User guide
Using AWS CloudTrail for Amazon Redshift
This service supports AWS CloudTrail, which is a service that records AWS calls for your AWS account
and delivers log files to an Amazon S3 bucket. By using information collected by CloudTrail, you can
determine what requests were successfully made to AWS services, who made the request, when it was
made, and so on.To learn more about CloudTrail, including how to turn it on and find your log files, see
the AWS CloudTrail User Guide.
CloudTrail can be used independently from or in addition to Amazon Redshift database audit logging.
Configuring Auditing Using the Console
You can configure Amazon Redshift to create audit log files and store them in S3.
Enabling Audit Logging Using the Console
1. Sign into the AWS Management Console and open the Amazon Redshift console at https://
console.aws.amazon.com/redshift.
2. In the navigation pane, click Clusters.
3. In the list, click the cluster for which you want to enable logging.
4. In the cluster details page, click Database, and then click Configure Audit Logging.
5. In the Configure Audit Logging dialog box, in the Enable Audit Logging box, click Yes.
6. For S3 Bucket, do one of the following:
• If you already have an S3 bucket that you want to use, select Use Existing and then select the
bucket from the Bucket list.
• If you need a new S3 bucket, select Create New, and in the New Bucket Name box, type a name.
API Version 2012-12-01
221
Amazon Redshift Management Guide
Using AWS CloudTrail for Amazon Redshift