# AWS CloudTrail

CloudTrail needs no integration of its own. Send the trail to CloudWatch Logs, turn the events you care about into a CloudWatch alarm with a **metric filter**, and send the alarm to EvoHub through the [AWS CloudWatch](https://docs-dev.evohub.io/integrations-overview.md#aws-cloudwatch) integration. The alert resolves when the alarm returns to OK.

## Set it up

:::steps
### Create a CloudWatch integration
In EvoHub, add an **AWS CloudWatch** integration and subscribe its webhook URL to an SNS topic (HTTPS, raw message delivery off), as described in [AWS CloudWatch](https://docs-dev.evohub.io/integrations-overview.md#aws-cloudwatch).
### Send the trail to CloudWatch Logs
In the CloudTrail console, edit the trail and turn on **CloudWatch Logs**, choosing a log group.
### Create a metric filter
In CloudWatch, open the log group, choose **Create metric filter** and paste a pattern (examples below). Give the metric a name and a value of `1`.
### Create the alarm
Create an alarm on the metric: statistic **Sum**, period 5 minutes, threshold **greater than or equal to 1**, and **treat missing data as not breaching**. Set the SNS topic as both the **In alarm** and the **OK** action.
:::

## Example filters

Root user sign-in or API use:

```text
{ $.userIdentity.type = "Root" && $.userIdentity.invokedBy NOT EXISTS && $.eventType != "AwsServiceEvent" }
```

Logging stopped or the trail changed:

```text
{ ($.eventName = StopLogging) || ($.eventName = DeleteTrail) || ($.eventName = UpdateTrail) }
```

The alert title is the alarm name, so name each alarm after what it watches.

## Related

- [AWS EventBridge](https://docs-dev.evohub.io/aws-eventbridge.md)
- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
