Creating an IAM role

After clicking on Continue, you will be redirected to the IAM console, to create an IAM role to grant the principal (in this case, Greeter-Audit-Trail, to assume permission to push events to the log group named CloudTrail/GreeterAuditTrailGroup).

This linking is done by AWS, to aid in the seamless integration of CloudTrail with CloudWatch.

After clicking on Allow, you will be redirected to the CloudTrail dashboard, and the integration will be complete. The following screenshot illustrates this step:

CloudTrail dashboard completing integration

The policy document for the IAM role can be viewed by clicking on View Policy ...

Get Hands-On Serverless Applications with Kotlin now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.