Lunker - Gone Fishing!

blog.lukach.io

Amazon Cloud

GitHub Profile

December 14, 2025

ClickOps #8 - Configure CloudTrail Lake Logging

by John Lukach

CloudTrail is available by default in Event History, on a per-account, per-region basis, with a 90-day retention. I prefer to use CloudTrail Lake to centralize logs with 1-year retention, avoiding S3 hassles.

The first step is to delegate CloudTrail administration to a new account to minimize management account overhead.

delegated administrator

delegated administrator

Switch to the delegated administrator account to start configuring the CloudTrail Lake.

cloudtrail lake

Create event data store

cloudtrail lake

cloudtrail lake

Choose events

cloudtrail lake

cloudtrail lake

Enrich events, enable large events - optional

cloudtrail lake

Termination protection is now enabled by default, so one less step for a new deployment!

cloudtrail lake

cloudtrail lake

tags: aws - cloudtrail - lake - logs