cloudtrail-s3-dataevents-enabled
Checks if at least one Amazon CloudTrail trail is logging Amazon Simple Storage Service (Amazon S3) data events for all S3 buckets. The rule is NON_COMPLIANT if there are trails or if no trails record S3 data events.
Identifier: CLOUDTRAIL_S3_DATAEVENTS_ENABLED
Trigger type: Periodic
Amazon Web Services Region: All supported Amazon regions except Asia Pacific (Malaysia), Canada West (Calgary) Region
Parameters:
- S3BucketNames (Optional)
- Type: String
-
Comma-separated list of S3 bucket names for which data events logging should be enabled. Default behavior checks for all S3 buckets.
Amazon CloudFormation template
To create Amazon Config managed rules with Amazon CloudFormation templates, see Creating Amazon Config Managed Rules With Amazon CloudFormation Templates.