diff --git a/modules/log_ingestion.s3.cft.yaml b/modules/log_ingestion.s3.cft.yaml index 028c36e..7d50530 100644 --- a/modules/log_ingestion.s3.cft.yaml +++ b/modules/log_ingestion.s3.cft.yaml @@ -358,8 +358,7 @@ Outputs: Value: !Sub | IMPORTANT: MANUAL ACTION REQUIRED - Please add the following statement to your KMS key policy to allow Sysdig to decrypt logs. - This is necessary when KMS encryption is enabled for your S3 bucket and the KMS key is in a different account. + Add the following statement to the KMS key policy used by CloudTrail Without this policy addition, Sysdig may not be able to read your encrypted logs. {