Monitor activity in your AWS account. You can use logging features in AWS to determine the actions users have taken in your account and the resources that were used. The log files show the time and date of actions, the source IP for an action, which actions failed due to inadequate permissions, and more. …
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html

