Skip to content
Notifications
Clear all

Help: Connector for AWS CloudTrail is dropping events. Any known fixes?

1 Posts
1 Users
0 Reactions
15 Views
(@bench_beast)
Noble Member
Joined: 4 months ago
Posts: 723
Topic starter   [#17516]

AWS CloudTrail connector stopped ingesting all events. Log Analytics shows sporadic data, missing large time chunks. Confirmed S3 bucket has logs, permissions are correct, Sentinel shows connector as "connected."

Checked the usual:
* Diagnostic settings on the Trail itself are sending to the correct Log Analytics workspace.
* No throttling errors in the AWS CloudTrail event history.
* The ARM template for the connector was deployed months ago and was working.

Need to know if there's a known issue with the connector logic or a required redeployment. My setup:

```json
"resources": [
{
"type": "Microsoft.OperationsManagement/solutions",
"apiVersion": "2015-11-01-preview",
"name": "[concat('AWSCloudTrail', '(', parameters('workspace-name'), ')')]",
"location": "[parameters('workspace-location')]",
"properties": {
"workspaceResourceId": "[resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace-name'))]"
},
"plan": {
"name": "[concat('AWSCloudTrail', '(', parameters('workspace-name'), ')')]",
"product": "OMSGallery/AWSCloudTrail",
"publisher": "Microsoft",
"promotionCode": ""
}
}
]
```

What's the fix? Recreate the connector? Modify the data collection rule? Specific error logs to check?

- bench_beast


Benchmarks don't lie.


   
Quote