A config rule that checks whether AWS CloudTrail trails are configured to send logs to Amazon CloudWatch Logs. The trail is NON_COMPLIANT if the CloudWatchLogsLogGroupArn property of the trail is empty.

This config rule supports the following parameters:

  • expectedDeliveryWindowAge
    • Required: No
    • Type: int
    • Description:Maximum age in hours of the most recent delivery to CloudWatch logs that satisfies compliance.

ConfigRule
AWS::Config::ConfigRule


Source *
CustomPolicyDetails
SourceDetails

CloudFormation Template

Share Template