Import Historical data from AWS CloudTrail Lake to Amazon CloudWatch
AWS Cloud Operations Blog
This article explains how to migrate CloudTrail data from CloudTrail Lake to Amazon CloudWatch for unified security and operational monitoring.
- Export historical CloudTrail Lake data to CloudWatch for specific date ranges
- No additional ingestion cost when exporting from CloudTrail Lake to CloudWatch
- Create telemetry enablement rules to automatically ingest new CloudTrail events organization-wide
- Use cross-account cross-region centralization rules to consolidate logs into single destination
- CloudWatch provides unified querying across CloudTrail, VPC Flow Logs, WAF logs, and custom data
- Data prior to 2023 cannot be migrated; older events remain queryable in CloudTrail Lake
- Exported data uses Infrequent Access storage class requiring CloudWatch Logs Insights
This guide enables organizations to centralize CloudTrail activity across all AWS accounts and regions into CloudWatch for improved incident response, compliance reporting, and security analysis.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Dec 30
2025
2025
AWS launches simplified import of CloudTrail Lake data in Amazon CloudWatch
Jun 6
2024
2024
Import Amazon RDS Enhanced Monitoring metrics into Amazon CloudWatch
Jun 12
2025
2025
Exporting a subset of AWS CloudTrail Lake events to Amazon S3
Mar 21
2024
2024
Securely share AWS CloudTrail Lake logs across accounts without replicating data
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.