AWS CloudTrail allows you to view and download the last 90 days of your account activity for create, modify, and delete operations of supported services free of charge.

AWS CloudTrail allows you to setup a trail that delivers a single copy of management events in each region free of charge. Once a CloudTrail trail is setup, Amazon S3 charges apply based on your usage. You will be charged for any data events or additional copies of management events recorded in that region.

  • Management events: provide insights into the management (“control plane”) operations performed on resources in your AWS account. For example, CloudTrail delivers management events for API calls such as launching Amazon EC2 instances or creating Amazon S3 buckets. Management events are enabled by default when you configure a trail and record supported activity at the account level. The first copy of management events within each region is delivered free of charge. Additional copies of management events are charged $2.00 per 100,000 events.
  • Data events: provide insights into the resource (“data plane”) operations performed on or within the resource itself. Data events are often high volume activities and include operations such as Amazon S3 object level APIs and Lambda function invoke API. For example, CloudTrail delivers data events for AWS Lambda Invoke API calls and Amazon S3 object level APIs such as Get, Put, Delete and List actions. Data events are recorded only for the Lambda functions and S3 buckets you specify and are charged at $0.10 per 100,000 events.

Example 1

Your AWS account does not have AWS CloudTrail setup. Supported management event activity recorded by AWS CloudTrail for the last 90 days can be viewed and searched free of charge from within the AWS CloudTrail console or AWS CLI.

Example 2

Your AWS account has AWS CloudTrail setup and is configured to record duplicate copies of management events across two trails and data events in one trail. In a month, you had 150,000 management events and 2M data events. Your charges for the monthly billing period are calculated as follows:

Charges for the first copy of 150,000 management events = $0 (first copy of management events is free)

Charges for the second copy of 150,000 management events = 150,000 at a price of $2 per 100,000 events = $3

Charges for 2M data events = 2M at a price of $0.10 per 100,000 events = $2


Once a CloudTrail trail is setup, Amazon S3 charges apply based on your usage, since AWS CloudTrail delivers logs to an S3 bucket. Typical Amazon S3 charges are less than $3 per month for most accounts.

You can optionally specify an Amazon SNS topic to get notified about CloudTrail log file delivery to Amazon S3, send CloudTrail logs to CloudWatch Logs, or encrypt your CloudTrail logs using AWS Key Management Service (AWS KMS). When these features are used, standard usage charges for the related services apply. For this pricing information, see the pricing page for each service.