1. Go to IAM configuration panel and click on “Users”

AWS

2. Add a new user filling the name and marking the access type “Programmatic access”. Then click on Next.

AWS

3. Click on Attach existing policies directly. Find CloudWatchReadOnlyAccess and mark it. Then click on next.

AWS

4. In the tags page click on next.

AWS

5. Create user and then download the csv file with the access and secret keys.

AWS

6. Fill the following inputs with the info obtained in previous steps.

AWS

Configuring AWS Cloudwatch

7. In the CloudTrail panel, select “Create trail”.

AWS

8. Fill in the “Trail name” field.

AWS

9. Mark “Select all S3 buckets in your account”.

AWS

10. Fill in the “S3 bucket” field. The name of the bucket must be unique in S3. Then click on “Create”.

AWS

11. Click on the name of the trail to edit.

AWS

12. Configure CloudWatch Logs.

AWS

13. Fill the group name and continue.

AWS

14. Click on “Allow” to grant CloudTrail permissions.

AWS