What's Happening?
AWS has launched enhanced event filtering for network activity events in CloudTrail, allowing users to log events based on IAM user identity. This feature enables customers to capture unauthorized access attempts while excluding routine traffic from trusted
identities, reducing logging costs and noise. The UserIdentity filtering is part of AWS's strategy to help customers focus on security-critical scenarios, such as detecting potential data exfiltration attempts through VPC endpoints.
Why It's Important?
This update enhances AWS CloudTrail's capabilities, providing users with more control over network activity logging. By allowing selective logging based on user identity, AWS helps customers improve their security posture while managing costs. This feature is particularly valuable for organizations implementing data perimeter strategies, as it enables more targeted and efficient monitoring of network activities, ensuring that security efforts are focused on the most critical areas.













