After you turn on CloudTrail integration with CloudWatch Logs, which you can do from the CloudTrail console or using the AWS SDKs or AWS CLI, CloudTrail begins to continuously and automatically deliver all the CloudTrail events associated with API activity to a CloudWatch Logs log group you specify. In the CloudWatch console, you can create metric filters, assign a CloudWatch metric, and create CloudWatch alarms to receive notification about specific API activity. For examples of creating CloudWatch alarms for critical security and network API activity such as changes to Security Groups, and Network ACLs, go to the CloudTrail documentation.
CloudTrail integration with CloudWatch Logs is currently supported in the N.Virginia, Oregon, and Ireland AWS regions, where CloudWatch Logs is supported. More regions will be supported in the future. After you turn on the integration, you incur standard CloudWatch Logs and CloudWatch charges.