0Pricing
AWS for Backend Developers (EC2, S3, RDS, Lambda) · บทเรียน

การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail

ติดตามกิจกรรมผู้ใช้และการเรียก API ทั่วทั้งบัญชี AWS เพื่อรองรับการวิเคราะห์ความปลอดภัย การติดตามการเปลี่ยนแปลงทรัพยากร และการตรวจสอบการปฏิบัติตามข้อกำหนด

การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail เป็นบทเรียน AWS for Backend Developers (EC2, S3, RDS, Lambda) ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน AWS for Backend Developers (EC2, S3, RDS, Lambda) และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส AWS for Backend Developers (EC2, S3, RDS, Lambda) มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

What is AWS CloudTrail?

Welcome to the lesson on AWS CloudTrail! This service is crucial for auditing, governance, and compliance within your AWS account.

Think of CloudTrail as a security camera for your AWS environment. It continuously monitors and records account activity.

Why Use CloudTrail?

CloudTrail captures a comprehensive history of events, including API calls, made by users, roles, or AWS services.

  • Security Analysis: Detect unusual activity or unauthorized access.
  • Compliance Auditing: Prove adherence to regulatory requirements.
  • Troubleshooting: Pinpoint who made what change and when.
  • Resource Change Tracking: Understand changes to your AWS resources.

How CloudTrail Works

CloudTrail logs events as JSON records. These records provide details like:

  • Who made the request (user or role)
  • What action was performed (e.g., RunInstances, PutObject)
  • When the action occurred
  • From which IP address
  • Which AWS service was involved

Event Types: Management Events

CloudTrail categorizes events into two main types. Management events capture control plane operations on your AWS resources.

  • Creating or deleting an EC2 instance.
  • Configuring security groups.
  • Updating an S3 bucket policy.

These events provide insight into management operations.

Event Types: Data Events

Data events log resource operations performed on or within a resource, which are often high-volume activities.

Examples include:

  • S3 object-level API activity (GetObject, PutObject, DeleteObject).
  • Lambda function invoke activities.

Data events can generate a lot of data and are optional to log.

CloudTrail Event History

Every AWS account automatically has Event History enabled, which provides a view of the past 90 days of management events in the CloudTrail console.

This is a quick way to search, view, and download recent activity without setting up a dedicated trail.

Creating a CloudTrail Trail

For long-term storage, advanced filtering, and integration with other services, you create a CloudTrail trail.

A trail is a configuration that enables CloudTrail to deliver log files to an Amazon S3 bucket you specify. You can create one trail that applies to all regions or specific regions.

Storing Logs in S3

When you create a trail, CloudTrail delivers log files to your chosen S3 bucket. These log files are encrypted and organized by region and date.

Storing logs in S3 provides durable, low-cost storage, which is ideal for compliance and long-term auditing requirements.

Integrating with CloudWatch Logs

For real-time monitoring and alerting, CloudTrail can be configured to send events to Amazon CloudWatch Logs.

This integration allows you to:

  • Create alarms based on specific API calls.
  • Build dashboards to visualize activity patterns.
  • Centralize logs from multiple AWS services.

CloudTrail Key Concepts

Which of the following are key benefits of using AWS CloudTrail?

CloudTrail: Your Audit Log

You've learned that AWS CloudTrail is essential for maintaining security, achieving compliance, and performing operational troubleshooting within your AWS account.

By logging management and data events to S3 and integrating with CloudWatch Logs, you gain deep visibility into all activities, ensuring you know who did what, when, and where.

คำถามที่พบบ่อย

บทเรียน “การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส AWS for Backend Developers (EC2, S3, RDS, Lambda) ให้อัปเกรดเป็น CoddyKit PRO คอร์ส AWS for Backend Developers (EC2, S3, RDS, Lambda) มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail”

ติดตามกิจกรรมผู้ใช้และการเรียก API ทั่วทั้งบัญชี AWS เพื่อรองรับการวิเคราะห์ความปลอดภัย การติดตามการเปลี่ยนแปลงทรัพยากร และการตรวจสอบการปฏิบัติตามข้อกำหนด คุณปฏิบัติ AWS for Backend Developers (EC2, S3, RDS, Lambda) ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน AWS for Backend Developers (EC2, S3, RDS, Lambda) หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน AWS for Backend Developers (EC2, S3, RDS, Lambda) บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน

บทเรียน “การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน AWS for Backend Developers (EC2, S3, RDS, Lambda) นี้ได้ไหม

ได้ บทเรียน AWS for Backend Developers (EC2, S3, RDS, Lambda) ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. ตัวชี้วัดและการแจ้งเตือนของ CloudWatch
  2. บันทึกและกลุ่มบันทึกของ CloudWatch
  3. การตรวจสอบที่ขับเคลื่อนด้วยเหตุการณ์ด้วย CloudTrail
  4. การสร้างแดชบอร์ด CloudWatch
← กลับไปที่ AWS for Backend Developers (EC2, S3, RDS, Lambda)