No more typing reviews! Try our Samantha, our new voice AI agent.

AWS CloudTrail vs CyberArk Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 3, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS CloudTrail
Ranking in User Activity Monitoring
2nd
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
16
Ranking in other categories
No ranking in other categories
CyberArk Privileged Access ...
Ranking in User Activity Monitoring
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of May 2026, in the User Activity Monitoring category, the mindshare of AWS CloudTrail is 9.1%, up from 7.4% compared to the previous year. The mindshare of CyberArk Privileged Access Manager is 12.6%, down from 17.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Activity Monitoring Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager12.6%
AWS CloudTrail9.1%
Other78.3%
User Activity Monitoring
 

Featured Reviews

CR
Principal Technical Architect at a tech vendor with 10,001+ employees
Comprehensive log management streamlines workflow and enhances monitoring capabilities
For monitoring, we use Dynatrace. Dynatrace is connected with AWS CloudTrail, so AWS CloudTrail sends the notifications via SNS to Dynatrace. We get notifications, and Dynatrace will send notifications. AWS CloudTrail is a log function that will store all logs easily for whatever services we are using on Amazon. All logs will be stored in AWS CloudTrail for 15 years, as we have the service purchased for that duration. The logs will be stored in AWS CloudTrail via S3 bucket. In AWS CloudTrail, we have enabled CPU, disk, and RAM monitoring. These are three services we are monitoring from AWS CloudTrail. AWS CloudTrail will monitor and produce graphs. We have separate L1 teams for monitoring; they will monitor and share the information. Also, Dynatrace will receive the information, and if any service goes beyond the threshold limit, AWS CloudTrail will create an alert. CloudTrail and CloudWatch are sister services. Both should be preconfigured internally. We only watch the dashboards because we can't go and watch each service; there are multiple servers running and multiple services configured, so we watch only the dashboard graphs. If any graph goes beyond the normal limit, we take action. We watch the graph. If any of the graphs show abnormal activity, then immediately we dig into AWS CloudWatch and AWS CloudTrail. We check the reason by verifying the logs. The graph will show you the time period, so we go into AWS CloudWatch, filter the logs for that particular time period, and from there, we identify the cause of the issue, and then we troubleshoot. API is a main element that allows us to connect AWS CloudWatch to AWS CloudTrail and AWS CloudTrail to Dynatrace. That connection is done via API. By API, everything is integrated. The integration part is managed by the API, transferring information from one service to another. We are not working on the API; the configuration team, the cloud operations team, they take care of it.
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana."
"The solution is good as a central logging platform for showing all cloud events."
"From a scalability point of view, the tool has no issue, and it is completely fine."
"AWS CloudTrail features a totally cloud-based deployment."
"AWS CloudTrail is very reasonably priced and I definitely recommend AWS CloudTrail to those who are planning or considering using it; it is a must-have service in the AWS environment, and it should be used."
"The product’s most valuable feature is monitoring. It helps us audit the changes in AWS account at the application and resource level."
"The management events and CloudTrail Insights are valuable."
"I have not encountered any stability issues, glitches, or performance problems with AWS CloudTrail."
"Identity and access management are fundamental in cybersecurity."
"DNA tool is amazing, far better than imaginable in previous years."
"Password Vault's policy configuration is very good - when you receive an attack, you can segment the structure of the project in order to isolate parts or users."
"The product has performed very well, and we will continue to invest in this space because the CyberArk tools are working well for us."
"If you compare this product with anything else as far as an endpoint solution, there is nothing which even compares."
"With reducing the privileged account access, there has been a huge improvement."
"CyberArk does its job very well, all the components are very useful and the benefits are all evident."
"We are able to centrally manage credentials, touch applications, and rotate passwords."
 

Cons

"Once the organization defines its policies, it must immediately enable AWS CloudTrail and integrate it with auto-remediation procedures using Lambda functions. This ensures that the main administrator can receive information quickly and on time without delay."
"The product's initial setup phase is not pretty straightforward."
"AWS CloudTrail should be redesigned to capture non-API calls. It would be more effective to have one tool that can perform multiple tasks instead of relying on multiple services for non-API activities."
"Filtering multiple values within the console is a feature that has yet to exist in AWS CloudTrail. You can look up a user identity, service, or action, but you can't search for multiple dimensions."
"Maybe if we could do direct queries on CloudTrail without needing to export it to Athena, that'd be great."
"AWS CloudTrail does not fit directly into our architecture as it functions more as a helper service, which limited our utilization of its capabilities."
"AWS CloudTrail could benefit from more comprehensive documentation and broader service integration."
"I have not experienced any challenges while using it."
"What needs to be improved in CyberArk Enterprise Password Vault is their customer support, particularly in terms of responsiveness, willingness to help, and being more understanding. The initial setup and upgrade process for the solution is complex and can only be done by CyberArk, so this is another area for improvement."
"There is a little bit of confusion in the implementation part, especially when one tries to understand the actual working of the product."
"The performance of this product needs to be improved. When the number of privileged accounts increases, i.e., exceeds 2000, then the performance of the system reduces."
"They can do a better job in the PSM space."
"Make it easier to deploy."
"It could be more user-friendly. Sometimes I encounter issues, and I do not know what the issue is."
"The only problem involves granting access to people who are authorized to view it."
"New functionalities and discovered bugs take longer to patch. We would greatly appreciate quicker development of security patches and bug corrections."
 

Pricing and Cost Advice

"CloudTrail itself is free of cost."
"AWS CloudTrail is a cheap solution."
"The solution is free if you don't need customizations but is not expensive otherwise."
"AWS CloudTrail is pretty affordable, and I have to double-check, but the service is free to use. I can add logs on the console, but if I want to store logs long-term, then I have to pay a storage fee, but it's relatively inexpensive."
"It is a very cheap service because management is a SaaS offering from AWS."
"AWS CloudTrail is free."
"The solution is costly but we get what we pay for."
"The price of CyberArk Privileged Access Manager could be less expensive."
"My company always complains about the cost of CyberArk Privileged Access Manager because it's too high."
"The cost is high compared to other products."
"I believe that this solution is priced well. It's the market leader and I think that it's the best solution."
"This product is very expensive."
"If you want a Ferrari, it will cost you. The solution is really nice, so it costs the client, but in the long run, it is very good. If you buy a solution that costs a lot to maintain because it is not stable, and you are frequently asking for consultant support, it costs more."
"If you are looking at implementing this solution, buy the training and go to it."
report
Use our free recommendation engine to learn which User Activity Monitoring solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
13%
Manufacturing Company
11%
Computer Software Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise7
Large Enterprise4
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
 

Questions from the Community

What is your experience regarding pricing and costs for AWS CloudTrail?
AWS CloudTrail is categorized into management events, data events, and CloudTrail Insights. For one hundred thousand events, management costs are approximately two dollars, data events ten cents, a...
What needs improvement with AWS CloudTrail?
I do not think there could be improvements in AWS CloudTrail because I am too small to suggest anything. It is already a well-established service from AWS, and I have only been using it for the las...
What is your primary use case for AWS CloudTrail?
My main use cases for AWS CloudTrail are troubleshooting, monitoring performance, and checking logs. AWS CloudTrail is primarily a log collection service. All AWS logs are sent to AWS CloudTrail, a...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
 

Also Known As

CloudTrail
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

HTC, British Gas, Solinor, 2C2P
Rockwell Automation
Find out what your peers are saying about AWS CloudTrail vs. CyberArk Privileged Access Manager and other solutions. Updated: April 2026.
893,244 professionals have used our research since 2012.