OpenSearch Service Serverless

eventNameDescriptionSampleRule
anyCatch-all entry for OpenSearch Service Serverless rules that match the service but not a specific eventName.NN
BatchGetCollectionReturns attributes for one or more collections, including the collection endpoint, the OpenSearch Dashboards endpoint, and FIPS-compliant endpoints. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
BatchGetCollectionGroupReturns attributes for one or more collection groups, including capacity limits and the number of collections in each group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
BatchGetEffectiveLifecyclePolicyReturns a list of successful and failed retrievals for the OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
BatchGetLifecyclePolicyReturns one or more configured OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
BatchGetVpcEndpointReturns attributes for one or more VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateAccessPolicyCreates a data access policy for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateCollectionCreates a new OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateCollectionGroupCreates a collection group within OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateIndexCreates an index within an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLifecyclePolicyCreates a lifecyle policy to be applied to OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateSecurityConfigSpecifies a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateSecurityPolicyCreates a security policy to be used by one or more OpenSearch Serverless collections. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateVpcEndpointCreates an OpenSearch Serverless-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteAccessPolicyDeletes an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteCollectionDeletes an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteCollectionGroupDeletes a collection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteIndexDeletes an index from an OpenSearch Serverless collection. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DeleteLifecyclePolicyDeletes an OpenSearch Serverless lifecycle policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSecurityConfigDeletes a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSecurityPolicyDeletes an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteVpcEndpointDeletes an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetAccessPolicyReturns an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetAccountSettingsReturns account-level settings related to OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetIndexRetrieves information about an index in an OpenSearch Serverless collection, including its schema definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetPoliciesStatsReturns statistical information about your OpenSearch Serverless access policies, security configurations, and security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetSecurityConfigReturns information about an OpenSearch Serverless security configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSecurityPolicyReturns information about a configured OpenSearch Serverless security policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListAccessPoliciesReturns information about a list of OpenSearch Serverless access policies.YN
ListCollectionGroupsReturns a list of collection groups. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCollectionsLists all OpenSearch Serverless collections.YN
ListLifecyclePoliciesReturns a list of OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListSecurityConfigsReturns information about configured OpenSearch Serverless security configurations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListSecurityPoliciesReturns information about configured OpenSearch Serverless security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceReturns the tags for an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListVpcEndpointsReturns the OpenSearch Serverless-managed interface VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
TagResourceAssociates tags with an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves a tag or set of tags from an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAccessPolicyUpdates an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
UpdateAccountSettingsUpdate the OpenSearch Serverless settings for the current Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateCollectionUpdates an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateCollectionGroupUpdates the description and capacity limits of a collection group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
UpdateIndexUpdates an existing index in an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLifecyclePolicyUpdates an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateSecurityConfigUpdates a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateSecurityPolicyUpdates an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateVpcEndpointUpdates an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: OpenSearch Service Serverless (catch-all)

#
Service
aoss

Description

Catch-all entry for OpenSearch Service Serverless rules that match the service but not a specific eventName.

BatchGetCollection

#
Service
aoss

Description

Returns attributes for one or more collections, including the collection endpoint, the OpenSearch Dashboards endpoint, and FIPS-compliant endpoints. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2936d6e0-692f-456d-9a44-f76c97c2c349",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "BatchGetCollection",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "cbf8ebde-d20b-4156-9834-9eafd08b5ad9",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

BatchGetCollectionGroup

#
Service
aoss

Description

Returns attributes for one or more collection groups, including capacity limits and the number of collections in each group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ebb5f4c3-fbc3-4240-bea2-053b2741a861",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "BatchGetCollectionGroup",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e1f3dc6c-38c5-491a-ac4f-a22f1ed31288",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

BatchGetEffectiveLifecyclePolicy

#
Service
aoss

Description

Returns a list of successful and failed retrievals for the OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

BatchGetLifecyclePolicy

#
Service
aoss

Description

Returns one or more configured OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

BatchGetVpcEndpoint

#
Service
aoss

Description

Returns attributes for one or more VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b5928ae4-0844-4dc9-bd08-d572d5106e35",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "BatchGetVpcEndpoint",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "e1d5df6e-2292-4461-8c56-31ab5f68dbce",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.32.1 m/g",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

CreateAccessPolicy

#
Service
aoss

Description

Creates a data access policy for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateCollection

#
Service
aoss

Description

Creates a new OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateCollectionGroup

#
Service
aoss

Description

Creates a collection group within OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateIndex

#
Service
aoss

Description

Creates an index within an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLifecyclePolicy

#
Service
aoss

Description

Creates a lifecyle policy to be applied to OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateSecurityConfig

#
Service
aoss

Description

Specifies a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateSecurityPolicy

#
Service
aoss

Description

Creates a security policy to be used by one or more OpenSearch Serverless collections. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateVpcEndpoint

#
Service
aoss

Description

Creates an OpenSearch Serverless-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteAccessPolicy

#
Service
aoss

Description

Deletes an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteCollection

#
Service
aoss

Description

Deletes an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteCollectionGroup

#
Service
aoss

Description

Deletes a collection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteIndex

#
Service
aoss

Description

Deletes an index from an OpenSearch Serverless collection. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a341867c-f242-48f1-ba60-bc815017b32d",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "DeleteIndex",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "f9e7ca0c-2af9-4af3-a287-9deeeed820a1",
  "userAgent": "aws-cli/2.34.24 md/awscrt#0.31.3 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.13.13 md/pyimpl#CPython m/E,b,Z,s,r cfg/retry-mode#standard md/installer#source sid/b501261856ea md/prompt#off md/command#opensearchserverless.delete-index",
  "errorCode": "ResourceNotFoundException",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

DeleteLifecyclePolicy

#
Service
aoss

Description

Deletes an OpenSearch Serverless lifecycle policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteSecurityConfig

#
Service
aoss

Description

Deletes a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteSecurityPolicy

#
Service
aoss

Description

Deletes an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteVpcEndpoint

#
Service
aoss

Description

Deletes an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetAccessPolicy

#
Service
aoss

Description

Returns an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "dbf26e7d-4e61-4778-85a5-18d481daa64b",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "GetAccessPolicy",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a6032ec1-30ac-4b70-b303-4da3df6334c0",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.19.6 m/E,i",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
  }
}

GetAccountSettings

#
Service
aoss

Description

Returns account-level settings related to OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetIndex

#
Service
aoss

Description

Retrieves information about an index in an OpenSearch Serverless collection, including its schema definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetPoliciesStats

#
Service
aoss

Description

Returns statistical information about your OpenSearch Serverless access policies, security configurations, and security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5a949d01-a6fb-4327-96aa-200a96a6e40c",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "GetPoliciesStats",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ccbd9536-74c4-44b7-85e5-324d4d4b53c7",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetSecurityConfig

#
Service
aoss

Description

Returns information about an OpenSearch Serverless security configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSecurityPolicy

#
Service
aoss

Description

Returns information about a configured OpenSearch Serverless security policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "21bec2dd-74cb-46c1-b473-f1ce50a72718",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "GetSecurityPolicy",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "5fbca854-07ba-4256-a9ea-7a73fa90d756",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.19.6 m/E,i",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.ca-central-1.amazonaws.com"
  }
}

ListAccessPolicies

#
Service
aoss

Description

Returns information about a list of OpenSearch Serverless access policies.

Example CloudTrail Event #

{
  "eventVersion": "1.08",
  "userIdentity": {
    "type": "AssumedRole",
    "principalId": "AROA****************:User",
    "arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b/AdanAlvarez",
    "accountId": "123456789012",
    "accessKeyId": "AKIA****************",
    "sessionContext": {
      "sessionIssuer": {
        "type": "Role",
        "principalId": "AROA****************:User",
        "arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/us-east-2/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b",
        "accountId": "123456789012",
        "userName": "AWSReservedSSO_AdministratorAccess_1b74cd717d47002b"
      },
      "webIdFederationData": {},
      "attributes": {
        "creationDate": "2026-02-08T16:28:43Z",
        "mfaAuthenticated": "false"
      }
    }
  },
  "eventTime": "2026-02-08T16:31:32Z",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "ListAccessPolicies",
  "awsRegion": "us-east-1",
  "sourceIPAddress": "0.0.0.0",
  "userAgent": "aws-cli/2.32.3 md/awscrt#0.28.4 ua/2.1 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.13.9 md/pyimpl#CPython m/g,E,b,Z cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#opensearchserverless.list-access-policies",
  "requestParameters": {
    "type": "data"
  },
  "responseElements": null,
  "requestID": "f182f77e-4670-4b97-b381-1b5e709991b9",
  "eventID": "5e7c50cd-4fe5-429e-ad3a-652c02ff3f60",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "clientProvidedHostHeader": "aoss.us-east-1.amazonaws.com"
  }
}

References #

ListCollectionGroups

#
Service
aoss

Description

Returns a list of collection groups. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a9c4a57e-5b40-49c8-813e-05d5e7bf4938",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "ListCollectionGroups",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "27788714-88f0-4d5a-b4fe-01f6ec089ff9",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListCollections

#
Service
aoss

Description

Lists all OpenSearch Serverless collections.

Example CloudTrail Event #

{
  "eventVersion": "1.08",
  "userIdentity": {
    "type": "AssumedRole",
    "principalId": "AROA****************:User",
    "arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b/AdanAlvarez",
    "accountId": "123456789012",
    "accessKeyId": "AKIA****************",
    "sessionContext": {
      "sessionIssuer": {
        "type": "Role",
        "principalId": "AROA****************:User",
        "arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/us-east-2/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b",
        "accountId": "123456789012",
        "userName": "AWSReservedSSO_AdministratorAccess_1b74cd717d47002b"
      },
      "webIdFederationData": {},
      "attributes": {
        "creationDate": "2026-02-08T16:28:43Z",
        "mfaAuthenticated": "false"
      }
    }
  },
  "eventTime": "2026-02-08T16:31:29Z",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "ListCollections",
  "awsRegion": "us-east-1",
  "sourceIPAddress": "0.0.0.0",
  "userAgent": "aws-cli/2.32.3 md/awscrt#0.28.4 ua/2.1 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.13.9 md/pyimpl#CPython m/g,Z,E,b cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#opensearchserverless.list-collections",
  "requestParameters": null,
  "responseElements": null,
  "requestID": "831cbbf1-d17e-4725-9b55-c11134eb6231",
  "eventID": "ca307b47-926c-434c-8a88-efd3b6410e20",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "clientProvidedHostHeader": "aoss.us-east-1.amazonaws.com"
  }
}

References #

ListLifecyclePolicies

#
Service
aoss

Description

Returns a list of OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListSecurityConfigs

#
Service
aoss

Description

Returns information about configured OpenSearch Serverless security configurations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "74e4f447-3c76-4577-9818-652876e66f36",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "ListSecurityConfigs",
  "awsRegion": "eu-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c4b07021-e133-404a-95d5-9e227f440431",
  "userAgent": "config.amazonaws.com"
}

ListSecurityPolicies

#
Service
aoss

Description

Returns information about configured OpenSearch Serverless security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a0600462-134d-46ae-8e3e-13c7a263cb47",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "ListSecurityPolicies",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "48a3271e-f796-48d2-8066-6a1e50ce8d0c",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.19.6 m/C,E,i",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
  }
}

ListTagsForResource

#
Service
aoss

Description

Returns the tags for an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListVpcEndpoints

#
Service
aoss

Description

Returns the OpenSearch Serverless-managed interface VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b58a8a40-eadc-4c07-8685-f4e6e96fff3a",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "ListVpcEndpoints",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7898be7d-5adb-47ab-b540-4260a5dede02",
  "userAgent": "config.amazonaws.com"
}

TagResource

#
Service
aoss

Description

Associates tags with an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
aoss

Description

Removes a tag or set of tags from an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAccessPolicy

#
Service
aoss

Description

Updates an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1a7aa3f1-ea10-40f7-8c63-a887d8aab270",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "UpdateAccessPolicy",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "3e10d156-9c87-4f6c-8476-fbac0d103b93",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.32.1 m/g",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

UpdateAccountSettings

#
Service
aoss

Description

Update the OpenSearch Serverless settings for the current Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateCollection

#
Service
aoss

Description

Updates an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateCollectionGroup

#
Service
aoss

Description

Updates the description and capacity limits of a collection group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4611a659-afa7-4840-b21e-20851834b178",
  "eventSource": "aoss.amazonaws.com",
  "eventName": "UpdateCollectionGroup",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "12dfed76-93d5-43e4-a6eb-3c2c8dc39212",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.32.1 m/g",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

UpdateIndex

#
Service
aoss

Description

Updates an existing index in an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLifecyclePolicy

#
Service
aoss

Description

Updates an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateSecurityConfig

#
Service
aoss

Description

Updates a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateSecurityPolicy

#
Service
aoss

Description

Updates an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateVpcEndpoint

#
Service
aoss

Description

Updates an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.