by John Lukach
CloudTrail is available by default in Event History, on a per-account, per-region basis, with a 90-day retention. I prefer to use CloudTrail Lake to centralize logs with 1-year retention, avoiding S3 hassles.
The first step is to delegate CloudTrail administration to a new account to minimize management account overhead.
Switch to the delegated administrator account to start configuring the CloudTrail Lake.
Termination protection is now enabled by default, so one less step for a new deployment!
tags: aws - cloudtrail - lake - logs