Centralized CloudTrail monitoring across 100+ AWS accounts
Big Data Blog
This article demonstrates how to build a centralized CloudTrail monitoring solution across 100+ AWS accounts using Amazon OpenSearch Service and Terraform for automated threat detection and compliance reporting.
- Aggregate CloudTrail logs from 100+ accounts into centralized S3 bucket with OpenSearch Ingestion pipeline auto-scaling between 2-10 OCUs
- Define index templates, lifecycle policies, and access control declaratively in Terraform to eliminate fragmented Lambda functions
- Implement multi-team role-based access with isolated OpenSearch Dashboards tenants for Security Ops, Incident Response, Compliance, and DevOps
- Deploy automated alerting monitors to detect CloudTrail tampering (StopLogging, DeleteTrail) within one minute
- Achieve 200 GB/day indexing throughput, 76ms average search latency, and 99.95% availability with OR1 storage-optimized instances
- Generate compliance reports on-demand using 600+ saved searches instead of manual processes taking days
- Extend with warm and cold storage tiers for long-term retention (7 years) meeting PCI DSS and HIPAA requirements
This infrastructure-as-code approach reduces threat detection time from hours to minutes while enabling multiple teams to operate independently with consistent, version-controlled deployments.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2024
2026
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.