnquery and cnspec.

AWSPrivate Resource

AWS CloudTrail trail

Min version: 5.15.0Defaults: name region

Relationships

Mini Map
AWS
5 resources · 6 relationshipsClick to select, expand fields to see properties.

Fields (15)

FieldTypeDescription
arnrequired
stringARN of the trail
cloudWatchLogsLogGroupArnrequired
stringGroup for logs endpoint to assume when writing to log group
cloudWatchLogsRoleArnrequired
stringRole for logs endpoint to assume when writing to log group
eventSelectors
[]dictSettings for the trail's configured event selectors
includeGlobalServiceEventsrequired
intWhether API calls from global services are included
isMultiRegionTrailrequired
intWhether the trail exists in multiple regions (false if single region)
isOrganizationTrailrequired
intWhether the trail is an organization trail (logs events for management and member accounts of the organization)
kmsKey
aws.kms.keyKMS key used to encrypt the logs
logFileValidationEnabledrequired
intWhether log file validation is enabled
logGroup
aws.cloudwatch.loggroupLog group where trail files are delivered
namerequired
stringName of the trail
regionrequired
stringRegion in which the trail was created (home region)
s3bucket
aws.s3.bucketS3 bucket where trail files are delivered
snsTopicARNrequired
stringARN of the SNS topic that the trail uses to send notifications
status
dictJSON list of information about the trail