AWS CloudTrail adds UserIdentity network filters
🔍 Today AWS announced enhanced CloudTrail filtering for VPC endpoint network activity events, allowing selectors that filter logs by the IAM user identity making API calls. This update lets customers log only relevant events — for example, access denied actions from identities outside a trusted list — reducing logging noise and cost. The feature supports console, CLI, and SDK access and is available in all Regions that support CloudTrail network activity events.
