I have an Organization setup in AWS and have a Management
account and also a Sec
Account. I have Delegated Admin of CloudTrail from the Management
account to the Sec
Account.
In the Sec
account I then setup an Organization
CloudTrail
and all logs are been delivered to an S3
bucket. This all works fine.
I would like to setup the streaming of the CloudTrail
logs
to CloudWatch
but in the Sec
Account this option is greyed out as seen below
If I log back into the Management
account this option is NOT greyed out and can setup this up.
This would mean that the CloudWatch
logs would be in the Management
Account and the CloudTrail
logs in the Sec
Account which is not what I want.
Why is the option to setup CloudWatch
logs in the Sec
account greyed out and is there a way round this? Is it possible to have an Organization
Trail
setup to deliver the logs in the Sec
Account and also to get those logs streamed into CloudWatch
?