AWS CloudTrail Cheatsheet

Top commands.

Overview

The CloudTrail CLI cheatsheet captures the patterns operators actually use during AWS API audit investigation. lookup-events covers recent investigation; Athena over S3 logs covers large windows; both belong in the muscle memory.

The approach

The practical approach: lookup-events for recent investigation, Athena for large windows, EventBridge for real-time detection, documented queries per incident. The team’s discipline produces fast audit investigation.

Why this compounds

CloudTrail fluency compounds across investigations. Each audit grows the team’s investigation expertise; cost-per-incident falls as the playbook matures.

CloudTrail fluency is an operational discipline that pays off across years. Nova AI Ops integrates with audit telemetry, surfaces patterns, and supports the team’s investigation discipline.