An organization is setting up a centralized logging solution across multiple accounts in their cloud environment. The security team requires that logs from all accounts be sent to a single security account, with lifecycle policies to transition logs to cheaper storage after 90 days. Which approach should be used?
Trap 1: Enable the cloud provider's native audit logging in each account…
Manually copying logs is inefficient and error-prone.
Trap 2: Create an audit log configuration in each account and export logs…
This approach uses a cross-account subscription, which is possible but not the simplest method; it requires additional configuration and may not leverage the organization management service.
Trap 3: Use a serverless function to copy logs from each account's storage…
Using a serverless function introduces additional complexity and cost.
- A
Enable the cloud provider's native audit logging in each account and manually copy logs daily to the security account.
Why it fails: Manually copying logs is inefficient and error-prone.
- B
Create an audit log configuration in each account and export logs to a centralized monitoring service, then use cross-account log forwarding to a central storage container.
Why it fails: This approach uses a cross-account subscription, which is possible but not the simplest method; it requires additional configuration and may not leverage the organization management service.
- C
Use a serverless function to copy logs from each account's storage container to the central storage container.
Why it fails: Using a serverless function introduces additional complexity and cost.
- D
Use the cloud provider's organizational structure and enable a single audit logging configuration that delivers logs to a central storage container in the management account.
AWS Organizations lets you attach a single organisation-wide CloudTrail trail delivering every account's logs to one central S3 bucket in the management or security account. S3 lifecycle policies then transition objects to cheaper classes after 90 days, meeting both centralisation and cost-retention requirements.