sparse-intern-71089
09/02/2020, 5:46 PMbroad-dog-22463
09/02/2020, 5:48 PMgifted-vase-28337
09/02/2020, 6:05 PMbroad-dog-22463
09/02/2020, 7:40 PMgifted-vase-28337
09/02/2020, 11:24 PMpulumi destroy
and pulumi up
it was created as expected). However, when I pass the ARN of the newly-created log group into CloudTrail, I get the following error:
error: Error creating CloudTrail: InvalidCloudWatchLogsLogGroupArnException: Check the log group ARN: CloudTrail can't validate it.
According to the AWS java SDK docs, "This exception is thrown when the provided CloudWatch log group is not valid."broad-dog-22463
09/02/2020, 11:40 PMgifted-vase-28337
09/25/2020, 5:52 PMlog_group
resource ARN lacks the :*
suffix required for the CloudTrail resource. My workaround:
log_group_arn = pulumi.Output.apply(log_group.arn, lambda arn: f"{arn}:*")
trail = cloudtrail.Trail(
...
cloud_watch_logs_group_arn=log_group_arn,
...
)
broad-dog-22463
09/25/2020, 6:30 PMbroad-dog-22463
09/25/2020, 6:30 PMbroad-dog-22463
09/25/2020, 6:30 PM