AWS eventbridge: CloudTrail logging of Custom Event Bus APIs and rule state note
Summary
Adds a note that CloudTrail records Custom Event Bus management API calls (CreateEventBus, CreateSubscriber, PutResourcePolicy) via the eventsv2 endpoint, and explains that forwarding read-only management events requires ENABLED_WITH_ALL_CLOUDTRAIL_MANAGEMENT_EVENTS on both the forwarding and destination rules.
Security assessment
Documents audit logging coverage (CloudTrail) for new management APIs and the rule state needed to forward read-only management events, which is audit/observability hardening guidance rather than a fix for a specific vulnerability.
Evidence
CloudTrail also records the Custom Event Bus management API calls, such as `CreateEventBus`, `CreateSubscriber`, and `PutResourcePolicy`, made through the `eventsv2` endpoint. See [Observability for the Custom Event Bus: metrics, logs, and CloudTrail](./eb-custom-bus-observability.html).
Diff
diff --git a/eventbridge/latest/userguide/eb-service-event-cloudtrail.md b/eventbridge/latest/userguide/eb-service-event-cloudtrail.md index 84963eb37..0a8755266 100644 --- a//eventbridge/latest/userguide/eb-service-event-cloudtrail.md +++ b//eventbridge/latest/userguide/eb-service-event-cloudtrail.md @@ -10,0 +11,4 @@ AWS CloudTrail is a service that automatically records events such as AWS API ca +###### Note + +CloudTrail also records the Custom Event Bus management API calls, such as `CreateEventBus`, `CreateSubscriber`, and `PutResourcePolicy`, made through the `eventsv2` endpoint. See [Observability for the Custom Event Bus: metrics, logs, and CloudTrail](./eb-custom-bus-observability.html). + @@ -56 +60,5 @@ To record events with one of the CloudTrail `detail-type` values, you must enabl -All CloudTrail events are delivered to the default event bus only. To process CloudTrail events on a custom event bus, create a rule on the default bus that forwards matching events to your custom bus. +All CloudTrail events are delivered to the default event bus only. To process CloudTrail events on a Custom Event Bus - Classic, create a rule on the default bus that forwards matching events to your Classic custom bus. + +###### Note + +If you forward read-only management events to another event bus (a Custom Event Bus - Classic, or a bus in another account or Region), two rules need the state `ENABLED_WITH_ALL_CLOUDTRAIL_MANAGEMENT_EVENTS`: the forwarding rule on the default event bus, and the rule on the destination event bus. A rule in the default `ENABLED` state does not match read-only management events, so its targets are not invoked.