Note: If you choose not to enable AWS CloudTrail, USM Anywhere processes all stored logs at initial startup. See the Amazon documentation for information about enabling AWS CloudTrail. After that initial processing, log collection jobs run every five minutes to ensure that logs are captured and can generate meaningful events in a timely manner.
Note: Sometimes you may see that the CloudTrail events in USM Anywhere display a different username compared to the raw log. This is because CloudTrail provides different types of user identities, one of which is AssumedRole. When the user identity type is set to AssumedRole, it means that the user credential is temporary and the username you see in the raw log is not the actual username. See Amazon documentation for more information.
- Go to Settings > Scheduler.
- Search for CloudTrail in the Job Scheduler Filter By field.
-
In the row for the CloudTrail job, click the
icon to enable the AWS CloudTrail jobs. This turns the
icon green.

Related Video Content