OpenSearch Service Serverless
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for OpenSearch Service Serverless rules that match the service but not a specific eventName. | N | N |
| Batch | Returns attributes for one or more collections, including the collection endpoint, the OpenSearch Dashboards endpoint, and FIPS-compliant endpoints. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Batch | Returns attributes for one or more collection groups, including capacity limits and the number of collections in each group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Batch | Returns a list of successful and failed retrievals for the OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Batch | Returns one or more configured OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Batch | Returns attributes for one or more VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Create | Creates a data access policy for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a new OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a collection group within OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates an index within an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a lifecyle policy to be applied to OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Specifies a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates a security policy to be used by one or more OpenSearch Serverless collections. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates an OpenSearch Serverless-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a collection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an index from an OpenSearch Serverless collection. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Delete | Deletes an OpenSearch Serverless lifecycle policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Returns an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Returns account-level settings related to OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves information about an index in an OpenSearch Serverless collection, including its schema definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Returns statistical information about your OpenSearch Serverless access policies, security configurations, and security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Returns information about an OpenSearch Serverless security configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Returns information about a configured OpenSearch Serverless security policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns information about a list of OpenSearch Serverless access policies. | Y | N |
| List | Returns a list of collection groups. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Lists all OpenSearch Serverless collections. | Y | N |
| List | Returns a list of OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Returns information about configured OpenSearch Serverless security configurations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns information about configured OpenSearch Serverless security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns the tags for an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Returns the OpenSearch Serverless-managed interface VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Tag | Associates tags with an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Untag | Removes a tag or set of tags from an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Update | Update the OpenSearch Serverless settings for the current Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates the description and capacity limits of a collection group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Update | Updates an existing index in an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
any: OpenSearch Service Serverless (catch-all)
#Description
Catch-all entry for OpenSearch Service Serverless rules that match the service but not a specific eventName.
BatchGetCollection
#Description
Returns attributes for one or more collections, including the collection endpoint, the OpenSearch Dashboards endpoint, and FIPS-compliant endpoints. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "2936d6e0-692f-456d-9a44-f76c97c2c349",
"eventSource": "aoss.amazonaws.com",
"eventName": "BatchGetCollection",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "cbf8ebde-d20b-4156-9834-9eafd08b5ad9",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
BatchGetCollectionGroup
#Description
Returns attributes for one or more collection groups, including capacity limits and the number of collections in each group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ebb5f4c3-fbc3-4240-bea2-053b2741a861",
"eventSource": "aoss.amazonaws.com",
"eventName": "BatchGetCollectionGroup",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "e1f3dc6c-38c5-491a-ac4f-a22f1ed31288",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
BatchGetEffectiveLifecyclePolicy
#Description
Returns a list of successful and failed retrievals for the OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
BatchGetLifecyclePolicy
#Description
Returns one or more configured OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
BatchGetVpcEndpoint
#Description
Returns attributes for one or more VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b5928ae4-0844-4dc9-bd08-d572d5106e35",
"eventSource": "aoss.amazonaws.com",
"eventName": "BatchGetVpcEndpoint",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "e1d5df6e-2292-4461-8c56-31ab5f68dbce",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.32.1 m/g",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
CreateAccessPolicy
#Description
Creates a data access policy for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateCollection
#Description
Creates a new OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateCollectionGroup
#Description
Creates a collection group within OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateIndex
#Description
Creates an index within an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateLifecyclePolicy
#Description
Creates a lifecyle policy to be applied to OpenSearch Serverless indexes. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateSecurityConfig
#Description
Specifies a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateSecurityPolicy
#Description
Creates a security policy to be used by one or more OpenSearch Serverless collections. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateVpcEndpoint
#Description
Creates an OpenSearch Serverless-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteAccessPolicy
#Description
Deletes an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteCollection
#Description
Deletes an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteCollectionGroup
#Description
Deletes a collection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteIndex
#Description
Deletes an index from an OpenSearch Serverless collection. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a341867c-f242-48f1-ba60-bc815017b32d",
"eventSource": "aoss.amazonaws.com",
"eventName": "DeleteIndex",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "f9e7ca0c-2af9-4af3-a287-9deeeed820a1",
"userAgent": "aws-cli/2.34.24 md/awscrt#0.31.3 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.13.13 md/pyimpl#CPython m/E,b,Z,s,r cfg/retry-mode#standard md/installer#source sid/b501261856ea md/prompt#off md/command#opensearchserverless.delete-index",
"errorCode": "ResourceNotFoundException",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
DeleteLifecyclePolicy
#Description
Deletes an OpenSearch Serverless lifecycle policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteSecurityConfig
#Description
Deletes a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteSecurityPolicy
#Description
Deletes an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteVpcEndpoint
#Description
Deletes an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetAccessPolicy
#Description
Returns an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "dbf26e7d-4e61-4778-85a5-18d481daa64b",
"eventSource": "aoss.amazonaws.com",
"eventName": "GetAccessPolicy",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "a6032ec1-30ac-4b70-b303-4da3df6334c0",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.19.6 m/E,i",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
}
}
GetAccountSettings
#Description
Returns account-level settings related to OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetIndex
#Description
Retrieves information about an index in an OpenSearch Serverless collection, including its schema definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetPoliciesStats
#Description
Returns statistical information about your OpenSearch Serverless access policies, security configurations, and security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "5a949d01-a6fb-4327-96aa-200a96a6e40c",
"eventSource": "aoss.amazonaws.com",
"eventName": "GetPoliciesStats",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "ccbd9536-74c4-44b7-85e5-324d4d4b53c7",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
GetSecurityConfig
#Description
Returns information about an OpenSearch Serverless security configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetSecurityPolicy
#Description
Returns information about a configured OpenSearch Serverless security policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "21bec2dd-74cb-46c1-b473-f1ce50a72718",
"eventSource": "aoss.amazonaws.com",
"eventName": "GetSecurityPolicy",
"awsRegion": "ca-central-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "5fbca854-07ba-4256-a9ea-7a73fa90d756",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.19.6 m/E,i",
"tlsDetails": {
"clientProvidedHostHeader": "example.ca-central-1.amazonaws.com"
}
}
ListAccessPolicies
#Description
Returns information about a list of OpenSearch Serverless access policies.
Example CloudTrail Event #
{
"eventVersion": "1.08",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROA****************:User",
"arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b/AdanAlvarez",
"accountId": "123456789012",
"accessKeyId": "AKIA****************",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROA****************:User",
"arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/us-east-2/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b",
"accountId": "123456789012",
"userName": "AWSReservedSSO_AdministratorAccess_1b74cd717d47002b"
},
"webIdFederationData": {},
"attributes": {
"creationDate": "2026-02-08T16:28:43Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-02-08T16:31:32Z",
"eventSource": "aoss.amazonaws.com",
"eventName": "ListAccessPolicies",
"awsRegion": "us-east-1",
"sourceIPAddress": "0.0.0.0",
"userAgent": "aws-cli/2.32.3 md/awscrt#0.28.4 ua/2.1 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.13.9 md/pyimpl#CPython m/g,E,b,Z cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#opensearchserverless.list-access-policies",
"requestParameters": {
"type": "data"
},
"responseElements": null,
"requestID": "f182f77e-4670-4b97-b381-1b5e709991b9",
"eventID": "5e7c50cd-4fe5-429e-ad3a-652c02ff3f60",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"clientProvidedHostHeader": "aoss.us-east-1.amazonaws.com"
}
}
References #
ListCollectionGroups
#Description
Returns a list of collection groups. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a9c4a57e-5b40-49c8-813e-05d5e7bf4938",
"eventSource": "aoss.amazonaws.com",
"eventName": "ListCollectionGroups",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "27788714-88f0-4d5a-b4fe-01f6ec089ff9",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
ListCollections
#Description
Lists all OpenSearch Serverless collections.
Example CloudTrail Event #
{
"eventVersion": "1.08",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROA****************:User",
"arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b/AdanAlvarez",
"accountId": "123456789012",
"accessKeyId": "AKIA****************",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROA****************:User",
"arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/us-east-2/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b",
"accountId": "123456789012",
"userName": "AWSReservedSSO_AdministratorAccess_1b74cd717d47002b"
},
"webIdFederationData": {},
"attributes": {
"creationDate": "2026-02-08T16:28:43Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-02-08T16:31:29Z",
"eventSource": "aoss.amazonaws.com",
"eventName": "ListCollections",
"awsRegion": "us-east-1",
"sourceIPAddress": "0.0.0.0",
"userAgent": "aws-cli/2.32.3 md/awscrt#0.28.4 ua/2.1 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.13.9 md/pyimpl#CPython m/g,Z,E,b cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#opensearchserverless.list-collections",
"requestParameters": null,
"responseElements": null,
"requestID": "831cbbf1-d17e-4725-9b55-c11134eb6231",
"eventID": "ca307b47-926c-434c-8a88-efd3b6410e20",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"clientProvidedHostHeader": "aoss.us-east-1.amazonaws.com"
}
}
References #
ListLifecyclePolicies
#Description
Returns a list of OpenSearch Serverless lifecycle policies. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListSecurityConfigs
#Description
Returns information about configured OpenSearch Serverless security configurations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "74e4f447-3c76-4577-9818-652876e66f36",
"eventSource": "aoss.amazonaws.com",
"eventName": "ListSecurityConfigs",
"awsRegion": "eu-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "c4b07021-e133-404a-95d5-9e227f440431",
"userAgent": "config.amazonaws.com"
}
ListSecurityPolicies
#Description
Returns information about configured OpenSearch Serverless security policies. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a0600462-134d-46ae-8e3e-13c7a263cb47",
"eventSource": "aoss.amazonaws.com",
"eventName": "ListSecurityPolicies",
"awsRegion": "ap-southeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "48a3271e-f796-48d2-8066-6a1e50ce8d0c",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.19.6 m/C,E,i",
"tlsDetails": {
"clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
}
}
ListVpcEndpoints
#Description
Returns the OpenSearch Serverless-managed interface VPC endpoints associated with the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b58a8a40-eadc-4c07-8685-f4e6e96fff3a",
"eventSource": "aoss.amazonaws.com",
"eventName": "ListVpcEndpoints",
"awsRegion": "us-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "7898be7d-5adb-47ab-b540-4260a5dede02",
"userAgent": "config.amazonaws.com"
}
TagResource
#Description
Associates tags with an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UntagResource
#Description
Removes a tag or set of tags from an OpenSearch Serverless resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateAccessPolicy
#Description
Updates an OpenSearch Serverless access policy. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1a7aa3f1-ea10-40f7-8c63-a887d8aab270",
"eventSource": "aoss.amazonaws.com",
"eventName": "UpdateAccessPolicy",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "3e10d156-9c87-4f6c-8476-fbac0d103b93",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.32.1 m/g",
"tlsDetails": {
"clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
}
}
UpdateAccountSettings
#Description
Update the OpenSearch Serverless settings for the current Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateCollection
#Description
Updates an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateCollectionGroup
#Description
Updates the description and capacity limits of a collection group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4611a659-afa7-4840-b21e-20851834b178",
"eventSource": "aoss.amazonaws.com",
"eventName": "UpdateCollectionGroup",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "12dfed76-93d5-43e4-a6eb-3c2c8dc39212",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/opensearchserverless#1.32.1 m/g",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
UpdateIndex
#Description
Updates an existing index in an OpenSearch Serverless collection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateLifecyclePolicy
#Description
Updates an OpenSearch Serverless access policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateSecurityConfig
#Description
Updates a security configuration for OpenSearch Serverless. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateSecurityPolicy
#Description
Updates an OpenSearch Serverless security policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateVpcEndpoint
#Description
Updates an OpenSearch Serverless-managed interface endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.