1 Comment
Thanks for the helpful article. I have a follow-up question:
What if the EC2 instances were** launched** more than 90 days ago? Since CloudTrail’s Event History only retains logs for the last 90 days, and I did not enable CloudTrail logging to an S3 bucket, I'm unable to retrieve older events.
I also have multiple IAM users and many EC2 instances across different regions, so it's becoming difficult to trace who launched which instance.
Is there any way to recover this information, or any AWS-native alternatives to identify the user who launched older instances without historical CloudTrail logs in S3?
replied 10 months ago
Relevant content
- AWS OFFICIALUpdated 3 years ago

