CloudWatch无法跨区域检测CloudTrail事件问题咨询
Got it, let's break down why you're seeing this behavior and how to fix it.
First off, Amazon CloudWatch Events (now part of Amazon EventBridge) is a regional service by default. That means the event bus in eu-central-1 only listens for events generated within eu-central-1 out of the box. Your cross-region CloudTrail works because it's explicitly configured to aggregate events from all regions, but CloudWatch Events doesn't do that automatically.
Here are two reliable approaches to get those eu-west-1 (or other region) events into your eu-central-1 CloudWatch setup:
1. Forward Events from Source Regions to Your Monitoring Region
You can set up EventBridge rules in each region where you want to capture events, and forward them to your central monitoring region's event bus:
- Switch to the source region (e.g., eu-west-1) in the AWS Console, head to EventBridge.
- Create a new rule:
- For the event source, pick
AWS API Call via CloudTrail, then filter for the specific action you care about (likeCreateInternetGateway). - For the target, select
Event bus in another AWS account or Region, choose your monitoring region (eu-central-1), and select the default event bus (or a custom one if you've set it up).
- For the event source, pick
- Critical: Update the permission policy on your eu-central-1 event bus to allow eu-west-1 to send events to it. The policy should include a statement allowing
events:PutEventsfrom the eu-west-1 region of your account.
2. Use Your Existing Cross-Region CloudTrail with CloudWatch Logs
Since you already have a cross-region CloudTrail that captures events in all regions, you can route those logs to a central CloudWatch Logs group in eu-central-1, then trigger EventBridge rules from there:
- Edit your cross-region CloudTrail configuration, and set it to deliver logs to a CloudWatch Logs group in eu-central-1. Make sure CloudTrail has the necessary permissions to write to that log group.
- In eu-central-1's EventBridge console, create a new rule using
CloudWatch Logsas the source:- Select the log group you configured for CloudTrail.
- Set a filter pattern to match the action you want to capture, like:
{ $.eventName = "CreateInternetGateway" } - Configure your desired target (e.g., an SNS topic, Lambda function, or CloudWatch alarm) to respond to these events.
- Method 2 is usually easier to manage if you need to monitor multiple regions—you only need one central setup instead of rules in every region.
- Cross-region event forwarding incurs minimal data transfer costs, but it's worth checking the AWS pricing page if you're handling high volumes.
- Double-check that your CloudTrail is set to log events from all regions (not just the current one) to ensure no events slip through.
内容的提问来源于stack exchange,提问作者Adrien Merlier

