Try our new research platform with insights from 80,000+ expert users

AWS CloudTrail vs CyberArk Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 3, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS CloudTrail
Ranking in User Activity Monitoring
2nd
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
16
Ranking in other categories
No ranking in other categories
CyberArk Privileged Access ...
Ranking in User Activity Monitoring
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Mainframe Security (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of March 2026, in the User Activity Monitoring category, the mindshare of AWS CloudTrail is 7.3%, up from 6.7% compared to the previous year. The mindshare of CyberArk Privileged Access Manager is 11.5%, down from 19.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Activity Monitoring Mindshare Distribution
ProductMindshare (%)
CyberArk Privileged Access Manager11.5%
AWS CloudTrail7.3%
Other81.2%
User Activity Monitoring
 

Featured Reviews

CR
Principal Technical Architect at a tech vendor with 10,001+ employees
Comprehensive log management streamlines workflow and enhances monitoring capabilities
For monitoring, we use Dynatrace. Dynatrace is connected with AWS CloudTrail, so AWS CloudTrail sends the notifications via SNS to Dynatrace. We get notifications, and Dynatrace will send notifications. AWS CloudTrail is a log function that will store all logs easily for whatever services we are using on Amazon. All logs will be stored in AWS CloudTrail for 15 years, as we have the service purchased for that duration. The logs will be stored in AWS CloudTrail via S3 bucket. In AWS CloudTrail, we have enabled CPU, disk, and RAM monitoring. These are three services we are monitoring from AWS CloudTrail. AWS CloudTrail will monitor and produce graphs. We have separate L1 teams for monitoring; they will monitor and share the information. Also, Dynatrace will receive the information, and if any service goes beyond the threshold limit, AWS CloudTrail will create an alert. CloudTrail and CloudWatch are sister services. Both should be preconfigured internally. We only watch the dashboards because we can't go and watch each service; there are multiple servers running and multiple services configured, so we watch only the dashboard graphs. If any graph goes beyond the normal limit, we take action. We watch the graph. If any of the graphs show abnormal activity, then immediately we dig into AWS CloudWatch and AWS CloudTrail. We check the reason by verifying the logs. The graph will show you the time period, so we go into AWS CloudWatch, filter the logs for that particular time period, and from there, we identify the cause of the issue, and then we troubleshoot. API is a main element that allows us to connect AWS CloudWatch to AWS CloudTrail and AWS CloudTrail to Dynatrace. That connection is done via API. By API, everything is integrated. The integration part is managed by the API, transferring information from one service to another. We are not working on the API; the configuration team, the cloud operations team, they take care of it.
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AWS CloudTrail provides significant efficiency gains as it allows thorough monitoring of the environment, contributing substantially to security improvements."
"AWS CloudTrail integrates with AWS Config and provides custom event, security, and compliance auditing."
"AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana."
"One of the most valuable features of AWS CloudTrail is its ability to track and monitor API calls detailedly."
"In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the employees' activities, revealing that they were downloading specific files from our customer's environment. Without it enabled, we wouldn't have been aware of this."
"From a scalability point of view, the tool has no issue, and it is completely fine."
"The solution is good as a central logging platform for showing all cloud events."
"What I found most valuable in AWS CloudTrail is that it provides a good context of what's happening in the environment, so it's an excellent way to baseline what's occurring. I also like that AWS CloudTrail helps with audits."
"It has helped from an auditing perspective identify who has access to privileged accounts."
"CyberArk has helped us to identify, store, protect, and monitor the usage of privileged accounts."
"CyberArk has the most extensive hardening and encryption techniques I have seen in a product, with equal intentions."
"CyberArk has been the most stable platform I have ever worked on and our redundancies allow for 100% uptime."
"Service count rotation is probably one of my favorite features... The ability to automatically rotate any password I need to really helps with the entire enterprise strategy that we're pushing right now."
"Rather than multiple tools for maintaining regulatory compliance around passwords and privileged accounts, we have centralized as much as possible with CyberArk."
"CyberArk is the best out there."
"DVR like video recording and text-based recording for easier audits."
 

Cons

"The solution's operation visibility could be improved."
"More controls should be introduced in CloudTrail, especially to see the logs in CloudTrail itself without saving them in S3, as S3 starts to incur charges."
"The solution should incorporate visibility for CloudWatch events."
"Filtering multiple values within the console is a feature that has yet to exist in AWS CloudTrail. You can look up a user identity, service, or action, but you can't search for multiple dimensions."
"AWS CloudTrail could benefit from more comprehensive documentation and broader service integration."
"AWS CloudTrail should be redesigned to capture non-API calls. It would be more effective to have one tool that can perform multiple tasks instead of relying on multiple services for non-API activities."
"Once the organization defines its policies, it must immediately enable AWS CloudTrail and integrate it with auto-remediation procedures using Lambda functions. This ensures that the main administrator can receive information quickly and on time without delay."
"AWS CloudTrail can sometimes generate too much information, which might lead to a lot of unnecessary data, particularly false positives."
"Enhanced PSM support for Java based applications."
"CyberArk Privileged Access Manager is more expensive than its competitors, such as BeyondTrust, Delinea, and ManageEngine PAM360."
"The current interface is not very intuitive."
"Password Vault is much pricier than other solutions. A vendor team might struggle to explain why that price is justified. There are good alternatives that cost less."
"This is where we have had some woes with this software."
"The web access piece needs improvement. We have version 9.5 or 9.9.5, and now we have to upgrade to version 10."
"Integration of this tool with SAML is a problem, as there is a bug."
"The user interface needs to be improved."
 

Pricing and Cost Advice

"AWS CloudTrail is free."
"CloudTrail itself is free of cost."
"The solution is free if you don't need customizations but is not expensive otherwise."
"AWS CloudTrail is pretty affordable, and I have to double-check, but the service is free to use. I can add logs on the console, but if I want to store logs long-term, then I have to pay a storage fee, but it's relatively inexpensive."
"It is a very cheap service because management is a SaaS offering from AWS."
"AWS CloudTrail is a cheap solution."
"It's an affordable platform."
"CyberArk Privileged Access Manager is perceived to be somewhat overpriced compared to similar market products. It is a little bit overvalued. It could come down a little bit for my liking. However, the industry-leading reputation and the quality of service justify the high price point to some extent."
"Before we bought it, they were licensing each function individually, which got complicated and very expensive. When we decided to buy it, it was much more straightforward and still quite expensive, but it brings a lot of value and risk reduction to the organization."
"The price of CyberArk Privileged Access Manager is expensive. There are no other fees other than the standard licensing fees."
"Since CyberArk is at the top of the Gartner list, the cost is indeed on the higher side, but customers must discern which entities are essential to purchase. They should weigh the cost against the quality received."
"CyberArk Enterprise Password Vault's pricing is reasonable."
"I haven't seen the numbers. I know it is not cheap, but I don't know what it is. I would rate it a six out of ten in terms of pricing. It is definitely more expensive than the other product, but it also provides more functionality, and it is modular too. So, we pay for the functionality we're actually going to use, and that's nice."
"In comparison to other products on the market, CyberArk is a more costly product."
report
Use our free recommendation engine to learn which User Activity Monitoring solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
14%
Manufacturing Company
10%
Computer Software Company
8%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise7
Large Enterprise3
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise174
 

Questions from the Community

What do you like most about AWS CloudTrail?
In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the emplo...
What is your experience regarding pricing and costs for AWS CloudTrail?
AWS CloudTrail is categorized into management events, data events, and CloudTrail Insights. For one hundred thousand events, management costs are approximately two dollars, data events ten cents, a...
What needs improvement with AWS CloudTrail?
I do not think there could be improvements in AWS CloudTrail because I am too small to suggest anything. It is already a well-established service from AWS, and I have only been using it for the las...
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
 

Also Known As

CloudTrail
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

HTC, British Gas, Solinor, 2C2P
Rockwell Automation
Find out what your peers are saying about AWS CloudTrail vs. CyberArk Privileged Access Manager and other solutions. Updated: March 2026.
884,933 professionals have used our research since 2012.