Control: CloudTrail multi region trails should be integrated with CloudWatch logs
Description
Ensure that CloudTrail multi region trail is itegrated with CloudWatch logs.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.cloudtrail_multi_region_trail_integrated_with_logs
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.cloudtrail_multi_region_trail_integrated_with_logs --share
SQL
This control uses a named query:
select arn as resource, case when log_group_arn != 'null' and ((latest_delivery_time) > current_date - 1) then 'ok' else 'alarm' end as status, case when log_group_arn != 'null' and ((latest_delivery_time) > current_date - 1) then title || ' multi region trail integrated with CloudWatch logs.' else title || ' multi region trail not integrated with CloudWatch logs.' end as reason , region, account_idfrom aws_cloudtrail_trailwhere region = home_region and is_multi_region_trail;