Refer to the following guide to learn how to use IAM in the cloud\ <https://scribehow.com/shared/Creating_an_IAM_User_and_User_Group_in_AWS_Management_Console__hWNiiXlcRJKFqYZZEJD-cg>
Sign in to **AWS Management Console** as an **IAM User** **Pre-requisite** - Ensure you have selected the AWS region closest to your location\ For this guide, we will be using us-east-2 (Ohio) as a preferred choice
Type **CloudTrail** in the search bar and click on **CloudTrail** to view the CloudTrail Dashboard
**What is CloudTrail in AWS?** It is a service provided by Amazon Web Services (AWS) that enables governance, compliance, operational auditing, and risk auditing of your AWS account. It records all API calls made on your account and delivers the log files to your Amazon S3 bucket.
On the **CloudTrail** dashboard click on the **Trails** from the left bar
**Trails** wizard will open, click on the **Create trail** button on the right side
**Choose trail attributes** wizard will open, give **Trail name** as "**cloudtrail-management-events**" and select the option **Create new S3 bucket** for **Storage location**
Scroll to the **Trail log bucket and folder section,** type "**aws-cloudtrail-management-events-in28minutes**" in the text input field and tick the checkbox **Enabled** for **Log file SSE-KMS encryption**
**What is Log file SSE-KMS encryption?** Log file SSE-KMS encryption refers to encrypting log files using the AWS Key Management Service (KMS) when using Server-Side Encryption (SSE) for Amazon Simple Storage Service (S3).
Scroll to the **Customer managed AWS KMS key** section and select the **New** radio button and type "**cloudtrail-kms-key"** in the text input field
Scroll the page and click on the **Next** button
**Choose log events** wizard will open, scroll to the **Management events** section and tick the checkbox **Write** for **API activity** then click on the **Next** button
**Review and create** wizard will open, review the settings and click on **Create trial** button
Trail successfully created
Congratulations, the CloudTrail trail has been successfully created!
On the **Trails** dashboard, click on the **aws-cloudtrial-management-events-in28minutes** link from the **S3 bucket**
**Amazon S3** dashboard will open, scroll the page and click on the **CloudTrail/** folder link
**CloudTrail/** wizard will open, click on the Folder Name **us-east-2/**
**us-east-2/** wizard will open, click on the Folder Name **2024/**
**2024/** wizard will open, click on the Folder Name **03/**