UpdateTrail
UpdateTrail
Event
UpdateTrail changes settings on an existing trail, such as its delivery destination, regional scope, or integrity-validation setting. It does not require stopping logging first, and the call must target the trail’s home Region. AWS API reference.
Security Context
The operation can improve collection or weaken it. Compare the requested changes with the approved configuration before assigning intent.
Legitimate uses: migrating a log destination, enabling broader coverage, or changing delivery integration settings during an approved deployment. Confirm that expected records still reach the investigation and alerting systems.
Mapping rationale: deliberately reducing audit scope or integrity protections fits Disable or Modify Cloud Log. A configuration change does not itself demonstrate that stored logs were altered.
Log Source
Search CloudTrail write management events for eventSource: cloudtrail.amazonaws.com and eventName: UpdateTrail. Review the full request and any returned settings; absence of a field in the request is not evidence that its setting was disabled.
Collection boundary: setting isMultiRegionTrail to false narrows this trail to its home Region. It does not disable other trails. Disabling validation stops digest creation for the disabled interval and breaks the digest chain; it does not stop ordinary log delivery by itself. Re-enabling validation does not create the missing digests retroactively. UpdateTrail behavior.
Integrity validation enables checks on delivered files; it is not a guarantee that all tampering is prevented or automatically detected. Validation overview.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.name | Resolve the affected trail and recover its prior configuration. |
requestParameters.isMultiRegionTrail | Identify requested changes in regional coverage. |
requestParameters.enableLogFileValidation | Identify changes in digest generation. |
requestParameters.s3BucketName and delivery integration fields | Compare requested destinations and roles with the approved setup. |
responseElements, errorCode, and errorMessage | Assess the outcome and returned configuration. |
userIdentity.arn, eventTime, and awsRegion | Attribute the change and establish its timing and regional context. |
What to Investigate
- Compare the request and outcome with a prior configuration snapshot. Confirm current settings separately, because a later update may have superseded this one.
- Trace the caller and validate the change owner. Identify which collection or validation capability actually changed, rather than treating every update as a shutdown.
- Check destination access and delivery health. A valid-looking bucket or role change may still interrupt downstream ingestion; a successful update alone does not prove end-to-end delivery.
- Correlate PutEventSelectors, StopLogging, and DeleteTrail. Document affected Regions and validation intervals while preserving previously delivered evidence.
Sample Event
Synthetic scenario — reduced protections. Draco requests single-Region collection and disables validation on an account trail in us-east-1. The scenario assumes the previous configuration enabled both settings; the request alone does not prove that prior state. Other collection and integrity controls may still exist.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:00:18Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "UpdateTrail", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail", "isMultiRegionTrail": false, "enableLogFileValidation": false }, "responseElements": { "name": "fantasticlogs-prod-trail", "s3BucketName": "fantasticlogs-cloudtrail", "includeGlobalServiceEvents": true, "isMultiRegionTrail": false, "trailARN": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail", "logFileValidationEnabled": false, "isOrganizationTrail": false }, "requestID": "90000000-0000-4000-8000-000111010010", "eventID": "90000000-0000-4000-8000-000111010011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...