AWS CloudTrail · Finder + automated fixer
CloudTrail Disable Duplicate Trail
DisableDuplicate Trail
Delete duplicate AWS CloudTrail trails to reduce logging costs. CloudFix identifies accounts with redundant trails and consolidates them.
What happens, in order.
Finder · read-only
Finds the opportunity
Scans your connected accounts with a read-only role. It can see resource metadata and usage; it can’t change anything.
You
Approve in Recommendations
It appears in your Recommendations view with what it would save. Approve the resources you choose. Nothing has changed yet.
Fixer
Runs in your account
The fixer runs as an AWS Systems Manager Automation runbook in your AWS account, and acts only on the resources you approved.
Record
Logs the execution
The Systems Manager execution is logged, so every change can be audited.
Finder role
Read-only. It can see resource metadata and usage. It can’t change anything.
Fixer role
A separate, minimal role that acts only on the resources you approved, through AWS Systems Manager.
Saves by
AWS CloudTrail records management events, data events and insight events. This opportunity relates only to management events, typically the highest-cost area. AWS allows duplicate trails, so the same events can be logged, and paid for, in two different trails. CloudFix identifies these duplicate trails so they can be disabled.
AWS CloudTrail helps organizations maintain governance, compliance, and operational and risk auditing of their AWS accounts. While CloudTrail is invaluable for its ability to monitor account activity, duplicate trails that log the same management events can lead to significant cost inefficiencies. CloudFix’s CloudTrail Delete Duplicate Trail feature identifies and disables redundant trails, reducing your AWS costs without compromising security or compliance.
What is a CloudTrail Duplicate Trail?
AWS CloudTrail can record three different types of events: management events, data events, and insight events. Management events provide information about management operations performed on resources in your AWS account, such as when a user signs in or a service is configured.
A CloudTrail duplicate trail occurs when multiple trails are configured to log the same events. This redundancy happens in two primary scenarios:
- Exact match: Two trails capture precisely the same set of events with identical configurations
- Subset trails: One trail captures a subset of events that are already being recorded by a more comprehensive trail
In either case, you’re paying twice for the same event data, creating unnecessary costs in your AWS bill.
Why It Matters
Duplicate CloudTrail trails can significantly impact your AWS costs. AWS charges $2.00 per 100,000 management events delivered beyond the first copy, which is free. For organizations with high AWS activity, these costs can accumulate rapidly.
Consider these facts:
- AWS provides the first copy of a management event for free, but subsequent copies of the same event incur charges
- Large enterprises can experience over 80% of their CloudTrail costs coming from redundant trails
- Some organizations have saved tens of thousands of dollars annually by removing duplicate trails
Organizations often create duplicate trails unintentionally, as different teams set up their own monitoring for specific needs without coordination. Eliminating these redundancies provides immediate cost savings without compromising monitoring capabilities.
How It Works
CloudFix reviews the CloudTrail trails across your AWS accounts and regions, read-only, and finds trails whose management events are already being recorded by another trail. Each redundant trail appears in your Recommendations for you to approve. Once approved, the fix runs as an AWS Systems Manager Automation runbook in your own account and stops the redundant trail from logging, while the trail that captures the full set of events keeps running. Every execution is logged.
No data is lost. The trail is stopped from recording new events, not deleted, so it can easily be reactivated if needed in the future.
Benefits
- Immediate cost savings: Eliminate redundant CloudTrail charges, which can represent up to 80% of CloudTrail costs
- Simplified audit landscape: Reduce complexity by removing unnecessary duplicate trails
- Non-disruptive: Trails are stopped, not deleted, allowing for easy reactivation if needed
- Compliance maintained: All events continue to be logged by at least one trail, preserving your audit capabilities
- Automated analysis: No need for manual comparison of complex trail configurations
AWS Services Affected
Related Resources
- AWS Documentation: Managing CloudTrail Costs
- AWS CloudTrail User Guide
- AWS Knowledge Center: How to remove duplicate CloudTrail events
- CloudFix Blog: Reduce AWS CloudTrail costs by de-duplicating trails
Frequently Asked Questions
Q: Will deactivating duplicate trails affect my compliance requirements?
A: No. The CloudFix Fixer ensures that all events continue to be logged by at least one active trail, maintaining full compliance with audit requirements. The primary purpose of CloudTrail logs is to exist in case of an audit, and as long as the data is being recorded somewhere, you remain compliant.
Q: What happens to existing logs when a trail is deactivated?
A: Existing logs remain unchanged in your S3 buckets. Deactivating a trail only prevents new events from being recorded to that specific trail going forward.
Q: What if I have dashboards or alerts based on the trail being deactivated?
A: You should identify any downstream consumers (such as dashboards, alerts, or automated processes) that depend on the trail being deactivated before approving the change. Then reconfigure these consumers to use the remaining active trail instead. Tools like Athena, CloudWatch Logs Insights, or other log analysis services can filter the necessary events from the consolidated trail.
Q: Is this change reversible?
A: Yes. CloudFix stops the trail from logging rather than deleting it, which means the trail configuration is preserved. You can easily reactivate the trail from the AWS Management Console if needed by clicking the “Start Logging” button.
Q: How does CloudFix determine which trail to deactivate?
A: CloudFix compares your trails and always keeps a trail that captures all of the required events, so only the redundant copy is recommended for deactivation. You see exactly which trail will be stopped before you approve the change.
Q: Does CloudFix automatically implement these changes?
A: CloudFix identifies the opportunities and presents them for your review. The changes are only implemented after you approve them, giving you full control over the process.
Ready to start saving on AWS? See how much you could cut from your cloud bill with a free cost optimization assessment, or explore CloudFix automated Finder/Fixers that eliminate waste across 30+ AWS services.
Related Articles
See whether this one applies to your account.
A free savings assessment reports which fixers can be applied to your environment. Results typically within 24 hours.