
AWS CloudTrail
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Connect AWS CloudTrail to PostHog to sync your data into the PostHog data warehouse for analysis and modeling.
Sync CloudTrail events and settings from one AWS region.
Grant cloudtrail:LookupEvents, cloudtrail:DescribeTrails, and cloudtrail:ListEventDataStores for the tables you select.
Enter an access key ID and secret access key. Add a session token for temporary credentials.
Event imports cover the past 90 days. They include management events and trail Insights events, but exclude data events. Insights must be enabled on a trail to return Insights events. The event stores table imports CloudTrail Lake settings, not stored events. CloudTrail Lake is available only to existing customers after May 31, 2026.
Configuration
| Option | Description |
|---|---|
AWS access key IDType: text Required: True | |
AWS secret access keyType: password Required: True | |
AWS session tokenType: password Required: False | Temporary credentials expire. Update them before scheduled imports run. |
AWS regionType: text Required: True |
Linking AWS CloudTrail to PostHog
- Go to the Data pipeline page in PostHog
- Click New source and select AWS CloudTrail
- Fill in the required configuration fields
- Click Next, select the tables you want to sync, and then press Import
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
events | Management events from the past 90 days in the selected AWS region. Data events are excluded. | Incremental, Full refresh | event_time | — |
insight_events | Insights events from the past 90 days for trails with Insights enabled in the selected region. | Incremental, Full refresh | event_time | — |
trails | Trail settings in the selected region, including shadow trails. | Full refresh | — | — |
event_data_stores | CloudTrail Lake event store settings in the selected region. Stored events are excluded. | Full refresh | — | — |