StopLogging
StopLogging
Event
StopLogging pauses recording and log delivery for one CloudTrail trail. It does not delete that trail’s previously delivered logs. For a multi-Region trail, the request must target its home Region. AWS API reference.
Security Context
An unexpected successful stop can interrupt the evidence pipeline used by investigations and alerts. Treat the trail’s purpose and scope as the starting point: a production audit trail warrants different scrutiny from a disposable test trail.
Legitimate uses: retiring a duplicate trail or ending a controlled test. Confirm the change owner and replacement collection path. Routine trail configuration changes do not require stopping logging first.
Mapping rationale: disabling a cloud audit trail supports the catalog’s Disable or Modify Cloud Log mapping. The API name alone does not establish malicious intent.
Log Source
Look for eventSource: cloudtrail.amazonaws.com and eventName: StopLogging in CloudTrail management events. For a retained trail feed, include write management events in its collection settings. Management event collection.
Collection boundary: stopping a trail does not stop CloudTrail Event history, which independently retains 90 days of regional management events. Other trails may also retain evidence. Event history does not recover missing data events. Avoid assuming the stop request is the final record delivered, or that all later activity is invisible. Event history behavior.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.name | Identify the trail by name or ARN; resolve its scope and home Region. |
userIdentity.arn and userIdentity.sessionContext | Attribute the caller and, when present, its role session. |
eventTime and awsRegion | Establish the investigation window and where to search. |
sourceIPAddress and userAgent | Compare the origin and client with the actor’s baseline. |
errorCode and errorMessage | Separate rejected attempts from apparent success; responseElements: null alone is not proof. |
What to Investigate
- Confirm the outcome and check the trail’s current
IsLoggingstate withGetTrailStatus. Current state does not establish what happened throughout the earlier interval. Status fields. - Identify who controlled the caller’s credentials. If it was a role session, trace the preceding AssumeRole activity and compare it with approved administration.
- Look for nearby DeleteTrail and PutEventSelectors calls. Determine whether collection was stopped, narrowed, or removed.
- Find any subsequent
StartLoggingcall and verify delivery resumed. Investigate the intervening activity using independent retained sources; record which event types are unavailable.
Sample Event
Synthetic scenario — suspicious change. Draco stops the account trail fantasticlogs-prod-trail in us-east-1. This illustrative record contains no error fields. Confirm the result and the trail state rather than treating the record as proof of a complete logging outage.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:04:08Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "StopLogging", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000110111010", "eventID": "90000000-0000-4000-8000-000110111011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...