Control: At least one multi-region AWS CloudTrail should be present in an account
Description
AWS CloudTrail records AWS Management Console actions and API calls. You can identify which users and accounts called AWS, the source IP address from where the calls were made, and when the calls occurred. CloudTrail will deliver log files from all AWS Regions to your S3 bucket if MULTI_REGION_CLOUD_TRAIL_ENABLED is enabled.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.cloudtrail_multi_region_trail_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.cloudtrail_multi_region_trail_enabled --share
SQL
This control uses a named query:
cloudtrail_multi_region_trail_enabled