setting-up-cloudtrail-multi-region
aws/agent-toolkit-for-aws
How to install setting-up-cloudtrail-multi-region
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill setting-up-cloudtrail-multi-regionFull instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: setting-up-cloudtrail-multi-region description: Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration, and CloudWatch Logs Insights queries for security monitoring and compliance auditing. Use when setting up centralized API activity logging across all AWS regions. version: 1
Setting Up CloudTrail Multi-Region
Overview
Domain expertise for enabling AWS CloudTrail across all regions to capture comprehensive API activity logs and configuring CloudWatch Logs Insights for security monitoring, compliance auditing, and operational analysis.
Set up a multi-region trail
To create a centralized multi-region CloudTrail trail with S3 storage, CloudWatch Logs integration, and log analysis, follow the procedure exactly. See CloudTrail multi-region setup procedure.
Troubleshooting
S3 bucket already exists
Choose a different globally unique name, or add a timestamp or organization identifier.
Permission denied errors
Verify your identity with aws sts get-caller-identity. Ensure your user/role has required actions attached. Do NOT use *FullAccess managed policies.
Trail not logging
Verify IAM role permissions, check S3 bucket policy allows CloudTrail access, and ensure the trail is started with start-logging.
Missing events in CloudWatch
Allow 5-15 minutes for initial log delivery. Verify the CloudWatch Logs role ARN is correct and the log group exists in the same region as the trail.
Opt-in region events not appearing
This is normal — events from opt-in regions may take several hours. Wait up to 24 hours before investigating further.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

setting-up-cloudwatch-alarm-notifications
Set up encrypted SNS topics and subscriptions for CloudWatch alarm notifications with proper security controls.

setting-up-ec2-instance-profiles
Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials. Use when an EC2 instance needs permissions to access AWS services like S3, DynamoDB, SQS, or CloudWatch through temporary credentials.

storing-and-querying-vectors
Cost-effective vector storage and semantic search with Amazon S3 Vectors

troubleshooting-application-failures
Diagnose application failures by analyzing CloudWatch logs for error patterns and root causes.

troubleshooting-efs
>

troubleshooting-s3-files
Diagnose and resolve Amazon S3 Files mount failures, permissions, sync, and performance issues.