Comparison route

Single service comparison

Back to main page

Audit and Trace

AWS CloudTrail

AWS CloudTrail records account-level API calls and control-plane activity across AWS services as an ongoing event log, used for governance, compliance, operational auditing, and risk tracking. Events can be streamed to S3, CloudWatch Logs, or EventBridge with management, data, and insight event categories, configurable trails, and organization-level aggregation across member accounts.

AWS logo

AWS

Service information

AWS CloudTrail iconAWS CloudTrail

Shortname: CloudTrail

Huawei equivalent shortnames: CTS

Keywords: audit, trace, compliance

Differences vs Huawei

CloudTrail separates management events (control-plane API calls), data events (S3/Lambda object-level access), and insight events (anomaly detection), with trails scoped per-account, all-regions, or organization-wide via AWS Organizations. Huawei CTS uses a single tenant-level "system" management tracker that captures console and API operations; for global services the tracker must be configured in the CN-Hong Kong central region. CTS event taxonomy is flatter and built around cloud-service operation records rather than the management/data/insight tri-channel model, so event-category filters, data-event selectors, and Lake-style query stores have no direct counterparts.

Retention and delivery models diverge sharply. CloudTrail writes immutable event history (default 90 days recent, plus configurable trails and CloudTrail Lake retention up to 2557 days) and supports Kinesis/Firehose/Lake federation for analytics. CTS keeps a short recent-event window and relies on transferring trace files to OBS buckets (long-term encrypted cold storage, lifecycle-managed) or to LTS log streams (default 7 days, extendable to e.g. 180 days). DEW encrypts transferred files, and SMN handles key-event notifications, but there is no native CloudTrail Lake equivalent, no Insights feature, and no direct CloudWatch Logs event-streaming parity.

Integrations and operational responsibility differ. CloudTrail integrates with Config, Security Hub, Detective, CloudWatch, and EventBridge for automated response, finding correlation, and GUARD duty-style detection. On Huawei the equivalent audit-to-response surface requires composing CTS with LTS (structured log query), SecMaster (SIEM/correlation), DEW (KMS), OBS (archive), SMN (alerts), and IAM; CTS itself is free but downstream LTS/OBS/SecMaster consumption is billed. Architects must rebuild org-trail aggregation, member-account scoping, and detective/alert playbooks manually since CTS is tenant-scoped, not organization-aware.

Migration to Huawei

Assessment: Map every CloudTrail use case (compliance audit retention, data-event monitoring on S3/Lambda, Insights anomalies, Security Hub/Detective correlation) to a Huawei target. Treat CTS as the core equivalent for control-plane audit; supplement with LTS for searchable hot retention and structured queries, OBS for long-term immutable archive (set lifecycle + encryption via DEW/KMS), SecMaster for correlation and incident response, and SMN for key-event notifications. Validate CTS coverage against the AWS services being migrated using the "Supported Services and Operations" list, since not every AWS data-event source has a CTS equivalent.

Configure target environment: Enable the CTS system management tracker in every region used and, for global services, configure it in the CN-Hong Kong central region. Create additional data trackers where supported and enable "Transfer to LTS" (set log stream retention to the compliance-required window, e.g. 180 days) and "Transfer to OBS" for cold archive with a defined file prefix and bucket lifecycle policy. Grant CTS FullAccess/OBS permissions to admins and use IAM to replicate any CloudTrail read-only role separation; configure DEW KMS keys for trace file encryption and SMN topics for key-event notifications.

Rebuild detection and audit-response workflows: Translate CloudWatch Logs Insights and EventBridge rules into LTS structured-query SQL and SMN-triggered alarms or FunctionGraph functions; map Security Hub custom rules to SecMaster playbook and correlation rules. Re-point any downstream SIEM, lake, or analytics consumer from CloudTrail S3 prefixes/SQS notifications to the OBS trace-file path and LTS ingestion, transforming the CloudTrail JSON schema to the CTS trace structure (Trace Structure/Example Traces) with care since field names and nesting differ.

Validation, cutover, and cost gaps: Run CTS and remaining AWS audit in parallel during migration, sample-comparing event coverage for migrated services against CloudTrail. Confirm integrity verification, event delivery latency, and notification reliability before switching dashboards and compliance reports to CTS/LTS/SecMaster. Cost model changes materially: CTS itself is free, so TCO shifts to LTS ingested/GB storage, OBS bucket storage and request/traffic fees, SecMaster edition, and SMN messages-size reassessment at peak API volume, retention length, and cross-region OBS access.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Cloud Trace Service iconCloud Trace Service

Shortname: CTS

General function: Audit and Trace

Operation audit trail and trace service.

Keywords: audit, trace, compliance