Skip to content
Back to skills

Setting Up Cloudtrail Multi Region

ASecurity

Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration, and CloudWatch Logs Insights queries for security monitoring and compliance auditing. Use when setting up centralized API activity logging across all AWS regions.

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 10, 2026
ai-agentsawsgitapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 10, 2026

npx -y skills add mouadja02/skills --skill setting-up-cloudtrail-multi-region --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Setting Up Cloudtrail Multi Region?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Setting Up Cloudtrail Multi Region
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mouadja02-setting-up-cloudtrail-multi-region/badge)](https://www.skillsdirectory.com/skills/mouadja02-setting-up-cloudtrail-multi-region)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
license: Apache-2.0
source: https://github.com/aws/agent-toolkit-for-aws
attribution: "Amazon Web Services - agent-toolkit-for-aws (Apache-2.0)"
name: setting-up-cloudtrail-multi-region
description: Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration, and CloudWatch Logs Insights queries for security monitoring and compliance auditing. Use when setting up centralized API activity logging across all AWS regions.
version: 1
---

# Setting Up CloudTrail Multi-Region

## Overview

Domain expertise for enabling AWS CloudTrail across all regions to capture
comprehensive API activity logs and configuring CloudWatch Logs Insights for
security monitoring, compliance auditing, and operational analysis.

## Set up a multi-region trail

To create a centralized multi-region CloudTrail trail with S3 storage, CloudWatch
Logs integration, and log analysis, follow the procedure exactly.
See [CloudTrail multi-region setup procedure](references/cloudtrail-multi-region-setup.md).

## Troubleshooting

### S3 bucket already exists

Choose a different globally unique name, or add a timestamp or organization identifier.

### Permission denied errors

Verify your identity with `aws sts get-caller-identity`. Ensure your user/role has required actions attached. Do NOT use `*FullAccess` managed policies.

### Trail not logging

Verify IAM role permissions, check S3 bucket policy allows CloudTrail access, and ensure the trail is started with `start-logging`.

### Missing events in CloudWatch

Allow 5-15 minutes for initial log delivery. Verify the CloudWatch Logs role ARN is correct and the log group exists in the same region as the trail.

### Opt-in region events not appearing

This is normal — events from opt-in regions may take several hours. Wait up to 24 hours before investigating further.

Files in this skill

  • SKILL.md1.8 KB
  • references/cloudtrail-multi-region-setup.md17.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…