We can send CloudTrail logs between two standalone accounts as follows:
- Log in to the log account where logs will be sent to. A trail should have already been configured, as described in the Getting ready section.
If you are using AWS Organizations, the steps are simpler and are provided in the There's more... section.
- Go to our trail's bucket and go to its Permissions tab. Then, click on Bucket Policy. The current policy should allow cloudtrail.amazonaws.com to perform the s3:GetBucketAcl action on the arn:aws:s3:::aws-sec-cb-trail resource. It should also allow cloudtrail.amazonaws.com to perform the s3:PutObject action on the arn:aws:s3:::aws-sec-cb-trail/AWSLogs/135301570106/* resource with a condition that checks if ...