# Unfiltered CloudTrail Data Event Logging | Cloud Efficiency Hub

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/unfiltered-cloudtrail-data-event-logging

CloudTrail data events record resource-level operations such as S3 GetObject and PutObject, Lambda Invoke and DynamoDB item reads and writes.

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

CloudTrail data events record resource-level operations such as S3 GetObject and PutObject, Lambda Invoke and DynamoDB item reads and writes.

PointFive Research

Cloud cost research at PointFive

AWS service

[AWS CloudTrail](https://www.pointfive.co/efficiency-hub/cloud-services/aws-cloudtrail)

Category

[Other](https://www.pointfive.co/efficiency-hub/service-category/other)

Reference

CER-0387

Type

Excessive Ingestion or Processing

## Explanation

Why the waste happens and who it affects.

Unlike the first copy of management events, every data event a trail delivers is billed. Security baselines and landing zones often enable data events for all S3 buckets or all Lambda functions in an account with a single broad selector, so every object read by an analytics job, every write to a log bucket and every function invocation becomes a billable CloudTrail event.

The volume concentrates in a few places: data lake and analytics buckets read by query engines, buckets that receive logs (including the trail's own destination bucket), high-throughput Lambda functions, and service-initiated activity such as S3 Lifecycle operations or authentication failures. Much of it has no audit value, yet it is paid for on delivery, and again if the same events are sent to CloudWatch Logs or ingested into CloudTrail Lake. CloudTrail documents advanced event selectors specifically as a way to control costs by logging only the data events of interest.

## Billing model

The pricing dimensions that drive this cost.

Trail data events

Billed per 100,000 data events delivered to Amazon S3 ($0.10 per 100,000 on the CloudTrail pricing page)

CloudWatch Logs delivery

Events that a trail also sends to a CloudWatch Logs group are billed per GB ingested

CloudTrail Lake ingestion

Data events ingested into an event data store are billed per GB, by retention option

Log storage

Delivered log files are billed as S3 storage and requests in the destination bucket

## How to detect

5 checks to find it in your estate.

- Run get-event-selectors on each trail and flag basic selectors that log all S3 buckets or all Lambda functions, and advanced selectors for AWS::S3::Object or AWS::Lambda::Function with no resources.ARN, eventName, readOnly, eventSource or eventType conditions

- Query the trail's logs with Athena or CloudTrail Lake to rank data events by eventSource, eventName and bucket or function ARN, and identify the few resources that generate most of the volume

- Check whether the trail's own destination bucket, other log buckets or data lake buckets read by query engines are included in data event logging

- Look for large counts of service-initiated events, such as eventSource s3lifecycle.amazonaws.com or s3-authn-errors.amazonaws.com, or eventType AwsServiceEvent

- Review CloudTrail cost in Cost Explorer by usage type to size data event charges per account and Region

## How to fix

5 ways to remove the waste.

- Replace broad selectors with advanced event selectors scoped by resources.ARN to the buckets, prefixes and functions that security or compliance actually require

- Log only the operations needed, for example write-only events with readOnly set to false, or specific eventName values such as PutObject and DeleteObject

- Exclude high-volume, low-value sources: the trail's own bucket, analytics scan traffic from known roles via userIdentity.arn, S3 Lifecycle events and S3 authentication failure events

- Avoid sending the same data events to several destinations (S3, CloudWatch Logs and CloudTrail Lake) unless each serves a distinct need

- Agree the scope with security and compliance owners before narrowing, and document which resources are intentionally excluded

## Documentation

Vendor references for pricing and configuration.

- [AWS CloudTrail pricing  aws.amazon.com](https://aws.amazon.com/cloudtrail/pricing/)

- [Filtering data events by using advanced event selectors  docs.aws.amazon.com](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/filtering-data-events.html)

- [Logging data events  docs.aws.amazon.com](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-data-events-with-cloudtrail.html)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- AWS CloudTrail  CER-0016

### [Duplicate or Overlapping AWS CloudTrail Trails](https://www.pointfive.co/efficiency-hub/inefficiencies/duplicate-or-overlapping-aws-cloudtrail-trails)

AWS CloudTrail enables event logging across AWS services, but when multiple trails are configured to log overlapping events - especially data events - it can result in redundant charges and unnecessary storage or ingestion costs. This...

Other

- AWS Config  CER-0228

### [Excessive AWS Config Costs from Spot Instances](https://www.pointfive.co/efficiency-hub/inefficiencies/excessive-aws-config-costs-from-spot-instances)

Spot Instances are designed to be short-lived, with frequent interruptions and replacements. When AWS Config continuously records every lifecycle change for these instances, it produces a large number of CIRs. This drives costs...

Other

- AWS Config  CER-0201

### [Continuous AWS Config Recording in Non-Production Environments](https://www.pointfive.co/efficiency-hub/inefficiencies/continuous-aws-config-recording-in-non-production-environments)

By default, AWS Config is enabled in continuous recording mode. While this may be justified for production workloads where detailed auditability is critical, it is rarely necessary in non-production environments. Frequent changes in...

Other

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

