Enabling evidence finder
You can enable the evidence finder feature in Audit Manager to search for evidence in your AWS account. If you're a delegated administrator for Audit Manager, you can search for evidence for all member accounts in your organization.
Follow these steps to learn how to enable evidence finder. Pay close attention to the prerequisites, as you'll need specific permissions to create and manage an event data store in CloudTrail Lake for this functionality.
Prerequisites
Required permissions to enable evidence finder
To enable evidence finder, you need permissions to create and manage an event data store in CloudTrail Lake. To use the feature, you need permissions to perform CloudTrail Lake queries. For an example permission policy that you can use, see Example 4 (Permissions to enable evidence finder).
If you need help with permissions, contact your AWS administrator. If you’re an AWS administrator, you can copy the required permission statement and attach it to an IAM policy.
Procedure
Requesting to enable evidence finder
You can complete this task using the Audit Manager console, the AWS Command Line Interface (AWS CLI), or the Audit Manager API.
Note
You must enable evidence finder in each AWS Region where you want to search for evidence.
Next steps
After you've requested to enable evidence finder, you can check the status of your request. For instructions, see Confirming the status of evidence finder.