AWS customers use AWS CloudTrail Lake to aggregate and analyze their AWS activity for security, operational troubleshooting, and compliance purposes. However, when investigating security incidents or conducting compliance audits, customers often need additional business context beyond the basic event details – like which team or project owns the affected resources, or what where the properties of the IAM principal that made changes to the resources. Today, we’re excited to announce a new enhancement to CloudTrail Lake: Event enrichment which makes it easier to categorize, search, and analyze your AWS activity.