Overview
AWS CloudTrail Lake supports ingesting activity events from non-AWS sources, making CloudTrail Lake a single location of immutable user and API activity events for auditing and security investigations across AWS and hybrid environments. CloudTrail Lake records all events in a prescribed CloudTrail schema, making it easier for users to manage and diagnose security, audit, and operational incidents in AWS and hybrid environments.
The combination of CloudTrail Lake and Idira Identity Security Intelligence enables organizations to enhance their security and compliance controls without increasing complexity. You can enable this integration for Idira Identity Security Intelligence to stream events such as alerts for User Behavior Analytics (UBA) events and Privileged Detection events and immutably store these logs to increase visibility into targeted threats enabling security teams to both investigate and respond with the appropriate actions.