When creating Cloudtrail in the AWS Management Console the trail is configured by default to be multi-region, this isn’t the case with the Terraform resource. Cloudtrail should cover the full AWS account to ensure you can track changes in regions you are not actively operting in.
Activity could be happening in your account in a different region
Enable Cloudtrail in all regions
The following example will fail the aws-cloudtrail-enable-all-regions check.
The following example will pass the aws-cloudtrail-enable-all-regions check.