Understanding CloudTrail events
An event in CloudTrail is the record of an activity in an AWS account. This activity can be an action taken by an IAM identity, or service that is monitorable by CloudTrail. CloudTrail events provide a history of both API and non-API account activity made through the AWS Management Console, AWS SDKs, command line tools, and other AWS services.
CloudTrail log files aren't an ordered stack trace of the public API calls, so events don't appear in any specific order.
There are four types of CloudTrail events:
By default, trails and event data stores log management events, but not data events, network activity events, or Insights events.
All event types use a CloudTrail JSON log format. The log contains information about requests for
resources in your account, such as who made the request, the services used, the actions
performed, and parameters for the action. The event data is enclosed in a Records
array.
For information about CloudTrail event record fields for management, data, and network activity events, see CloudTrail record contents for management, data, and network activity events.
For information about CloudTrail event record fields for Insights events for trails, see CloudTrail record contents for Insights events for trails.
For information about CloudTrail event record fields for Insights events for event data stores, see CloudTrail record contents for Insights events for event data stores.
Management events
Management events provide information about management operations that are performed on resources in your AWS account. These are also known as control plane operations.
Example management events include:
-
Configuring security (for example, AWS Identity and Access Management
AttachRolePolicyAPI operations). -
Registering devices (for example, Amazon EC2
CreateDefaultVpcAPI operations). -
Configuring rules for routing data (for example, Amazon EC2
CreateSubnetAPI operations). -
Setting up logging (for example, AWS CloudTrail
CreateTrailAPI operations).
Management events can also include non-API events that occur in your account. For
example, when a user signs in to your account, CloudTrail logs the
ConsoleLogin event. For more information, see Non-API events captured by CloudTrail.
By default, CloudTrail trails and CloudTrail Lake event data stores log management events. For more information about logging management events, see Logging management events.
The following example shows a single log record of a management event. In this event, an IAM user
named Mary_Major ran the aws cloudtrail start-logging command to call the CloudTrail StartLogging action
to start the logging process on a trail named myTrail.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "EXAMPLE6E4XEGITWATV6R", "arn": "arn:aws:iam::123456789012:user/Mary_Major", "accountId": "123456789012", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "userName": "Mary_Major", "sessionContext": { "attributes": { "creationDate": "2023-07-19T21:11:57Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-07-19T21:33:41Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "StartLogging", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "userAgent": "aws-cli/2.13.5 Python/3.11.4 Linux/4.14.255-314-253.539.amzn2.x86_64 exec-env/CloudShell exe/x86_64.amzn.2 prompt/off command/cloudtrail.start-logging", "requestParameters": { "name": "myTrail" }, "responseElements": null, "requestID": "9d478fc1-4f10-490f-a26b-EXAMPLE0e932", "eventID": "eae87c48-d421-4626-94f5-EXAMPLEac994", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "123456789012", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }, "sessionCredentialFromConsole": "true" }
In this next example, an IAM user user named Paulo_Santos
ran the aws cloudtrail start-event-data-store-ingestion command to call the StartEventDataStoreIngestion action
to start ingestion on an event data store.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "EXAMPLEPHCNW5EQV7NA54", "arn": "arn:aws:iam::123456789012:user/Paulo_Santos", "accountId": "123456789012", "accessKeyId": "(AKIAIOSFODNN7EXAMPLE", "userName": "Paulo_Santos", "sessionContext": { "attributes": { "creationDate": "2023-07-21T21:55:30Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-07-21T21:57:28Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "StartEventDataStoreIngestion", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "userAgent": "aws-cli/2.13.1 Python/3.11.4 Linux/4.14.255-314-253.539.amzn2.x86_64 exec-env/CloudShell exe/x86_64.amzn.2 prompt/off command/cloudtrail.start-event-data-store-ingestion", "requestParameters": { "eventDataStore": "arn:aws:cloudtrail:us-east-1:123456789012:eventdatastore/2a8f2138-0caa-46c8-a194-EXAMPLE87d41" }, "responseElements": null, "requestID": "f62a3494-ba4e-49ee-8e27-EXAMPLE4253f", "eventID": "d97ca7e2-04fe-45b4-882d-EXAMPLEa9b2c", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "123456789012", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }, "sessionCredentialFromConsole": "true" }
Data events
Data events provide information about the resource operations performed on or in a resource. These are also known as data plane operations. Data events are often high-volume activities.
Example data events include:
-
Amazon S3 object-level API activity (for example,
GetObject,DeleteObject, andPutObjectAPI operations) on objects in S3 buckets. -
AWS Lambda function execution activity (the
InvokeAPI). -
CloudTrail
PutAuditEventsactivity on a CloudTrail Lake channel that is used to log events from outside AWS. -
Amazon SNS
PublishandPublishBatchAPI operations on topics.
For trails, you can use basic or advanced event selectors to log data events for Amazon S3 objects in general purpose buckets, Lambda functions, and DynamoDB tables (shown in the first three rows of the table). You can use only advanced event selectors to log the resource types shown in the remaining rows.
Data events supported by AWS CloudTrail
| AWS service | Description | Resource type (console) | resources.type value |
|---|---|---|---|
Amazon WorkSpaces Applications |
Agents accessing WorkSpaces Applications MCP tool events |
Agent Access MCP Tools |
|
AWS Agent Registry |
API activity on |
AWS Agent Registry |
|
Amazon AIDevOps |
AIDevOps API activity on agent spaces. |
Agent Space |
|
Amazon AIDevOps |
AIDevOps API activity on associations. |
AIDevOps association |
|
Amazon AIDevOps |
AIDevOps API activity on operator app teams. |
AIDevOps operator app team |
|
Amazon AIDevOps |
AIDevOps API activity on pipeline metadata. |
AIDevOps Pipelines Metadata |
|
Amazon AIDevOps |
AIDevOps API activity on services. |
AIDevOps service |
|
Amazon Q Developer |
Amazon Q Developer API activity on operational investigations. For more information, see Amazon Q Developer. |
AIOps Investigation Group |
|
Amazon OpenSearch Serverless |
API activity on |
AWS::AOSS::Collection |
|
AWS AppConfig |
AWS AppConfig API activity for configuration operations such as calls to StartConfigurationSession and GetLatestConfiguration. For more information, see AWS AppConfig. |
AWS AppConfig |
|
CloudWatch Application Signals |
API activity on |
AWS::ApplicationSignals::InstrumentationConfig |
|
AWS AppSync |
AWS AppSync API activity on AppSync GraphQL APIs. For more information, see AWS AppSync. |
AppSync GraphQL |
|
External anthropic workspace |
API activity on |
External anthropic workspace |
|
AWS B2B Data Interchange |
B2B Data Interchange API activity for Transformer operations such as calls to GetTransformerJob and StartTransformerJob. |
B2B Data Interchange |
|
AWS Backup access point |
API activity on |
AWS Backup access point |
|
AWS Backup |
AWS Backup Search Data API activity on search jobs. |
AWS Backup Search Data APIs |
|
Amazon Bedrock |
Bedrock API activity on advanced optimize prompt jobs. |
AdvancedOptimizePromptJob |
|
Amazon Bedrock |
Amazon Bedrock API activity on an agent alias. For more information, see Amazon Bedrock. |
Bedrock agent alias |
|
Amazon Bedrock |
Amazon Bedrock API activity on async invocations. |
Bedrock async invoke |
|
Amazon Bedrock |
Amazon Bedrock API activity on an automated reasoning policy. |
Bedrock Automated Reasoning Policy |
|
Amazon Bedrock |
Amazon Bedrock API activity on an automated reasoning policy version. |
Bedrock Automated Reasoning Policy Version |
|
Amazon Bedrock |
Amazon Bedrock blueprint API activity. |
Bedrock blueprint |
|
Amazon Bedrock |
Bedrock data automation invocation API activity. |
Bedrock Data Automation invocation |
|
Amazon Bedrock |
Amazon Bedrock data automation profile API activity. |
Bedrock Data Automation profile |
|
Amazon Bedrock |
Amazon Bedrock data automation project API activity. |
Bedrock Data Automation project |
|
Amazon Bedrock |
Amazon Bedrock API activity on a flow alias. |
Bedrock flow alias |
|
Amazon Bedrock |
Amazon Bedrock API activity on flow executions. |
Flow Execution |
|
Amazon Bedrock |
Amazon Bedrock API activity on guardrails. |
Bedrock guardrail |
|
Amazon Bedrock |
Amazon Bedrock API activity on inline agents. |
Bedrock Invoke Inline-Agent |
|
Amazon Bedrock |
Amazon Bedrock API activity on a knowledge base. For more information, see Amazon Bedrock. |
Bedrock knowledge base |
|
Amazon Bedrock |
Amazon Bedrock API activity on models. |
Bedrock model |
|
Amazon Bedrock |
Amazon Bedrock API activity on prompts. |
Bedrock prompt |
|
Amazon Bedrock |
Amazon Bedrock API activity on sessions. |
Bedrock session |
|
Amazon Bedrock |
Amazon Bedrock Tool API activity. |
Bedrock Tool |
|
Bedrock-AgentCore ABTest |
API activity on |
Bedrock-AgentCore ABTest |
|
Amazon Bedrock |
Amazon Bedrock APIKey CredentialProvider API activity. |
Bedrock-AgentCore APIKey CredentialProvider |
|
BedrockAgentCore batch evaluate |
API activity on |
BedrockAgentCore batch evaluate |
|
Amazon Bedrock |
Amazon Bedrock Browser API activity. |
Bedrock-AgentCore Browser |
|
Amazon Bedrock |
Amazon Bedrock Browser-Custom API activity. |
Bedrock-AgentCore Browser-Custom |
|
Bedrock-AgentCore Browser Profile |
API activity on |
Bedrock-AgentCore Browser Profile |
|
BedrockAgentCore CapacityProvider |
API activity on |
BedrockAgentCore CapacityProvider |
|
Amazon Bedrock |
Amazon Bedrock Code-Interpreter API activity. |
Bedrock-AgentCore Code-Interpreter |
|
Amazon Bedrock |
Amazon Bedrock Code-Interpreter-Custom API activity. |
Bedrock-AgentCore Code-Interpreter-Custom |
|
Amazon Bedrock AgentCore |
Bedrock AgentCore API activity on evaluators. |
Bedrock-AgentCore Evaluator |
|
Amazon Bedrock |
Amazon Bedrock Gateway API activity. |
Bedrock-AgentCore Gateway |
|
Amazon Bedrock |
Amazon Bedrock Memory API activity. |
Bedrock-AgentCore Memory |
|
Amazon Bedrock |
Amazon Bedrock Oauth2 CredentialProvider API activity. |
Bedrock-AgentCore Oauth2 CredentialProvider |
|
Bedrock-AgentCore payments |
API activity on |
Bedrock-AgentCore payments |
|
Bedrock-AgentCore policy |
API activity on |
Bedrock-AgentCore policy |
|
Bedrock-AgentCore policy engine |
API activity on |
Bedrock-AgentCore policy engine |
|
Bedrock-AgentCore Recommendation |
API activity on |
Bedrock-AgentCore Recommendation |
|
Bedrock-AgentCore Registry |
API activity on |
Bedrock-AgentCore Registry |
|
Amazon Bedrock |
Amazon Bedrock Runtime API activity. |
Bedrock-AgentCore Runtime |
|
Amazon Bedrock |
Amazon Bedrock Runtime-Endpoint API activity. |
Bedrock-AgentCore Runtime-Endpoint |
|
Amazon Bedrock |
Amazon Bedrock Token Vault API activity. |
Bedrock-AgentCore Token Vault |
|
Amazon Bedrock |
Amazon Bedrock Workload Identity API activity. |
Bedrock-AgentCore Workload Identity |
|
Amazon Bedrock |
Amazon Bedrock Workload Identity Directory API activity. |
Bedrock-AgentCore Workload Identity Directory |
|
Bedrock Mantle Project |
API activity on |
Bedrock Mantle Project |
|
Bedrock Web Search Tool |
API activity on |
Bedrock Web Search Tool |
|
Amazon Keyspaces (for Apache Cassandra) |
Amazon Keyspaces (for Apache Cassandra) API activity on Cassandra CDC streams. |
Cassandra CDC streams |
|
Amazon Keyspaces (for Apache Cassandra) |
Amazon Keyspaces API activity on a table. For more information, see Amazon Keyspaces (for Apache Cassandra). |
Cassandra table |
|
Certificate Manager |
API activity on |
AWS::CertificateManager::AcmeEndpoint |
|
Clinical Trials Tech codelist |
API activity on |
Clinical Trials Tech codelist |
|
Clinical Trials Tech dataset |
API activity on |
Clinical Trials Tech dataset |
|
Clinical Trials Tech execution |
API activity on |
Clinical Trials Tech execution |
|
Clinical Trials Tech instance |
API activity on |
Clinical Trials Tech instance |
|
Clinical Trials Tech mapping |
API activity on |
Clinical Trials Tech mapping |
|
Clinical Trials Tech schedule |
API activity on |
Clinical Trials Tech schedule |
|
Clinical Trials Tech study |
API activity on |
Clinical Trials Tech study |
|
Amazon CloudFront |
CloudFront API activity on a KeyValueStore. For more information, see Amazon CloudFront. |
CloudFront KeyValueStore |
|
Amazon Cost Optimization |
CloudOptimization API activity on profiles. |
AWS::CloudOptimization::Profile |
|
Amazon Cost Optimization |
CloudOptimization API activity on recommendations. |
AWS::CloudOptimization::Recommendation |
|
AWS CloudTrail |
CloudTrail PutAuditEvents activity on a CloudTrail Lake channel that is used to log events from outside AWS. For more information, see AWS CloudTrail. |
CloudTrail channel |
|
CloudWatch dataset |
API activity on |
CloudWatch dataset |
|
Observability ingestion endpoint |
API activity on |
Observability ingestion endpoint |
|
Amazon CloudWatch |
Amazon CloudWatch API activity on metrics. For more information, see Amazon CloudWatch. |
CloudWatch metric |
|
Amazon CodeGuru Profiler |
CodeGuru Profiler API activity on profiling groups. |
CodeGuru Profiler profiling group |
|
Amazon CodeWhisperer |
Amazon CodeWhisperer API activity on a customization. |
CodeWhisperer customization |
|
Amazon CodeWhisperer |
Amazon CodeWhisperer API activity on a profile. |
CodeWhisperer |
|
Amazon Cognito |
Amazon Cognito API activity on Amazon Cognito identity pools. For more information, see Amazon Cognito. |
Cognito Identity Pools |
|
AWS Data Exchange |
AWS Data Exchange API activity on assets. |
Data Exchange asset |
|
AWS Deadline Cloud |
Deadline Cloud API activity on fleets. For more information, see AWS Deadline Cloud. |
Deadline Cloud fleet |
|
AWS Deadline Cloud |
Deadline Cloud API activity on jobs. For more information, see AWS Deadline Cloud. |
Deadline Cloud job |
|
AWS Deadline Cloud |
Deadline Cloud API activity on queues. For more information, see AWS Deadline Cloud. |
Deadline Cloud queue |
|
AWS Deadline Cloud |
Deadline Cloud API activity on workers. For more information, see AWS Deadline Cloud. |
Deadline Cloud worker |
|
Diode Alerting linked alert |
API activity on |
Diode Alerting linked alert |
|
Amazon Aurora DSQL |
Amazon Aurora DSQL API activity on cluster resources. |
Amazon Aurora DSQL |
|
Amazon DynamoDB |
Amazon DynamoDB API activity on streams. For more information, see Amazon DynamoDB. |
DynamoDB Streams |
|
Amazon DynamoDB |
Amazon DynamoDB item-level API activity on tables (for example, PutItem, DeleteItem, and UpdateItem API operations). For tables with streams enabled, the resources field in the data event contains both AWS::DynamoDB::Stream and AWS::DynamoDB::Table. If you specify AWS::DynamoDB::Table for the resources.type, it will log both DynamoDB table and DynamoDB streams events by default. To exclude streams events, add a filter on the eventName field. For more information, see Amazon DynamoDB. |
DynamoDB |
|
Amazon Elastic Compute Cloud |
Amazon EC2 instance connect endpoint API activity. |
EC2 instance connect endpoint |
|
Amazon Elastic Block Store |
Amazon Elastic Block Store (EBS) direct APIs, such as PutSnapshotBlock, GetSnapshotBlock, and ListChangedBlocks on Amazon EBS snapshots. For more information, see Amazon Elastic Block Store. |
EBS direct APIs |
|
Amazon Elastic Container Service |
Amazon Elastic Container Service API activity on a container instance. |
ECS container instance |
|
Amazon Elastic Kubernetes Service |
Amazon Elastic Kubernetes Service API activity on dashboards. |
EKS dashboard |
|
Amazon EMR |
Amazon EMR API activity on a write-ahead log workspace. For more information, see Amazon EMR. |
EMR write-ahead log workspace |
|
EventBridge endpoint |
API activity on |
EventBridge endpoint |
|
EventBridge event bus |
API activity on |
EventBridge event bus |
|
EventBridge partner event source |
API activity on |
EventBridge partner event source |
|
EventBridge rule |
API activity on |
EventBridge rule |
|
Amazon FinSpace |
Amazon FinSpace API activity on environments. For more information, see Amazon FinSpace. |
FinSpace |
|
Amazon FSx |
Amazon FSx API activity on volumes. |
FSx Volume |
|
Amazon GameLift Streams |
Amazon GameLift Streams streaming API activity on applications. For more information, see Amazon GameLift Streams. |
GameLift Streams application |
|
Amazon GameLift Streams |
Amazon GameLift Streams streaming API activity on stream groups. For more information, see Amazon GameLift Streams. |
GameLift Streams stream group |
|
Amazon Location Maps |
Amazon Location Maps API activity. |
Geo Maps |
|
Amazon Location Places |
Amazon Location Places API activity. |
Geo Places |
|
Amazon Location Routes |
Amazon Location Routes API activity. |
Geo Routes |
|
AWS Glue |
AWS Glue API activity on tables that were created by Lake Formation. |
Lake Formation |
|
AWS IoT Greengrass Version 2 |
Greengrass API activity from a Greengrass core device on a component version. Greengrass doesn't log access denied events. For more information, see AWS IoT Greengrass Version 2. |
IoT Greengrass component version |
|
AWS IoT Greengrass Version 2 |
Greengrass API activity from a Greengrass core device on a deployment. Greengrass doesn't log access denied events. For more information, see AWS IoT Greengrass Version 2. |
IoT Greengrass deployment |
|
Amazon GuardDuty |
Amazon GuardDuty API activity for a detector. For more information, see Amazon GuardDuty. |
GuardDuty detector |
|
Amazon GuardDuty |
GuardDuty API activity on malware scans. |
GuardDuty malware scan |
|
Health agent domain |
API activity on |
Health agent domain |
|
Amazon Connect Health |
API activity on |
AWS::HealthAgent::Integration |
|
Amazon Connect Health |
API activity on |
health-agent.amazonaws.com |
|
Amazon Connect Health |
API activity on |
AWS::HealthAgent::Session |
|
Health agent subscription |
API activity on |
Health agent subscription |
|
Health Lake data transformation profile |
API activity on |
Health Lake data transformation profile |
|
AWS IoT |
AWS IoT API activity on certificates. For more information, see AWS IoT. |
IoT certificate |
|
AWS IoT |
AWS IoT API activity on things. For more information, see AWS IoT. |
IoT thing |
|
AWS IoT tunnel |
API activity on |
AWS IoT tunnel |
|
AWS IoT SiteWise |
IoT SiteWise API activity on assets. For more information, see AWS IoT SiteWise. |
IoT SiteWise asset |
|
IoT SiteWise dataset |
API activity on |
IoT SiteWise dataset |
|
IoT SiteWise pipeline |
API activity on |
IoT SiteWise pipeline |
|
AWS IoT SiteWise |
IoT SiteWise API activity on time series. For more information, see AWS IoT SiteWise. |
IoT SiteWise time series |
|
IoT SiteWise workspace |
API activity on |
IoT SiteWise workspace |
|
AWS IoT TwinMaker |
IoT TwinMaker API activity on an entity. For more information, see AWS IoT TwinMaker. |
IoT TwinMaker entity |
|
AWS IoT TwinMaker |
IoT TwinMaker API activity on a workspace. For more information, see AWS IoT TwinMaker. |
IoT TwinMaker workspace |
|
Amazon Kendra Intelligent Ranking |
Amazon Kendra Intelligent Ranking API activity on rescore execution plans. For more information, see Amazon Kendra Intelligent Ranking. |
Kendra Ranking |
|
Amazon Kinesis Data Streams |
Kinesis Data Streams API activity on streams. For more information, see Amazon Kinesis Data Streams. |
Kinesis stream |
|
Amazon Kinesis Data Streams |
Kinesis Data Streams API activity on stream consumers. For more information, see Amazon Kinesis Data Streams. |
Kinesis stream consumer |
|
Amazon Data Firehose |
Amazon Data Firehose delivery stream API activity. |
Amazon Data Firehose |
|
Amazon Kinesis Video Streams |
Kinesis Video Streams video signaling channel API activity. |
Kinesis video signaling channel |
|
Amazon Kinesis Video Streams |
Kinesis Video Streams API activity on video streams, such as calls to GetMedia and PutMedia. |
Kinesis video stream |
|
AWS Lambda |
AWS Lambda function execution activity (the Invoke API). |
Lambda |
|
Lambda microvm image |
API activity on |
Lambda microvm image |
|
Lex Bot |
API activity on |
Lex Bot |
|
AWS Lex Bot Alias |
API activity on |
AWS Lex Bot Alias |
|
CloudWatch Logs log group authorization |
API activity on |
CloudWatch Logs log group authorization |
|
Logs ScheduledQuery |
API activity on |
Logs ScheduledQuery |
|
Amazon Machine Learning |
Machine Learning API activity on ML models. |
Machine Learning MlModel |
|
Amazon Managed Blockchain |
Amazon Managed Blockchain API activity on a network. |
Managed Blockchain network |
|
Amazon Managed Blockchain |
Amazon Managed Blockchain JSON-RPC calls on Ethereum nodes, such as eth_getBalance or eth_getBlockByNumber. For more information, see Amazon Managed Blockchain. |
Managed Blockchain |
|
Amazon Managed Blockchain Query |
Amazon Managed Blockchain Query API activity. |
Managed Blockchain Query |
|
AWS HealthImaging |
AWS HealthImaging API activity on data stores. |
MedicalImaging data store |
|
AWS HealthImaging |
AWS HealthImaging image set API activity. |
MedicalImaging image set |
|
Amazon Managed Workflows for Apache Airflow |
Amazon MWAA API activity on environments. |
Managed Apache Airflow |
|
Amazon Neptune Graph |
Data API activities, for example queries, algorithms, or vector search, on a Neptune Graph. |
Neptune Graph |
|
Amazon CloudWatch Network Flow Monitor |
Amazon CloudWatch Network Flow Monitor API activity on monitors. |
Network Flow Monitor monitor |
|
Amazon CloudWatch Network Flow Monitor |
Amazon CloudWatch Network Flow Monitor API activity on scopes. |
Network Flow Monitor scope |
|
Amazon NovaAct |
Amazon NovaAct API activity on workflow definitions. |
Workflow definition |
|
Amazon NovaAct |
Amanzon NovaAct API activity on workflow runs. |
Workflow run |
|
Amazon One Enterprise |
Amazon One Enterprise API activity on a UKey. |
Amazon One UKey |
|
Amazon One Enterprise |
Amazon One Enterprise API activity on users. |
Amazon One User |
|
AWS Payment Cryptography |
AWS Payment Cryptography API activity on aliases. |
Payment Cryptography alias |
|
AWS Payment Cryptography |
AWS Payment Cryptography API activity on keys. |
Payment Cryptography key |
|
AWS Private CA |
AWS Private CA Connector for Active Directory API activity. |
Private CA Connector for Active Directory |
|
AWS Private CA |
AWS Private CA Connector for SCEP API activity. |
Private CA Connector for SCEP |
|
Amazon Pinpoint |
Amazon Pinpoint API activity on mobile targeting applications. |
Mobile Targeting Application |
|
Amazon Q Apps |
Data API activity on Amazon Q Apps. For more information, see Amazon Q Apps. |
Amazon Q Apps |
|
Amazon Q Apps |
Data API activity on Amazon Q App sessions. |
Amazon Q App Session |
|
Amazon Q Business |
Amazon Q Business API activity on an application. For more information, see Amazon Q Business. |
Amazon Q Business application |
|
Amazon Q Business |
Amazon Q Business API activity on a data source. For more information, see Amazon Q Business. |
Amazon Q Business data source |
|
Amazon Q Business |
Amazon Q Business API activity on an index. For more information, see Amazon Q Business. |
Amazon Q Business index |
|
Amazon Q Business |
Amazon Q Business integration API activity. |
Amazon Q Business integration |
|
Amazon Q Business |
Amazon Q Business API activity on a web experience. For more information, see Amazon Q Business. |
Amazon Q Business web experience |
|
Amazon Q Developer |
Amazon Q Developer API activity on an integration. |
Q Developer integration |
|
Amazon Quick |
Amazon Quick API activity on an action connector. |
AWS QuickSuite Actions |
|
Amazon QuickSight App |
API activity on |
Amazon QuickSight App |
|
QuickSight automation |
API activity on |
QuickSight automation |
|
QuickSight automation job |
API activity on |
QuickSight automation job |
|
AWS QuickSight Extension |
API activity on |
AWS QuickSight Extension |
|
AWS QuickSight Extension Access |
API activity on |
AWS QuickSight Extension Access |
|
Amazon Quick |
Amazon Quick Flow API activity. |
AWS QuickSight flow |
|
Amazon Quick |
Amazon Quick FlowSession API activity. |
AWS QuickSight flow session |
|
Amazon QuickSight Page |
API activity on |
Amazon QuickSight Page |
|
QuickSight Task |
API activity on |
QuickSight Task |
|
Amazon RDS |
Amazon RDS API activity on a DB Cluster. For more information, see Amazon RDS. |
RDS Data API - DB Cluster |
|
Amazon Redshift |
Redshift API activity on clusters. |
Redshift Cluster |
|
AWS Resource Explorer managed-view |
API activity on |
AWS Resource Explorer managed-view |
|
AWS Resource Explorer view |
API activity on |
AWS Resource Explorer view |
|
Amazon CloudWatch RUM |
Amazon CloudWatch RUM API activity on app monitors. |
RUM app monitor |
|
Amazon S3 |
Amazon S3 API activity on access points. For more information, see Amazon S3. |
S3 Access Point |
|
Amazon S3 |
Amazon S3 object-level API activity (for example, GetObject, DeleteObject, and PutObject API operations) on objects in general purpose buckets. For more information, see Amazon S3. |
S3 |
|
S3 Express Access Point |
API activity on |
S3 Express Access Point |
|
Amazon S3 |
Amazon S3 object-level API activity (for example, GetObject, DeleteObject, and PutObject API operations) on objects in directory buckets. For more information, see Amazon S3. |
S3 Express |
|
Amazon S3 |
Amazon S3 Object Lambda access points API activity, such as calls to CompleteMultipartUpload and GetObject. For more information, see Amazon S3. |
S3 Object Lambda |
|
Amazon S3 on Outposts |
Amazon S3 on Outposts object-level API activity. For more information, see Amazon S3 on Outposts. |
S3 Outposts |
|
Amazon S3 Tables |
Amazon S3 API activity on tables. For more information, see Amazon S3 Tables. |
S3 table |
|
Amazon S3 Tables |
Amazon S3 API activity on table buckets. For more information, see Amazon S3 Tables. |
S3 table bucket |
|
Amazon S3 Vectors |
Amazon S3 API activity on vector indexes. For more information, see Amazon S3 Vectors. |
S3 vector index |
|
Amazon S3 Vectors |
Amazon S3 API activity on vector buckets. For more information, see Amazon S3 Vectors. |
S3 vector bucket |
|
Amazon SageMaker AI |
Amazon SageMaker AI InvokeEndpointWithResponseStream activity on endpoints. For more information, see Amazon SageMaker AI. |
SageMaker endpoint |
|
Amazon SageMaker AI |
Amazon SageMaker AI API activity on experiment trial components. For more information, see Amazon SageMaker AI. |
SageMaker metrics experiment trial component |
|
Amazon SageMaker AI |
Amazon SageMaker AI API activity on feature stores. |
SageMaker Feature Store |
|
SageMaker hub |
API activity on |
SageMaker hub |
|
SageMaker jobs |
API activity on |
SageMaker jobs |
|
AWS SageMaker MlflowApp |
API activity on |
AWS SageMaker MlflowApp |
|
Amazon SageMaker AI |
Amazon SageMaker AI MLflow API activity. |
SageMaker MLflow |
|
SageMaker training session |
API activity on |
SageMaker training session |
|
AWS Supply Chain |
API activity on |
AWS::SCN::BusinessRule |
|
AWS Supply Chain |
API activity on |
AWS::SCN::DataLakeException |
|
AWS Supply Chain |
API activity on |
AWS::SCN::ExceptionInvestigation |
|
AWS Supply Chain |
API activity on |
AWS::SCN::ExceptionRule |
|
AWS Supply Chain |
Supply Chain API activity on an instance. |
Amazon Connect Decisions |
|
AWS Supply Chain |
API activity on |
AWS::SCN::Metric |
|
AWS Supply Chain |
API activity on |
AWS::SCN::MetricEvaluation |
|
AWS Supply Chain |
API activity on |
AWS::SCN::Outcome |
|
AWS Supply Chain |
API activity on |
AWS::SCN::OutcomeTemplate |
|
Amazon SimpleDB |
Amazon SimpleDB API activity on domains. |
SimpleDB domain |
|
AWS Cloud Map |
AWS Cloud Map API activity on a namespace. For more information, see AWS Cloud Map. |
AWS Cloud Map namespace |
|
AWS Cloud Map |
AWS Cloud Map API activity on a service. For more information, see AWS Cloud Map. |
AWS Cloud Map service |
|
Amazon Simple Email Service |
Amazon Simple Email Service (Amazon SES) API activity on configuration sets. |
SES configuration set |
|
Amazon Simple Email Service |
Amazon Simple Email Service (Amazon SES) API activity on email identities. |
SES identity |
|
Amazon Simple Email Service |
Amazon Simple Email Service (Amazon SES) API activity on templates. |
SES template |
|
AWS Signer |
Signer API activity on signing jobs. |
Signer signing job |
|
AWS Signer |
Signer API activity on signing profiles. |
Signer signing profile |
|
AWS IoT SiteWise Assistant |
Sitewise Assistant API activity on conversations. |
Sitewise Assistant conversation |
|
Carrier Lookup |
API activity on |
Carrier Lookup |
|
Configuration Set |
API activity on |
Configuration Set |
|
AWS End User Messaging SMS |
AWS End User Messaging SMS API activity on messages. For more information, see AWS End User Messaging SMS. |
SMS Voice message |
|
Notify Configuration |
API activity on |
Notify Configuration |
|
AWS End User Messaging SMS |
AWS End User Messaging SMS API activity on origination identities. For more information, see AWS End User Messaging SMS. |
SMS Voice origination identity |
|
Amazon SNS |
Amazon SNS Publish API operations on platform endpoints. For more information, see Amazon SNS. |
SNS platform endpoint |
|
Amazon SNS |
Amazon SNS Publish and PublishBatch API operations on topics. For more information, see Amazon SNS. |
SNS topic |
|
AWS End User Messaging Social |
AWS End User Messaging Social API activity on phone number IDs. For more information, see AWS End User Messaging Social. |
Social-Messaging Phone Number ID |
|
AWS End User Messaging Social |
AWS End User Messaging Social API activity on Waba IDs. |
Social-Messaging Waba ID |
|
Amazon SQS |
Amazon SQS API activity on messages. For more information, see Amazon SQS. |
SQS |
|
AWS Systems Manager |
Systems Manager API activity on impact assessments. |
SSM Impact Assessment |
|
AWS Systems Manager |
Systems Manager API activity on managed nodes. For more information, see AWS Systems Manager. |
Systems Manager managed node |
|
AWS Systems Manager |
Systems Manager API activity on control channels. For more information, see AWS Systems Manager. |
Systems Manager |
|
AWS Step Functions |
Step Functions API activity on activities. For more information, see AWS Step Functions. |
Step Functions activity |
|
AWS Step Functions |
Step Functions API activity on state machines. For more information, see AWS Step Functions. |
Step Functions state machine |
|
Amazon Support |
SupportAccess API activity on tenants. |
SupportAccess tenant |
|
Amazon Support |
SupportAccess API activity on trusting accounts. |
SupportAccess trusting account |
|
Amazon Support |
SupportAccess API activity on trusting roles. |
SupportAccess trusting role |
|
Amazon SWF |
Amazon SWF API activity on domains. For more information, see Amazon SWF. |
SWF domain |
|
Amazon WorkSpaces Thin Client |
WorkSpaces Thin Client API activity on a Device. |
Thin Client Device |
|
Amazon WorkSpaces Thin Client |
WorkSpaces Thin Client API activity on an Environment. |
Thin Client Environment |
|
Amazon Timestream |
Amazon Timestream Query API activity on databases. For more information, see Amazon Timestream. |
Timestream database |
|
Amazon Timestream |
Amazon Timestream API activity on regional endpoints. |
Timestream regional endpoint |
|
Amazon Timestream |
Amazon Timestream Query API activity on tables. For more information, see Amazon Timestream. |
Timestream table |
|
Amazon Transform |
Transform API activity on agent instances. |
Transform agent instance |
|
Amazon Q Transform AKA AWS Transform |
API activity on |
transform |
|
Amazon Transform Custom |
Transform Custom API activity on campaigns. |
Transform-Custom campaign |
|
Amazon Transform Custom |
Transform Custom API activity on conversations. |
Transform-Custom conversation |
|
Amazon Transform Custom |
Transform Custom API activity on knowledge items. |
Transform-Custom knowledge item |
|
Amazon Transform Custom |
Transform Custom API activity on packages. |
Transform-Custom package |
|
UXC account customization |
API activity on |
UXC account customization |
|
Amazon Verified Permissions |
Amazon Verified Permissions API activity on a policy store. |
Amazon Verified Permissions |
|
Well-Architected agent recommendation |
API activity on |
Well-Architected agent recommendation |
|
AWS X-Ray |
X-Ray API activity on traces. For more information, see AWS X-Ray. |
X-Ray trace |
|
Additional charges apply for logging data events. For CloudTrail pricing, see AWS CloudTrail Pricing.
The following example shows a single log record of a data event for the Amazon SNS
Publish action.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "EX_PRINCIPAL_ID", "arn": "arn:aws:iam::123456789012:user/Bob", "accountId": "123456789012", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn": "arn:aws:iam::123456789012:role/Admin", "accountId": "123456789012", "userName": "ExampleUser" }, "attributes": { "creationDate": "2023-08-21T16:44:05Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-08-21T16:48:37Z", "eventSource": "sns.amazonaws.com", "eventName": "Publish", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "userAgent": "aws-cli/1.29.16 md/Botocore#1.31.16 ua/2.0 os/linux#5.4.250-173.369.amzn2int.x86_64 md/arch#x86_64 lang/python#3.8.17 md/pyimpl#CPython cfg/retry-mode#legacy botocore/1.31.16", "requestParameters": { "topicArn": "arn:aws:sns:us-east-1:123456789012:ExampleSNSTopic", "message": "HIDDEN_DUE_TO_SECURITY_REASONS", "subject": "HIDDEN_DUE_TO_SECURITY_REASONS", "messageStructure": "json", "messageAttributes": "HIDDEN_DUE_TO_SECURITY_REASONS" }, "responseElements": { "messageId": "0787cd1e-d92b-521c-a8b4-90434e8ef840" }, "requestID": "0a8ab208-11bf-5e01-bd2d-ef55861b545d", "eventID": "bb3496d4-5252-4660-9c28-3c6aebdb21c0", "readOnly": false, "resources": [{ "accountId": "123456789012", "type": "AWS::SNS::Topic", "ARN": "arn:aws:sns:us-east-1:123456789012:ExampleSNSTopic" }], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "123456789012", "eventCategory": "Data", "tlsDetails": { "tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "sns.us-east-1.amazonaws.com" } }
The next example shows a single log record of a data event for the Amazon Cognito
GetCredentialsForIdentity action.
{ "eventVersion": "1.08", "userIdentity": { "type": "Unknown" }, "eventTime": "2023-01-19T16:55:08Z", "eventSource": "cognito-identity.amazonaws.com", "eventName": "GetCredentialsForIdentity", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.4", "userAgent": "aws-cli/2.7.25 Python/3.9.11 Darwin/21.6.0 exe/x86_64 prompt/off command/cognito-identity.get-credentials-for-identity", "requestParameters": { "logins": { "cognito-idp.us-east-1.amazonaws.com/us-east-1_aaaaaaaaa": "HIDDEN_DUE_TO_SECURITY_REASONS" }, "identityId": "us-east-1:1cf667a2-49a6-454b-9e45-23199EXAMPLE" }, "responseElements": { "credentials": { "accessKeyId": "ASIAIOSFODNN7EXAMPLE", "sessionToken": "aAaAaAaAaAaAab1111111111EXAMPLE", "expiration": "Jan 19, 2023 5:55:08 PM" }, "identityId": "us-east-1:1cf667a2-49a6-454b-9e45-23199EXAMPLE" }, "requestID": "659dfc23-7c4e-4e7c-858a-1abce884d645", "eventID": "6ad1c766-5a41-4b28-b5ca-e223ccb00f0d", "readOnly": false, "resources": [{ "accountId": "111122223333", "type": "AWS::Cognito::IdentityPool", "ARN": "arn:aws:cognito-identity:us-east-1:111122223333:identitypool/us-east-1:2dg778b3-50b7-565c-0f56-34200EXAMPLE" }], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111122223333", "eventCategory": "Data" }
Network activity events
CloudTrail network activity events enable VPC endpoint owners to record AWS API calls made using their VPC endpoints from a private VPC to the AWS service. Network activity events provide visibility into the resource operations performed within a VPC.
You can log network activity events for the following services:
Amazon Aurora DSQL
Amazon Bedrock
Amazon Connect Voice ID
Amazon EventBridge Scheduler
Amazon Fraud Detector
Amazon HealthLake
Amazon Lookout for Equipment
Amazon Lookout for Vision
Amazon Q Subscriptions
Amazon QuickSight
Amazon Rekognition
Amazon SageMaker
Amazon Textract
Amazon Transcribe Streaming Service
Amazon Verified Permissions
Amazon WorkMail
Anthropic Claude Developer Platform on AWS
Athena
AWS Agent Registry
AWS AppConfig
aws assurance
AWS B2B Data Interchange
AWS BCM Pricing Calculator
AWS Billing
AWS Cloud Map
AWS Glue
AWS IdentityStore Service
AWS Invoicing
AWS IoT FleetWise
AWS IoT Secured Tunneling
AWS IoT SiteWise
AWS License Manager
AWS Partner Central Revenue Measurement
AWS Secrets Manager
AWS SSO
AWS Step Functions
AWS Transfer Family
AWS Transform
AWSBillingAndCostManagementDataExports
AWSLakeFormation
Backup Gateway
Bedrock Agent Core
Cloud Control API
CloudFormation
CloudHSM
CloudTrail
CodeDeploy
Comprehend medical
Compute Optimizer Automation
DynamoDB
EC2 Auto Scaling
Elastic Compute Cloud (EC2)
Elastic File System (EFS)
IoT
Key Management Service (KMS)
Lambda
Relational Database Service (RDS) Core Control Plane
Route 53 Public DNS
S3 Vectors
Security Token Service (STS)
Sign-In Portal
Simple Email Service (SES)
Simple Notification Service (SNS)
Simple Queue Service (SQS)
Simple Storage Service (S3)
Simple Workflow Service (SWF)
SSM Contacts
Storage Gateway
Network activity events are not logged by default when you create a trail or event data store. To record CloudTrail network activity events, you must explicitly set the event source for which you want to collect activity. For more information, see Logging network activity events.
Additional charges apply for logging network activity events. For CloudTrail pricing, see AWS CloudTrail Pricing.
The following example shows a successful AWS KMS ListKeys event that traversed a VPC endpoint. The vpcEndpointId field shows the ID of the VPC endpoint. The
vpcEndpointAccountId field shows the account ID of the VPC endpoint owner. In this example, the request was made by the VPC endpoint owner.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "ASIAIOSFODNN7EXAMPLE:role-name", "arn": "arn:aws:sts::123456789012:assumed-role/Admin/role-name", "accountId": "123456789012", "accessKeyId": "ASIAIOSFODNN7EXAMPLE", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "ASIAIOSFODNN7EXAMPLE", "arn": "arn:aws:iam::123456789012:role/Admin", "accountId": "123456789012", "userName": "Admin" }, "attributes": { "creationDate": "2024-06-04T23:10:46Z", "mfaAuthenticated": "false" } } }, "eventTime": "2024-06-04T23:12:50Z", "eventSource": "kms.amazonaws.com", "eventName": "ListKeys", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "requestID": "16bcc089-ac49-43f1-9177-EXAMPLE23731", "eventID": "228ca3c8-5f95-4a8a-9732-EXAMPLE60ed9", "eventType": "AwsVpceEvent", "recipientAccountId": "123456789012", "sharedEventID": "a1f3720c-ef19-47e9-a5d5-EXAMPLE8099f", "vpcEndpointId": "vpce-EXAMPLE08c1b6b9b7", "vpcEndpointAccountId": "123456789012", "eventCategory": "NetworkActivity" }
The next example shows an unsuccessful AWS KMS ListKeys event with a VPC endpoint policy violation. Because a VPC policy violation occurred, both the
errorCode and errorMessage fields are present. The account ID in the recipientAccountId and vpcEndpointAccountId
fields is the same, which indicates the event was sent to the VPC endpoint owner. The accountId
in the userIdentity element is not the vpcEndpointAccountId, which indicates that the user making the request is not the VPC endpoint owner.
{ "eventVersion": "1.09", "userIdentity": { "type": "AWSAccount", "principalId": "AKIAIOSFODNN7EXAMPLE", "accountId": "777788889999" }, "eventTime": "2024-07-15T23:57:12Z", "eventSource": "kms.amazonaws.com", "eventName": "ListKeys", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "errorCode": "VpceAccessDenied", "errorMessage": "The request was denied due to a VPC endpoint policy", "requestID": "899003b8-abc4-42bb-ad95-EXAMPLE0c374", "eventID": "7c6e3d04-0c3b-42f2-8589-EXAMPLE826c0", "eventType": "AwsVpceEvent", "recipientAccountId": "123456789012", "sharedEventID": "702f74c4-f692-4bfd-8491-EXAMPLEb1ac4", "vpcEndpointId": "vpce-EXAMPLE08c1b6b9b7", "vpcEndpointAccountId": "123456789012", "eventCategory": "NetworkActivity" }
Insights events
CloudTrail Insights events capture unusual API call rate or error rate activity in your AWS account by analyzing CloudTrail management activity. Insights events provide relevant information, such as the associated API, error code, incident time, and statistics, that help you understand and act on unusual activity. Unlike other types of events captured in a CloudTrail trail or event data store, Insights events are logged only when CloudTrail detects changes in your account's API usage or error rate logging that differ significantly from the account's typical usage patterns. For more information, see Working with CloudTrail Insights.
Examples of activity that might generate Insights events include:
-
Your account typically logs no more than 20 Amazon S3
deleteBucketAPI calls per minute, but your account starts to log an average of 100deleteBucketAPI calls per minute. An Insights event is logged at the start of the unusual activity, and another Insights event is logged to mark the end of the unusual activity. -
Your account typically logs 20 calls per minute to the Amazon EC2
AuthorizeSecurityGroupIngressAPI, but your account starts to log zero calls toAuthorizeSecurityGroupIngress. An Insights event is logged at the start of the unusual activity, and ten minutes later, when the unusual activity ends, another Insights event is logged to mark the end of the unusual activity. -
Your account typically logs less than one
AccessDeniedExceptionerror in a seven-day period on the AWS Identity and Access Management API,DeleteInstanceProfile. Your account starts to log an average of 12AccessDeniedExceptionerrors per minute on theDeleteInstanceProfileAPI call. An Insights event is logged at the start of the unusual error rate activity, and another Insights event is logged to mark the end of the unusual activity.
These examples are provided for illustration purposes only. Your results may vary depending on your use case.
To log CloudTrail Insights events, you must explicitly enable Insights events on a new or existing trail or event data store. For more information about creating a trail, see Creating a trail with the CloudTrail console. For more information about creating an event data store, see Create an event data store for Insights events with the console.
Additional charges apply for Insights events. You will be charged separately if you enable Insights for both trails and event data stores. For more information, see AWS CloudTrail Pricing
There are two events logged to show unusual activity in CloudTrail Insights: a start event and
an end event. The following example shows a single log record of a starting Insights event that
occurred when the Application Auto Scaling API CompleteLifecycleAction was called an unusual number
of times. For Insights events, the value of eventCategory is Insight.
An insightDetails block identifies the event state, source, name, Insights type,
and context, including statistics and attributions. For more information about the
insightDetails block, see CloudTrail record contents for Insights events for trails.
{ "eventVersion": "1.08", "eventTime": "2023-07-10T01:42:00Z", "awsRegion": "us-east-1", "eventID": "55ed45c5-0b0c-4228-9fe5-EXAMPLEc3f4d", "eventType": "AwsCloudTrailInsight", "recipientAccountId": "123456789012", "sharedEventID": "979c82fe-14d4-4e4c-aa01-EXAMPLE3acee", "insightDetails": { "state": "Start", "eventSource": "autoscaling.amazonaws.com", "eventName": "CompleteLifecycleAction", "insightType": "ApiCallRateInsight", "insightContext": { "statistics": { "baseline": { "average": 9.82222E-5 }, "insight": { "average": 5.0 }, "insightDuration": 1, "baselineDuration": 10181 }, "attributions": [{ "attribute": "userIdentityArn", "insight": [{ "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole1", "average": 5.0 }, { "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole2", "average": 5.0 }, { "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole3", "average": 5.0 }], "baseline": [{ "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole1", "average": 9.82222E-5 }] }, { "attribute": "userAgent", "insight": [{ "value": "codedeploy.amazonaws.com", "average": 5.0 }], "baseline": [{ "value": "codedeploy.amazonaws.com", "average": 9.82222E-5 }] }, { "attribute": "errorCode", "insight": [{ "value": "null", "average": 5.0 }], "baseline": [{ "value": "null", "average": 9.82222E-5 }] }] } }, "eventCategory": "Insight" }