Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cloudtrail-enabled managed rule evaluates at a regional level #391

Open
misraved opened this issue Aug 12, 2022 · 0 comments
Open

cloudtrail-enabled managed rule evaluates at a regional level #391

misraved opened this issue Aug 12, 2022 · 0 comments

Comments

@misraved
Copy link

misraved commented Aug 12, 2022

As per the documentation, the cloudtrail-enabled managed rule evaluates trails as per the following statement -

Checks if AWS CloudTrail is enabled in your AWS account. Optionally, you can specify which S3 bucket, SNS topic, and AWS CloudTrail ARN to use. The rule is NON_COMPLIANT if AWS CloudTrail is not enabled.

However, if I create a single trail in the us-east-1 region, and create a config rule to evaluate cloudtrail-enabled rule in the us-east-2 region, the rule evaluates it to Noncompliant.

Shouldn't the description be updated to say that the rule is looking for trails(or multi-region trails) in all the regions? Is my understanding correct or am I missing something?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant