Explanation
Why the waste happens and who it affects.
Unlike the first copy of management events, every data event a trail delivers is billed. Security baselines and landing zones often enable data events for all S3 buckets or all Lambda functions in an account with a single broad selector, so every object read by an analytics job, every write to a log bucket and every function invocation becomes a billable CloudTrail event.
The volume concentrates in a few places: data lake and analytics buckets read by query engines, buckets that receive logs (including the trail's own destination bucket), high-throughput Lambda functions, and service-initiated activity such as S3 Lifecycle operations or authentication failures. Much of it has no audit value, yet it is paid for on delivery, and again if the same events are sent to CloudWatch Logs or ingested into CloudTrail Lake. CloudTrail documents advanced event selectors specifically as a way to control costs by logging only the data events of interest.
Billing model
The pricing dimensions that drive this cost.
- Trail data events
- Billed per 100,000 data events delivered to Amazon S3 ($0.10 per 100,000 on the CloudTrail pricing page)
- CloudWatch Logs delivery
- Events that a trail also sends to a CloudWatch Logs group are billed per GB ingested
- CloudTrail Lake ingestion
- Data events ingested into an event data store are billed per GB, by retention option
- Log storage
- Delivered log files are billed as S3 storage and requests in the destination bucket
How to detect
5 checks to find it in your estate.
- Run get-event-selectors on each trail and flag basic selectors that log all S3 buckets or all Lambda functions, and advanced selectors for AWS::S3::Object or AWS::Lambda::Function with no resources.ARN, eventName, readOnly, eventSource or eventType conditions
- Query the trail's logs with Athena or CloudTrail Lake to rank data events by eventSource, eventName and bucket or function ARN, and identify the few resources that generate most of the volume
- Check whether the trail's own destination bucket, other log buckets or data lake buckets read by query engines are included in data event logging
- Look for large counts of service-initiated events, such as eventSource s3lifecycle.amazonaws.com or s3-authn-errors.amazonaws.com, or eventType AwsServiceEvent
- Review CloudTrail cost in Cost Explorer by usage type to size data event charges per account and Region
How to fix
5 ways to remove the waste.
- Replace broad selectors with advanced event selectors scoped by resources.ARN to the buckets, prefixes and functions that security or compliance actually require
- Log only the operations needed, for example write-only events with readOnly set to false, or specific eventName values such as PutObject and DeleteObject
- Exclude high-volume, low-value sources: the trail's own bucket, analytics scan traffic from known roles via userIdentity.arn, S3 Lifecycle events and S3 authentication failure events
- Avoid sending the same data events to several destinations (S3, CloudWatch Logs and CloudTrail Lake) unless each serves a distinct need
- Agree the scope with security and compliance owners before narrowing, and document which resources are intentionally excluded
Documentation
Vendor references for pricing and configuration.