CuraDevOps

Plan archived

AWS CloudTrail adds UserIdentity filtering for VPC endpoint events

2026-07-21 12:20 UTC · AWS What's New · read the source ↗ #aws-cloudtrail#vpc-endpoints#data-perimeter
  • Platform/SRE — Plan: This GA feature lets you reduce CloudTrail network activity event volume and cost by scoping logging to untrusted or access-denied identities on VPC endpoints — a concrete improvement for data perimeter monitoring. Update your CloudTrail advanced event selectors this quarter to filter trusted IAM roles and cut noise on VpceAccessDenied events.
  • CI/CD — Skip
  • Leader — Learn: This feature enables selective CloudTrail logging that can meaningfully reduce ingestion costs for high-volume VPC endpoint environments, relevant for FinOps conversations around AWS audit logging spend — no strategic decision required now.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.