No more typing reviews! Try our Samantha, our new voice AI agent.

AWS CloudTrail vs Idira Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS CloudTrail
Ranking in User Activity Monitoring
2nd
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
16
Ranking in other categories
No ranking in other categories
Idira Privileged Access Man...
Ranking in User Activity Monitoring
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
Enterprise Password Managers (3rd), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of June 2026, in the User Activity Monitoring category, the mindshare of AWS CloudTrail is 10.7%, up from 8.0% compared to the previous year. The mindshare of Idira Privileged Access Manager is 11.8%, down from 16.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Activity Monitoring Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager11.8%
AWS CloudTrail10.7%
Other77.5%
User Activity Monitoring
 

Featured Reviews

CR
Principal Technical Architect at a tech vendor with 10,001+ employees
Comprehensive log management streamlines workflow and enhances monitoring capabilities
For monitoring, we use Dynatrace. Dynatrace is connected with AWS CloudTrail, so AWS CloudTrail sends the notifications via SNS to Dynatrace. We get notifications, and Dynatrace will send notifications. AWS CloudTrail is a log function that will store all logs easily for whatever services we are using on Amazon. All logs will be stored in AWS CloudTrail for 15 years, as we have the service purchased for that duration. The logs will be stored in AWS CloudTrail via S3 bucket. In AWS CloudTrail, we have enabled CPU, disk, and RAM monitoring. These are three services we are monitoring from AWS CloudTrail. AWS CloudTrail will monitor and produce graphs. We have separate L1 teams for monitoring; they will monitor and share the information. Also, Dynatrace will receive the information, and if any service goes beyond the threshold limit, AWS CloudTrail will create an alert. CloudTrail and CloudWatch are sister services. Both should be preconfigured internally. We only watch the dashboards because we can't go and watch each service; there are multiple servers running and multiple services configured, so we watch only the dashboard graphs. If any graph goes beyond the normal limit, we take action. We watch the graph. If any of the graphs show abnormal activity, then immediately we dig into AWS CloudWatch and AWS CloudTrail. We check the reason by verifying the logs. The graph will show you the time period, so we go into AWS CloudWatch, filter the logs for that particular time period, and from there, we identify the cause of the issue, and then we troubleshoot. API is a main element that allows us to connect AWS CloudWatch to AWS CloudTrail and AWS CloudTrail to Dynatrace. That connection is done via API. By API, everything is integrated. The integration part is managed by the API, transferring information from one service to another. We are not working on the API; the configuration team, the cloud operations team, they take care of it.
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a stable solution. AWS handles it well."
"The solution is good as a central logging platform for showing all cloud events."
"One of the most valuable features of AWS CloudTrail is its ability to track and monitor API calls detailedly."
"AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana."
"In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the employees' activities, revealing that they were downloading specific files from our customer's environment. Without it enabled, we wouldn't have been aware of this."
"What I found most valuable in AWS CloudTrail is that it provides a good context of what's happening in the environment, so it's an excellent way to baseline what's occurring. I also like that AWS CloudTrail helps with audits."
"AWS CloudTrail features a totally cloud-based deployment."
"The management events and CloudTrail Insights are valuable."
"Since then, CyberArk's Privileged Access Management is still our central solution for the entire estate, including all our servers (Windows/Unix), databases, devices, and so on, with around 5,000 to 8,000 users globally."
"The most important feature is managing the credentials and implementing those policies which rotate the credentials. Session Manager is also key in not letting the users have access to those credentials. Instead, CyberArk actually manages everything by itself."
"It gives us the capability to rotate passwords, which is the biggest thing because we do not want them being stagnant so every service account that we have needs to be rotated at least once a year."
"The vault is almost a set-and-forget solution."
"CyberArk is one of the best PAM solutions and one of the most expensive, but it works better than the others, so the pricing is fair."
"CyberArk Privileged Access Manager has positively impacted my organization, showing significant improvement since all sessions are monitored and isolated using isolated RDP sessions, which are created temporarily and expire if not used."
"Their legacy of more than 20 years is very valuable; it brings a lot of stability to the product and a wide variety of integration with the ecosystem, and because of these factors it has been very successful in deployment, making the PAM platform very stable and strong."
"The interface is very simple to use."
 

Cons

"I have not experienced any challenges while using it."
"The platform’s reporting log sheet feature could be more user-friendly."
"Searching the logs is not very easy; it requires a lot of patience and hard work to find the right information in the log."
"AWS CloudTrail does not fit directly into our architecture as it functions more as a helper service, which limited our utilization of its capabilities."
"More controls should be introduced in CloudTrail, especially to see the logs in CloudTrail itself without saving them in S3, as S3 starts to incur charges."
"AWS CloudTrail can sometimes generate too much information, which might lead to a lot of unnecessary data, particularly false positives."
"AWS CloudTrail should be redesigned to capture non-API calls. It would be more effective to have one tool that can perform multiple tasks instead of relying on multiple services for non-API activities."
"AWS CloudTrail only supports AWS, and Azure has its functions, GCP has their own. Dynatrace offers more flexible dashboards and services, making it more adaptable compared to AWS CloudTrail."
"Performance of PIM could be better and intended for usability as well as security."
"The tool needs to improve its usage and interface. They need to have a modern and useful interface. I want the product to improve its integration capabilities as well since some of the integration features do not work always."
"Areas of CyberArk Privileged Access Manager that can be improved include offering clearer configuration options."
"The major pain point that we have is the capacity of CyberArk due to the sheer volume of NPAs that we are managing."
"It is complicated to deploy for Windows servers compared to other vendors."
"The license is expensive."
"Authentication to the PVWA utilises integration to IIS. Therefore, it is not as strong as desired."
"PAM could be more user-friendly and CyberArk could update the documentation to include more real-world examples. You have to learn it yourself through trial and error. In particular, the online documentation should have more information about troubleshooting."
 

Pricing and Cost Advice

"CloudTrail itself is free of cost."
"It is a very cheap service because management is a SaaS offering from AWS."
"AWS CloudTrail is a cheap solution."
"The solution is free if you don't need customizations but is not expensive otherwise."
"AWS CloudTrail is free."
"AWS CloudTrail is pretty affordable, and I have to double-check, but the service is free to use. I can add logs on the console, but if I want to store logs long-term, then I have to pay a storage fee, but it's relatively inexpensive."
"The product's licensing is yearly. I would rate the solution's pricing a six out of ten."
"The pricing for CyberArk Privileged Access Manager is quite expensive, and the pricing varies from region to region. In APAC, CyberArk Privileged Access Manager can be obtained for less than in North America, according to my understanding."
"Payments have to be made on a yearly basis toward the licensing costs of the solution."
"This product is very expensive."
"They have two types of licensing: purchase and subscription. You have to pay for each admin user, such as Microsoft admin, mail admin, database admin, etc."
"The product’s pricing is feasible for enterprise customers. The pricing is expensive for smaller businesses. You need to pay additional costs for service implementation and local support."
"Compared to other solutions, it is costly."
"There are additional features added to our CyberArk Privileged Access Manager license. For example, features that allow us to integrate into various kinds of platforms."
report
Use our free recommendation engine to learn which User Activity Monitoring solutions are best for your needs.
896,942 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
13%
Manufacturing Company
11%
Computer Software Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise7
Large Enterprise4
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
 

Questions from the Community

What is your experience regarding pricing and costs for AWS CloudTrail?
AWS CloudTrail is categorized into management events, data events, and CloudTrail Insights. For one hundred thousand events, management costs are approximately two dollars, data events ten cents, a...
What needs improvement with AWS CloudTrail?
I do not think there could be improvements in AWS CloudTrail because I am too small to suggest anything. It is already a well-established service from AWS, and I have only been using it for the las...
What is your primary use case for AWS CloudTrail?
My main use cases for AWS CloudTrail are troubleshooting, monitoring performance, and checking logs. AWS CloudTrail is primarily a log collection service. All AWS logs are sent to AWS CloudTrail, a...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

CloudTrail
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

HTC, British Gas, Solinor, 2C2P
Rockwell Automation
Find out what your peers are saying about AWS CloudTrail vs. Idira Privileged Access Manager and other solutions. Updated: April 2026.
896,942 professionals have used our research since 2012.