CloudTrail审计员
cinq-auditor-cloudtrail的Python项目详细描述
请在Cloud-Inquisitor存储库中打开问题
说明
该审计员确保cloudtrail:
- 在多个区域上全局启用
- 记录到中心位置
- 已启用sns/sqs通知并将其发送到正确的队列
- 而且(我们选择的名称)区域路径未启用
配置选项
Option name | Default Value | Type | Description |
---|---|---|---|
enabled | False | bool | Enable the CloudTrail auditor |
interval | 60 | int | Run frequency in minutes |
bucket_account | CHANGE ME | string | Name of the account (must exist), in which to create the S3 bucket where CloudTrail logs will be delivered |
bucket_name | CHANGE ME | string | Name of the S3 bucket to send CloudTrail logs to |
bucket_region | us-west-2 | string | Region where to enable global events logging |
global_cloudtrail_region | us-west-2 | string | Region where to enable the global CloudTrail |
sns_topic_name | CHANGE ME | string | Name of the SNS topic for CloudTrail log delivery |
sqs_queue_account | CHANGE ME | string | Name of the account (must exist) which owns the SQS queue for CloudTrail log delivery notifications |
sqs_queue_name | SET ME | string | Name of the SQS queue |
sqs_queue_region | us-west-2 | string | Region for the SQS queue |
trail_name | us-west-2 | string | Name of the CloudTrail trail region |