AWS CloudTrail enhances network activity event filtering by IAM identity
AWS CloudTrail now allows selective logging of network activity events for VPC endpoints based on the IAM user identity making the API call. This feature helps reduce logging costs and noise by filtering out routine traffic from trusted identities, enabling focus on critical security events like access denials. It is available in all regions supporting CloudTrail network activity events and can be configured via the console, CLI, and SDKs.
- →Filter network activity events by IAM user identity
- →Reduce logging costs and noise with selective filtering
- →Support for fine-grained filtering combinations
- →Availability and access methods
Features (1) ›
- Filter network activity events by IAM user identity
AWS CloudTrail now supports enhanced event filtering for network activity events related to VPC endpoints, allowing customers to control which events are logged based on the IAM user identity making the API call. This enables more granular control over logging, focusing on security-relevant events while reducing costs and noise.
Enhancements (2) ›
- Reduce logging costs and noise with selective filtering
By filtering network activity events based on trusted or untrusted IAM identities, customers can reduce logging costs and noise. For example, logging only access denied events from unknown identities helps detect unauthorized access attempts without logging routine traffic from approved principals.
- Support for fine-grained filtering combinations
UserIdentity filtering can be combined with existing fields like eventName or vpcEndpointId for more precise control over what network activity events are recorded. This allows for fine-grained logging strategies tailored to specific security needs.
Notes (1) ›
- Availability and access methods
This feature is available in all AWS Regions where CloudTrail network activity events are supported. It can be configured using the AWS Management Console, AWS Command Line Interface, and AWS SDKs.
https://aws.amazon.com/about-aws/whats-new/2026/07/aws-cloudtrail-filter-useridentity-advance-selectors/
Related releases
- Amazon Neptune adds IAM tag-based access control for data plane operations AWS What's New ·
- Amazon Bedrock AgentCore enables unified observability for AI agents AWS What's New ·
- Amazon GameLift Streams adds IAM role credentials for secure resource access AWS What's New ·
- AWS IAM Identity Center Achieves FedRAMP Class C Certification AWS What's New ·
- Build Stateful IT Service Desk Agent with LangGraph on EKS AWS Open Source Blog ·
- AWS Certificate Manager adds ACME support for public TLS certificates AWS News Blog ·