AWS CloudTrail
Business software
Sync AWS CloudTrail event, trail, and insight data into your warehouse. Ingest builds this connector the first time a customer asks for it, then keeps the tables current in a data warehouse you own, on the schedule you choose.
The AWS CloudTrail connector syncs your audit logging data into analytics-ready tables in your data warehouse. Pull events, trails, and insights from the CloudTrail API, with Ingest handling auth, pagination, and retries so the tables stay current.
What you would get
Each of these arrives as its own table, kept current on the schedule you choose:
- Events
- Trails
- Insights
How it gets built
- Choose AWS CloudTrail when you set up a pipeline, with the warehouse it goes to and a schedule.
- Ingest reads AWS CloudTrail's documentation, and you choose the tables you want.
- Ingest builds the connector and tests it against AWS CloudTrail itself.
- A person at Ingest reviews and publishes it, and your pipeline starts on its own.
What you will need
AWS IAM credentials (SigV4 signing). Attach an IAM policy granting cloudtrail permissions to a user or role; requests are signed with that identity's credentials.
You enter it once, in a form in Ingest, and it is kept in a secret store set aside for your organization.
Questions
- Does Ingest have a AWS CloudTrail connector?
- Not as a finished connector yet. Ingest builds it from AWS CloudTrail's own documentation the first time a customer asks, tests it against the real service, and lists it once it passes.
- Which warehouses can AWS CloudTrail data go to?
- Amazon S3, Google Cloud Storage, Azure Blob Storage, Apache Iceberg, Ingest Managed Lakehouse, MotherDuck, Postgres, Amazon Athena, Databricks, Redshift, BigQuery, ClickHouse, MySQL / generic SQL and Snowflake, in an account you own.
- Do I need to write code?
- No. Ingest builds, runs and maintains the connector. Someone with access to your warehouse connects it once, following a short guide.
AWS CloudTrail API documentation: https://docs.aws.amazon.com/awscloudtrail/latest/APIReference/Welcome.html
Where this would land, and what else connects
Setting up the destination is its own short guide, one per warehouse or lake: Amazon S3, Google Cloud Storage, Azure Blob Storage, Apache Iceberg, Ingest Managed Lakehouse, MotherDuck, Postgres, Amazon Athena, Databricks, Redshift, BigQuery, ClickHouse, MySQL / generic SQL, Snowflake.
Other sources Ingest connects for SaaS teams: Asana, Jira, Airtable, Clockify, Facebook Ads, Frankfurter.