Selectively log network activity events by identity in AWS CloudTrail
News
AWS launches enhanced event filtering for CloudTrail network activity events, allowing customers to control logging based on IAM user identity making API calls.
- Filter network activity events by IAM user identity to log only relevant security scenarios
- Configure selectors to capture unauthorized access attempts while excluding routine traffic from trusted identities
- Combine UserIdentity conditions with eventName or vpcEndpointId for fine-grained control
- Reduce logging costs and noise by focusing on VpceAccessDenied events from untrusted identities
- Available via AWS Management Console, CLI, and SDKs in all supported regions
This feature enables data perimeter strategies by selectively logging VPC endpoint access based on user identity, helping detect potential data exfiltration attempts without logging every successful API call.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Aug 11
2026
2026
Centralized CloudTrail monitoring across 100+ AWS accounts
May 28
2026
2026
AWS Organizations emits CloudTrail events for account membership changes
May 27
2026
2026
Amazon S3 audit logging, Part 2: Centralized logging and analysis of S3 data events in AWS CloudTrail for security and compliance
May 11
2025
2025
Announcing AWS CloudTrail network activity events for VPC Endpoints
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.