﻿---
title: AWS CloudTrail Logs OpenTelemetry Assets
description: This package contains Kibana assets for monitoring AWS CloudTrail Logs. ECF is the simplest way to configure AWS CloudTrail log collection. Refer to the...
url: https://www.elastic.co/docs/reference/integrations/aws_cloudtrail_otel
products:
  - Elastic integrations
applies_to:
  - Serverless Observability projects: Preview
  - Serverless Security projects: Preview
  - Elastic Stack: Preview since 9.2
---

# AWS CloudTrail Logs OpenTelemetry Assets
|                                                                                                 |                                                                   |
|-------------------------------------------------------------------------------------------------|-------------------------------------------------------------------|
| **Version**                                                                                     | 0.3.0 <applies-to>: Preview</applies-to> ([View all](#changelog)) |
| **Subscription level**[What's this?](https://www.elastic.co/subscriptions)                      | Basic                                                             |
| **Developed by**[What's this?](https://www.elastic.co/docs/reference/integrations/developed-by) | Elastic                                                           |
| **Minimum Kibana version(s)**                                                                   | 9.2.0                                                             |

<admonition title="The AWS CloudTrail Logs OpenTelemetry Assets integration v0.3.0 is in technical preview">
  To use pre-release integrations, go to the **Integrations** page in Kibana, scroll down, and toggle on the _Display beta integrations_ option.
</admonition>

This package contains Kibana assets for monitoring [AWS CloudTrail Logs](https://aws.amazon.com/cloudtrail/).

## Supported data sources


### EDOT Cloud Forwarder (ECF) for AWS

ECF is the simplest way to configure AWS CloudTrail log collection. Refer to the [ECF for AWS documentation](https://www.elastic.co/docs/reference/opentelemetry/edot-cloud-forwarder/aws) for full setup instructions.

### Standalone OTel Collector

Any OTel-supported collection method is supported provided the required extension is included.

#### Compatibility

This package has been tested with OpenTelemetry Collector version `0.138.0`. The OpenTelemetry components used are [awss3receiver](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/awss3receiver#aws-s3-receiver), [awslogsencodingextension](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/extension/encoding/awslogsencodingextension#aws-logs-encoding-extension), and [elasticsearchexporter](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/exporter/elasticsearchexporter#elasticsearch-exporter).

#### Sample configuration

```yaml
extensions:
  awslogs_encoding/cloudtrail:
    format: cloudtrail

receivers:
  awss3:
    sqs:
      queue_url: "<sqs-url>"
      region: "<region>"
    s3downloader:
      region: "<region>"
      s3_bucket: '<bucket_name>'
      s3_prefix: 'AWSLogs/<account-id>'
    encodings:
      - extension: awslogs_encoding/cloudtrail

exporters:
  elasticsearch/otel:
    endpoints: https://<host>:<port>
    api_key: <api_key>

service:
  extensions: [awslogs_encoding/cloudtrail]
  pipelines:
    logs:
      exporters: [elasticsearch/otel]
      receivers: [awss3]
```


## Screenshots

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.
<carousel>
  ![Dashboard screenshot](https://epr.elastic.co/package/aws_cloudtrail_otel/0.3.0/img/dashboard.png)

  ![Dashboard screenshot (continuation)](https://epr.elastic.co/package/aws_cloudtrail_otel/0.3.0/img/dashboard_continued.png)
</carousel>


## Changelog

<dropdown title="Changelog">
  | Version   | Details                                                                                                                                                        | Minimum Kibana version |
  |-----------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------|
  | **0.3.0** | **Enhancement** ([View pull request](https://github.com/elastic/integrations/pull/19940))Add tags to Kibana assets                                             | 9.2.0                  |
  | **0.2.0** | **Enhancement** ([View pull request](https://github.com/elastic/integrations/pull/19175))Use standardized asset naming convention                              | 9.2.0                  |
  | **0.1.0** | **Enhancement** ([View pull request](https://github.com/elastic/integrations/pull/15644))Initial draft of the AWS CloudTrail Logs OpenTelemetry Assets package | 9.2.0                  |
</dropdown>