CloudBurn Logo
CloudBurnHome
  • Blog
  • Docs
  • Tools
  • Features
  • Roadmap
  • Changelog
Join the CloudBurn Discord community
1.8k
Join the CloudBurn Discord community1.8k
  • Home
  • Blog
  • Docs
  • Tools
  • Features
  • Roadmap
  • Changelog
Navigation
    • Overview
    • Understanding Rules
      • CloudFront
      • CloudTrail
      • CloudWatch
      • AWS Config
      • Cost Explorer
      • Cost Guardrails
      • Cost Optimization Hub
      • DynamoDB
      • EBS
      • EC2
      • ECR
      • ECS
      • EKS
      • ElastiCache
      • ELB
      • EMR
      • KMS
      • Lambda
      • RDS
      • Redshift
      • Route 53
      • S3
      • SageMaker
      • Secrets Manager
      • Tagging
    • Overview
    • Understanding Rules
      • CloudFront
      • CloudTrail
      • CloudWatch
      • AWS Config
      • Cost Explorer
      • Cost Guardrails
      • Cost Optimization Hub
      • DynamoDB
      • EBS
      • EC2
      • ECR
      • ECS
      • EKS
      • ElastiCache
      • ELB
      • EMR
      • KMS
      • Lambda
      • RDS
      • Redshift
      • Route 53
      • S3
      • SageMaker
      • Secrets Manager
      • Tagging
Loading documentation page
CloudBurn Logo
CloudBurn

AWS cost intelligence platform that automatically identifies waste, optimizes resources, and provides actionable recommendations to reduce cloud spend.

Product

  • Features
  • Roadmap
  • Changelog
  • About
  • Blog
  • Newsletter
  • Docs
  • Contact

Free Tools

  • Lambda Cost Calculator
  • EC2 Pricing Calculator
  • S3 Pricing Calculator
  • EBS Pricing Calculator
  • Fargate Pricing Calculator
  • RDS Pricing Calculator
  • Aurora Cost Calculator
  • All AWS pricing calculators →

Newsletter

Subscribe for CloudBurn product updates, changelogs, and actionable AWS cost optimization tips delivered to your inbox.

Newsletter signup form loading.
Enter your email…
Subscribe
---- subscribers
OR SIGN UP WITH
GGH

By signing up you agree to our privacy policy.

CloudBurn © 2026 | Terms & Privacy

Built with ❤️ by Towards the Cloud

CloudBurn Rules

CloudTrail Rules

CloudBurn cost optimization rules for AWS CloudTrail.

These rules catch redundant CloudTrail trail configurations that generate duplicate event charges without adding audit coverage.

Rule IDScan TypeSeverityName
CLDBRN-AWS-CLOUDTRAIL-1DiscoveryMediumCloudTrail Redundant Global Trails
CLDBRN-AWS-CLOUDTRAIL-2DiscoveryMediumCloudTrail Redundant Regional Trails

CLDBRN-AWS-CLOUDTRAIL-1

CloudTrail Redundant Global Trails

Scan type: Discovery

Severity: Medium

What it checks

Flags multi-region CloudTrail trails when an account has more than one trail configured to cover all regions. A single multi-region trail is sufficient for account-wide audit coverage; additional multi-region trails record the same events and incur duplicate charges.

Why it matters

CloudTrail charges $2 per 100,000 management events after the first free copy. Each additional multi-region trail processes the full event volume across every region, so one redundant trail can easily double your CloudTrail spend.

What triggers a finding

The account has more than one multi-region trail. CloudBurn keeps the trail with the lowest ARN (alphabetically first) and flags all others.

How to remediate

Delete all but one multi-region trail per account. Verify the trail you keep has delivery to an S3 bucket configured correctly before deleting the others.


CLDBRN-AWS-CLOUDTRAIL-2

CloudTrail Redundant Regional Trails

Scan type: Discovery

Severity: Medium

What it checks

Flags single-region CloudTrail trails when more than one trail covers the same region in the same account. A single trail per region captures all regional events; additional trails produce identical records at additional cost.

Why it matters

Per-trail event charges apply regardless of whether another trail already covers the same region. Multiple regional trails for the same region multiply costs with no audit benefit.

What triggers a finding

The account has more than one single-region trail for the same region. CloudBurn flags duplicates beyond the first trail per region.

How to remediate

Delete all but one single-region trail per region. If you need both multi-region and regional coverage, use the multi-region trail and remove the redundant regional one.


See Also

  • CLI discover command — scan live CloudTrail resources
  • SDK Reference — run discovery programmatically
← CloudFrontCloudWatch →