EvoHub Docs Sign in

Integrations

AWS CloudTrail

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

CloudTrail needs no integration of its own. Send the trail to CloudWatch Logs, turn the events you care about into a CloudWatch alarm with a metric filter, and send the alarm to EvoHub through the AWS CloudWatch integration. The alert resolves when the alarm returns to OK.

Set it up

Create a CloudWatch integration

In EvoHub, add an AWS CloudWatch integration and subscribe its webhook URL to an SNS topic (HTTPS, raw message delivery off), as described in AWS CloudWatch.

Send the trail to CloudWatch Logs

In the CloudTrail console, edit the trail and turn on CloudWatch Logs, choosing a log group.

Create a metric filter

In CloudWatch, open the log group, choose Create metric filter and paste a pattern (examples below). Give the metric a name and a value of 1.

Create the alarm

Create an alarm on the metric: statistic Sum, period 5 minutes, threshold greater than or equal to 1, and treat missing data as not breaching. Set the SNS topic as both the In alarm and the OK action.

Example filters

Root user sign-in or API use:

{ $.userIdentity.type = "Root" && $.userIdentity.invokedBy NOT EXISTS && $.eventType != "AwsServiceEvent" }

Logging stopped or the trail changed:

{ ($.eventName = StopLogging) || ($.eventName = DeleteTrail) || ($.eventName = UpdateTrail) }

The alert title is the alarm name, so name each alarm after what it watches.

Last updated