You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When deploying LZA into a management account with CloudTrail organization trail enabled, and both s3DataEvents & lambdaDataEvents enabled we would expect a single Management event selector to be created and two data event selectors.
Instead, three management event selectors are created, this produces multiple copies of CloudTrail management events, incurring additional and significant CloudTrail event data costs.
This appears to be caused by calls to organizationsTrail.addEventSelector (example) which do not pass the third options argument. As a result, the includeManagementEvents option defaults to true for each additional event selector.
Within the AWSAccelerator-Organizations-CloudTrail trail we would expect a single management event selector to be created and two data event selectors. Management events should be recorded once within this trail.
Please complete the following information about the solution:
Version: 1.6.0
Region: eu-west-2
Was the solution modified from the version published on this repository? No
Have you checked your service quotas for the services this solution uses? Yes
Were there any errors in the CloudWatch Logs? No
Screenshots
The text was updated successfully, but these errors were encountered:
Describe the bug
When deploying LZA into a management account with CloudTrail organization trail enabled, and both
s3DataEvents
&lambdaDataEvents
enabled we would expect a single Management event selector to be created and two data event selectors.Instead, three management event selectors are created, this produces multiple copies of CloudTrail management events, incurring additional and significant CloudTrail event data costs.
This appears to be caused by calls to
organizationsTrail.addEventSelector
(example) which do not pass the third options argument. As a result, theincludeManagementEvents
option defaults totrue
for each additional event selector.Resulting configuration:
To Reproduce
global-config.yaml
:CloudTrail -> Trails
AWSAccelerator-Organizations-CloudTrail
Expected behavior
Within the
AWSAccelerator-Organizations-CloudTrail
trail we would expect a single management event selector to be created and two data event selectors. Management events should be recorded once within this trail.Please complete the following information about the solution:
Screenshots
![Screenshot 2024-05-10 at 13 40 24](https://private-user-images.githubusercontent.com/783245/329595292-09b8a693-bbb8-4418-8dd9-dbc8bc189144.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MTgzODY4MTUsIm5iZiI6MTcxODM4NjUxNSwicGF0aCI6Ii83ODMyNDUvMzI5NTk1MjkyLTA5YjhhNjkzLWJiYjgtNDQxOC04ZGQ5LWRiYzhiYzE4OTE0NC5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjQwNjE0JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI0MDYxNFQxNzM1MTVaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1hMTljYjEwY2VmNzgyMDcwZTIwOGIyN2RjNjdkOWJhNjc0OGEzNDdiZGVhNjVjMmQzMjk0NDlkYjMzZTYyMjY0JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9.nQKGQ968bU477P03Seul3inPhhyF3C6zRr4hislZ-9Y)
The text was updated successfully, but these errors were encountered: