Centralized Enterprise Security Log Lake: CloudTrail & VPC Flow Logs
Aggregating multi-account security telemetry into an immutable S3 lake with AWS Glue crawlers and Athena forensics.
1. Business Problem & Context
An enterprise with 50 AWS accounts struggled to investigate security incidents. Audit logs were scattered across local CloudWatch log groups in different regions and accounts. When a security compromise occurred, gathering and correlating logs took over 4 hours, delaying threat containment.
2. Requirements & Constraints
- Centralized Multi-Account Aggregation: Ingest CloudTrail and VPC Flow Logs into a dedicated Log Archive AWS account.
- Tamper-Proof Immutability: Enforce S3 Object Lock in Compliance Mode to satisfy SOC2/HIPAA mandates.
- Rapid Forensic Querying: Search billions of IP connection records with SQL in seconds.
3. Architecture Overview & Data Flow
Interactive Architecture Diagram (Use controls to zoom & pan)
4. AWS Services Used & Rationales
AWS Services Architecture Rationale
Concrete reasons why these specific services were chosen over alternatives
| Service | Category | Architectural Rationale ("Why this service?") |
|---|---|---|
| Amazon S3 Object Lock | Storage | Prevents log deletion or alteration by any IAM user (even root) for a designated retention period (e.g. 7 years). |
| AWS CloudTrail Org Trail | Security | Automatically enables logging for all current and future accounts created in AWS Organizations. |
| Amazon Athena | Analytics | Allows SecOps to run SQL queries identifying suspicious IP addresses across all VPCs simultaneously. |
5. Key Design Trade-offs
Architecture Decision & Trade-Off Matrix
Evaluating alternative approaches under real-world constraints
CloudWatch Logs in Each Member Account
- + Zero cross-account setup
- − Scattered logs
- − High log ingestion fees ($0.50/GB)
- − Compromised accounts can delete logs
Centralized S3 Object Lock Lake (Chosen)
✓ Chosen Design- + Immutable WORM storage
- + Single pane of glass
- + Low-cost S3 Standard + Glacier lifecycle ($0.023/GB down to $0.00099/GB)
- − Requires cross-account S3 bucket policy
6. Implementation Highlights
Forensic SQL Sample Athena Threat Hunting Query: Rejected Port Scans
SELECT srcaddr, dstaddr, dstport, protocol, count(*) as reject_count
FROM vpc_flow_logs_db.vpc_flow_logs
WHERE action = 'REJECT'
AND year = '2026' AND month = '08' AND day = '20'
GROUP BY srcaddr, dstaddr, dstport, protocol
ORDER BY reject_count DESC
LIMIT 50; 7. Results & Key Metrics
- Incident Response Time: Investigation duration reduced from 4 hours to 2 minutes.
- Compliance Audit: 100% pass rate for SOC2 Type II audit trail requirements.
8. Key Architectural Takeaways
Security Rule: Always send security logs to a separate, isolated Log Archive Account with S3 Object Lock. A compromised developer account must never have permissions to erase audit traces.