Logging provides us with insight into the availability and integrity of our clouds.
Logging
CloudTrail
CloudTrail captures and records account activity:
resource "aws_cloudtrail" "example" {
name = "tf-trail-foobar"
s3_bucket_name = "${aws_s3_bucket.mybookbucket.id}"
s3_key_prefix = "prefix"
include_global_service_events = false
kms_key_id : "${aws_kms_key.book_key.id}"
event_selector {
read_write_type = "All"
include_management_events = true
data_resource {
type = "AWS::S3::Object"
values = ["arn:aws:s3:::"]
}
}
}