We can integrate CloudWatch with an existing trail as follows:
- Go to the CloudTrail service in the console.
- Click on Trails.
- Click on the name of our trail to go to the trail's Configuration page.
- Scroll down to the CloudWatch Logs section. Click on Configure.
- Leave the auto-populated value for New or existing log group as is, which is CloudTrail/DefaultLogGroup in my case, and click Continue.
- Click Allow to give CloudTrail permission to deliver CloudTrail events associated with API activity in our account to our CloudWatch Logs log group. We should see the CloudWatch details in the CloudWatch Logs section of our trail's configuration:
- Click on the Create CloudWatch Alarms for Security and Network related API activity ...