AWS Backup

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Backup rules that match the service but not a specific eventName.NN
DeleteBackupPlanDeletes a backup plan, removing all scheduled backup rules and preventing future automatic backups under that plan.YY
DeleteBackupSelectionRemoves a resource assignment (selection) from a backup plan, stopping the plan from protecting the specified resources.YY
AssociateBackupVaultMpaApprovalTeamAssociates an MPA approval team with a backup vault.NN
CancelLegalHoldRemoves the specified legal hold on a recovery point.YN
CreateBackupPlanCreates a backup plan using a backup plan name and backup rules.YN
CreateBackupSelectionCreates a JSON document that specifies a set of resources to assign to a backup plan.YN
CreateBackupVaultCreates a logical container where backups are stored.YN
CreateFrameworkCreates a framework with one or more controls.YN
CreateLegalHoldCreates a legal hold on a recovery point (backup).YN
CreateLogicallyAirGappedBackupVaultCreates a logical container to where backups may be copied.NN
CreateReportPlanCreates a report plan.NN
CreateRestoreAccessBackupVaultCreates a restore access backup vault that provides temporary access to recovery points in a logically air-gapped backup vault, subject to MPA approval.NN
CreateRestoreTestingPlanCreates a restore testing plan.YN
CreateRestoreTestingSelectionThis request can be sent after CreateRestoreTestingPlan request returns successfully.YN
CreateTieringConfigurationCreates a tiering configuration.NN
DeleteBackupVaultDeletes the backup vault identified by its name.YY
DeleteBackupVaultAccessPolicyDeletes the policy document that manages permissions on a backup vault.YN
DeleteBackupVaultLockConfigurationDeletes Backup Vault Lock from a backup vault specified by a backup vault name.YY
DeleteBackupVaultNotificationsDeletes event notifications for the specified backup vault.YN
DeleteFrameworkDeletes the framework specified by a framework name.YN
DeleteRecoveryPointDeletes the recovery point specified by a recovery point ID.YY
DeleteReportPlanDeletes the report plan specified by a report plan name.YN
DeleteRestoreTestingPlanThis request deletes the specified restore testing plan.YN
DeleteRestoreTestingSelectionInput the Restore Testing Plan name and Restore Testing Selection name.YN
DeleteTieringConfigurationDeletes the tiering configuration specified by a tiering configuration name.YN
DescribeBackupJobReturns backup job details for the specified BackupJobId.YN
DescribeBackupVaultReturns metadata about a backup vault specified by its name.YN
DescribeCopyJobReturns metadata associated with creating a copy of a resource.YN
DescribeFrameworkReturns the framework details for the specified FrameworkName.YN
DescribeGlobalSettingsDescribes whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator.YN
DescribeProtectedResourceReturns information about a saved resource, including the last time it was backed up, its Amazon Resource Name (ARN), and the Amazon Web Services service type of the saved resource.YN
DescribeRecoveryPointReturns metadata associated with a recovery point, including ID, status, encryption, and lifecycle.YN
DescribeRegionSettingsReturns the current service opt-in settings for the Region.YN
DescribeReportJobReturns the details associated with creating a report as specified by its ReportJobId.YN
DescribeReportPlanReturns a list of all report plans for an Amazon Web Services account and Amazon Web Services Region.YN
DescribeRestoreJobReturns metadata associated with a restore job that is specified by a job ID.YN
DescribeScanJobReturns scan job details for the specified ScanJobID.YN
DisassociateBackupVaultMpaApprovalTeamRemoves the association between an MPA approval team and a backup vault, disabling the MPA approval workflow for restore operations.YN
DisassociateRecoveryPointDeletes the specified continuous backup recovery point from Backup and releases control of that continuous backup to the source service, such as Amazon RDS.YN
DisassociateRecoveryPointFromParentThis action to a specific child (nested) recovery point removes the relationship between the specified recovery point and its parent (composite) recovery point.YN
ExportBackupPlanTemplateReturns the backup plan that is specified by the plan ID as a backup template.YN
GetBackupPlanReturns BackupPlan details for the specified BackupPlanId.YN
GetBackupPlanFromJSONReturns a valid JSON document specifying a backup plan or an error.YN
GetBackupPlanFromTemplateReturns the template specified by its templateId as a backup plan.YN
GetBackupSelectionReturns selection metadata and a document in JSON format that specifies a list of resources that are associated with a backup plan.YN
GetBackupVaultAccessPolicyReturns the access policy document that is associated with the named backup vault.YN
GetBackupVaultNotificationsReturns event notifications for the specified backup vault.YN
GetLegalHoldThis action returns details for a specified legal hold.YN
GetPITRMalwareScanResultsReturns the malware scan results for a specified point in time within a continuous (point-in-time recovery) backup.NN
GetRecoveryPointIndexDetailsThis operation returns the metadata and details specific to the backup index associated with the specified recovery point.YN
GetRecoveryPointRestoreMetadataReturns a set of metadata key-value pairs that were used to create the backup.YN
GetRestoreJobMetadataThis request returns the metadata for the specified restore job.YN
GetRestoreTestingInferredMetadataThis request returns the minimal required set of metadata needed to start a restore job with secure default settings.YN
GetRestoreTestingPlanReturns RestoreTestingPlan details for the specified RestoreTestingPlanName.YN
GetRestoreTestingSelectionReturns RestoreTestingSelection, which displays resources and elements of the restore testing plan.YN
GetSupportedResourceTypesReturns the Amazon Web Services resource types supported by Backup.YN
GetTieringConfigurationReturns TieringConfiguration details for the specified TieringConfigurationName.YN
ListBackupJobsReturns a list of existing backup jobs for an authenticated account for the last 30 days.YN
ListBackupJobSummariesThis is a request for a summary of backup jobs created or running within the most recent 30 days.YN
ListBackupPlansLists the active backup plans for the account.YN
ListBackupPlanTemplatesLists the backup plan templates.YN
ListBackupPlanVersionsReturns version metadata of your backup plans, including Amazon Resource Names (ARNs), backup plan IDs, creation and deletion dates, plan names, and version IDs.YN
ListBackupSelectionsReturns an array containing metadata of the resources associated with the target backup plan.YN
ListBackupVaultsReturns a list of recovery point storage containers along with information about them.YN
ListCopyJobsReturns metadata about your copy jobs.YN
ListCopyJobSummariesThis request obtains a list of copy jobs created or running within the the most recent 30 days.YN
ListFrameworksReturns a list of all frameworks for an Amazon Web Services account and Amazon Web Services Region.YN
ListIndexedRecoveryPointsThis operation returns a list of recovery points that have an associated index, belonging to the specified account.YN
ListLegalHoldsThis action returns metadata about active and previous legal holds.YN
ListProtectedResourcesReturns an array of resources successfully backed up by Backup, including the time the resource was saved, an Amazon Resource Name (ARN) of the resource, and a resource type.YN
ListProtectedResourcesByBackupVaultThis request lists the protected resources corresponding to each backup vault.YN
ListRecoveryPointsByBackupVaultReturns detailed information about the recovery points stored in a backup vault.YN
ListRecoveryPointsByLegalHoldThis action returns recovery point ARNs (Amazon Resource Names) of the specified legal hold.YN
ListRecoveryPointsByResourceThe information about the recovery points of the type specified by a resource Amazon Resource Name (ARN).YN
ListReportJobsReturns details about your report jobs.YN
ListReportPlansReturns a list of your report plans.YN
ListRestoreAccessBackupVaultsReturns a list of restore access backup vaults associated with a specified backup vault.YN
ListRestoreJobsReturns a list of jobs that Backup initiated to restore a saved resource, including details about the recovery process.YN
ListRestoreJobsByProtectedResourceThis returns restore jobs that contain the specified protected resource.YN
ListRestoreJobSummariesThis request obtains a summary of restore jobs created or running within the the most recent 30 days.YN
ListRestoreTestingPlansReturns a list of restore testing plans.YN
ListRestoreTestingSelectionsReturns a list of restore testing selections.YN
ListScanJobsReturns a list of existing scan jobs for an authenticated account for the last 30 days.YN
ListScanJobSummariesThis is a request for a summary of scan jobs created or running within the most recent 30 days.YN
ListTagsReturns the tags assigned to the resource, such as a target recovery point, backup plan, or backup vault.YN
ListTieringConfigurationsReturns a list of tiering configurations.YN
PutBackupVaultAccessPolicySets a resource-based policy that is used to manage access permissions on the target backup vault.YN
PutBackupVaultLockConfigurationApplies Backup Vault Lock to a backup vault, preventing attempts to delete any recovery point stored in or created in a backup vault.NN
PutBackupVaultNotificationsTurns on notifications on a backup vault for the specified topic and events.YN
PutRestoreValidationResultThis request allows you to send your independent self-run restore test validation results.NN
RevokeRestoreAccessBackupVaultRevokes access to a restore access backup vault, removing the ability to restore from its recovery points and permanently deleting the vault.YN
StartBackupJobStarts an on-demand backup job for the specified resource.NN
StartCopyJobStarts a job to create a one-time copy of the specified resource.NN
StartReportJobStarts an on-demand report job for the specified report plan.NN
StartRestoreJobRecovers the saved resource identified by an Amazon Resource Name (ARN).NN
StartScanJobStarts scanning jobs for specific resources.NN
StopBackupJobAttempts to cancel a job to create a one-time backup of a resource.YN
TagResourceAssigns a set of key-value pairs to a resource.YN
UntagResourceRemoves a set of key-value pairs from a recovery point, backup plan, or backup vault identified by an Amazon Resource Name (ARN) This API is not supported for recovery points for resource types including Aurora, Amazon DocumentDB.YN
UpdateBackupPlanUpdates the specified backup plan.YN
UpdateFrameworkUpdates the specified framework.YN
UpdateGlobalSettingsUpdates whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator.NN
UpdateRecoveryPointIndexSettingsThis operation updates the settings of a recovery point index.YN
UpdateRecoveryPointLifecycleSets the transition lifecycle of a recovery point.YN
UpdateRegionSettingsUpdates the current service opt-in settings for the Region.NN
UpdateReportPlanUpdates the specified report plan.YN
UpdateRestoreTestingPlanThis request will send changes to your specified restore testing plan.YN
UpdateRestoreTestingSelectionUpdates the specified restore testing selection.YN
UpdateTieringConfigurationThis request will send changes to your specified tiering configuration.YN
AuthorizeRecoveryPointTaggingAuthorizeRecoveryPointTagging recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
BackupDeletedBackupDeleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
BackupJobCompletedBackupJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
BackupJobStartedBackupJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
COPY_JOB_COMPLETEDCOPY_JOB_COMPLETED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
COPY_JOB_STARTEDCOPY_JOB_STARTED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
CopyJobCompletedCopyJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
CopyJobStartedCopyJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
RecoveryPointCreatedRecoveryPointCreated recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
CreateBackupAccessPointCreates a backup access point for an Amazon S3 recovery point.NN
DeleteBackupAccessPointDeletes a backup access point.NN
DescribeBackupAccessPointReturns metadata about a backup access point, including its status and the details of the underlying Amazon S3 access point.NN
ListBackupAccessPointsReturns a list of the backup access points in your account and Region.NN
ListBackupAccessPointsByRecoveryPointReturns the backup access points associated with the specified recovery point.NN
ListBackupAccessPointsByResourceReturns the backup access points associated with the specified resource, such as an Amazon S3 bucket.NN

any: AWS Backup (catch-all)

#
Service
backup

Description

Catch-all entry for AWS Backup rules that match the service but not a specific eventName.

DeleteBackupPlan

#
Service
backup

Description

Deletes a backup plan, removing all scheduled backup rules and preventing future automatic backups under that plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup plan ID",
  "eventCategory": "Management",
  "eventID": "9507a1ce-1dcf-4fd7-9206-6426d6ee490c",
  "eventName": "DeleteBackupPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6af8828a-5b15-4811-9877-4112112a90b2",
  "requestParameters": {
    "backupPlanId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

DeleteBackupSelection

#
Service
backup

Description

Removes a resource assignment (selection) from a backup plan, stopping the plan from protecting the specified resources.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup plan ID",
  "eventCategory": "Management",
  "eventID": "2240edef-0688-4066-b8d3-ecc21050096a",
  "eventName": "DeleteBackupSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "14c17982-4404-46b7-8493-9e9b30ba5b3b",
  "requestParameters": {
    "backupPlanId": "dw-probe",
    "selectionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

AssociateBackupVaultMpaApprovalTeam

#
Service
backup

Description

Associates an MPA approval team with a backup vault.

CancelLegalHold

#
Service
backup

Description

Removes the specified legal hold on a recovery point.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Can not find Legal Hold ARN.",
  "eventCategory": "Management",
  "eventID": "60ab5024-44f4-49d3-856f-b1234d3a9ab4",
  "eventName": "CancelLegalHold",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eb38ac27-756a-425a-a77a-3bd811b1f8a7",
  "requestParameters": {
    "cancelDescription": "dw-probe",
    "legalHoldId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateBackupPlan

#
Service
backup

Description

Creates a backup plan using a backup plan name and backup rules.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ead0622e-78b6-4449-88c7-d0561899a44c",
  "eventName": "CreateBackupPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "93cef107-bbd8-4a7f-8454-fafbcec68424",
  "requestParameters": {
    "backupPlan": {
      "backupPlanName": "dwfixplanbz9vn61lmy",
      "rules": [
        {
          "completionWindowMinutes": 180,
          "lifecycle": {
            "deleteAfterDays": 1
          },
          "ruleName": "dwfix-daily",
          "scheduleExpression": "cron(0 12 * * ? *)",
          "startWindowMinutes": 60,
          "targetBackupVaultName": "dwfix-vault-bz9vn61lmy"
        }
      ]
    },
    "backupPlanTags": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "creatorRequestId": "4cc66d2b-265f-4056-a40d-0c5d9a5041ce"
  },
  "responseElements": {
    "backupPlanArn": "arn:aws:backup:us-west-1:123456789012:backup-plan:ab6eee5e-6a45-4730-bf39-724df73407b3",
    "backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3",
    "creationDate": "2026-06-29T21:01:38Z",
    "versionId": "YzNlYzdhNzEtN2ViZi00MjgyLThhYmQtYWU1YzY1MTEwNWJj"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateBackupSelection

#
Service
backup

Description

Creates a JSON document that specifies a set of resources to assign to a backup plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0614dcd7-9d69-46ab-90e5-99d9b07794c2",
  "eventName": "CreateBackupSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "61974a11-eaf4-49b5-9619-94539953ccfe",
  "requestParameters": {
    "backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3",
    "backupSelection": {
      "iamRoleArn": "arn:aws:iam::123456789012:role/service-role/AWSBackupDefaultServiceRole",
      "resources": [
        "arn:aws:dynamodb:us-west-1:123456789012:table/dwfix-placeholder"
      ],
      "selectionName": "dwfix-sel"
    },
    "creatorRequestId": "1aef2ed1-d791-438d-9818-ad4afd0ed4d0"
  },
  "responseElements": {
    "backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3",
    "creationDate": "2026-06-29T21:01:38Z",
    "selectionId": "58849ff1-0c83-47c5-88de-dc4a96d55a6b"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateBackupVault

#
Service
backup

Description

Creates a logical container where backups are stored.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "79b71214-0df6-4d5d-b378-30debb576350",
  "eventName": "CreateBackupVault",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4ecfb09b-7384-4b22-8284-14321c7ad4a6",
  "requestParameters": {
    "backupVaultName": "dwfix-vault-bz9vn61lmy",
    "backupVaultTags": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "creatorRequestId": "c4690368-9c56-42cd-9159-43a8ebb01bd5"
  },
  "responseElements": {
    "backupVaultArn": "arn:aws:backup:us-west-1:123456789012:backup-vault:dwfix-vault-bz9vn61lmy",
    "backupVaultName": "dwfix-vault-bz9vn61lmy",
    "creationDate": "2026-06-29T21:01:38Z"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateFramework

#
Service
backup

Description

Creates a framework with one or more controls.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b95600df-d086-403d-a157-0d308746ce90",
  "eventName": "CreateFramework",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "748051be-426e-45f1-9c1b-259ff2a819f5",
  "requestParameters": {
    "frameworkControls": [
      {
        "controlInputParameters": [
          {
            "parameterName": "requiredFrequencyValue",
            "parameterValue": "1"
          },
          {
            "parameterName": "requiredFrequencyUnit",
            "parameterValue": "days"
          },
          {
            "parameterName": "requiredRetentionDays",
            "parameterValue": "7"
          }
        ],
        "controlName": "BACKUP_PLAN_MIN_FREQUENCY_AND_MIN_RETENTION_CHECK"
      }
    ],
    "frameworkDescription": "dwfix sample-collection framework",
    "frameworkName": "dwfixfwbz9vn61lmy",
    "frameworkTags": {
      "Project": "dwfix"
    },
    "idempotencyToken": "e2f554e0-3109-4716-9fa8-e33996b13166"
  },
  "responseElements": {
    "frameworkArn": "arn:aws:backup:us-west-1:123456789012:framework:dwfixfwbz9vn61lmy-283fa74e-2aa1-439f-a812-d752c5192306",
    "frameworkName": "dwfixfwbz9vn61lmy"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateLegalHold

#
Service
backup

Description

Creates a legal hold on a recovery point (backup).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "MissingParameterValueException",
  "errorMessage": "Missing Resource Selection.",
  "eventCategory": "Management",
  "eventID": "5267dcd4-3ce8-4a26-b506-1b8920676ac4",
  "eventName": "CreateLegalHold",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6fe7dfc5-b92f-4cb7-a87d-93f0230aeb59",
  "requestParameters": {
    "description": "dwfix sample-collection legal hold - safe to cancel",
    "idempotencyToken": "941f38d4-9ba3-4de0-ba20-993e2c6c09c2",
    "title": "dwfix-hold-bz9vn61lmy"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateLogicallyAirGappedBackupVault

#
Service
backup

Description

Creates a logical container to where backups may be copied.

CreateReportPlan

#
Service
backup

Description

Creates a report plan.

CreateRestoreAccessBackupVault

#
Service
backup

Description

Creates a restore access backup vault that provides temporary access to recovery points in a logically air-gapped backup vault, subject to MPA approval.

CreateRestoreTestingPlan

#
Service
backup

Description

Creates a restore testing plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e9d63e95-6bc8-4238-ac4f-42b653523f55",
  "eventName": "CreateRestoreTestingPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1221195d-f23c-4345-af5f-148904082011",
  "requestParameters": {
    "restoreTestingPlan": {
      "recoveryPointSelection": {
        "algorithm": "LATEST_WITHIN_WINDOW",
        "includeVaults": [
          "arn:aws:backup:us-west-1:123456789012:backup-vault:dwfix-vault-bz9vn61lmy"
        ],
        "recoveryPointTypes": [
          "SNAPSHOT"
        ],
        "selectionWindowDays": 7
      },
      "restoreTestingPlanName": "dwfixrtpbz9vn61lmy",
      "scheduleExpression": "cron(0 12 ? * 1 *)",
      "startWindowHours": 8
    },
    "tags": "HIDDEN_DUE_TO_SECURITY_REASONS"
  },
  "responseElements": {
    "creationTime": "2026-06-29T21:01:40Z",
    "restoreTestingPlanArn": "arn:aws:backup:us-west-1:123456789012:restore-testing-plan:dwfixrtpbz9vn61lmy-178ba446-9fdd-4287-94bd-af24ed23d5a6",
    "restoreTestingPlanName": "dwfixrtpbz9vn61lmy"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateRestoreTestingSelection

#
Service
backup

Description

This request can be sent after CreateRestoreTestingPlan request returns successfully.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "be98f834-03a8-40d6-bf3f-975dbd6aec4f",
  "eventName": "CreateRestoreTestingSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ee496ff3-9d49-4cac-9a26-149d2416e6a2",
  "requestParameters": {
    "restoreTestingPlanName": "dwfixrtpbz9vn61lmy",
    "restoreTestingSelection": {
      "iamRoleArn": "arn:aws:iam::123456789012:role/service-role/AWSBackupDefaultServiceRole",
      "protectedResourceType": "DynamoDB",
      "restoreTestingSelectionName": "dwfixrtsel"
    }
  },
  "responseElements": {
    "creationTime": "2026-06-29T21:01:40Z",
    "restoreTestingPlanArn": "arn:aws:backup:us-west-1:123456789012:restore-testing-plan:dwfixrtpbz9vn61lmy-178ba446-9fdd-4287-94bd-af24ed23d5a6",
    "restoreTestingPlanName": "dwfixrtpbz9vn61lmy",
    "restoreTestingSelectionName": "dwfixrtsel"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTieringConfiguration

#
Service
backup

Description

Creates a tiering configuration.

DeleteBackupVault

#
Service
backup

Description

Deletes the backup vault identified by its name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "d22a9e7e-777a-4656-a8ef-a1c3ed2acb69",
  "eventName": "DeleteBackupVault",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9c106e28-5a64-4361-8bdf-82d29684753c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Backup Vault Deleted or Vault Lock Removed source high: Identifies deletion of an AWS Backup vault or removal of its Vault Lock configuration via DeleteBackupVault or DeleteBackupVaultLockConfiguration. A backup vault stores recovery points, and Vault Lock enforces WORM (write-once, read-many) immutability that prevents recovery points from being deleted before their retention expires. Removing the lock defeats the primary control designed to stop ransomware from destroying backups, and deleting the vault removes the backup container entirely. Both actions are strong anti-recovery signals and are rare in normal operations.T1490, T1562↳ also matches DeleteBackupVaultLockConfiguration

DeleteBackupVaultAccessPolicy

#
Service
backup

Description

Deletes the policy document that manages permissions on a backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "6b34f283-e0bb-477b-8c87-5090115ce353",
  "eventName": "DeleteBackupVaultAccessPolicy",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "58f0b99c-ba63-470a-8e62-d3fdf0748b47",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBackupVaultLockConfiguration

#
Service
backup

Description

Deletes Backup Vault Lock from a backup vault specified by a backup vault name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "941eb5d0-8429-46ab-8b07-d2a1103a1254",
  "eventName": "DeleteBackupVaultLockConfiguration",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "50e443b9-4052-45f1-9a0d-d5af83d30302",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Backup Vault Deleted or Vault Lock Removed source high: Identifies deletion of an AWS Backup vault or removal of its Vault Lock configuration via DeleteBackupVault or DeleteBackupVaultLockConfiguration. A backup vault stores recovery points, and Vault Lock enforces WORM (write-once, read-many) immutability that prevents recovery points from being deleted before their retention expires. Removing the lock defeats the primary control designed to stop ransomware from destroying backups, and deleting the vault removes the backup container entirely. Both actions are strong anti-recovery signals and are rare in normal operations.T1490, T1562↳ also matches DeleteBackupVault

DeleteBackupVaultNotifications

#
Service
backup

Description

Deletes event notifications for the specified backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "a13e734e-a047-4aa9-a4db-a2d65329efbc",
  "eventName": "DeleteBackupVaultNotifications",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8f9ca09c-501f-4fe4-9802-8e13a75c086e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteFramework

#
Service
backup

Description

Deletes the framework specified by a framework name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Framework ddddd not found in account 123456789012.",
  "eventCategory": "Management",
  "eventID": "73779cb6-71c0-4677-ad03-cbc7eeb20e07",
  "eventName": "DeleteFramework",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5de0f17b-c6b6-4082-9163-feaba8423d95",
  "requestParameters": {
    "frameworkName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRecoveryPoint

#
Service
backup

Description

Deletes the recovery point specified by a recovery point ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "89d6a500-e77f-4ab8-9bb5-b5ac4c2f1424",
  "eventName": "DeleteRecoveryPoint",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "59f8696d-191f-47e2-bdc4-5c53d6d4b793",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Backup Recovery Point Deleted source high: Identifies deletion of an AWS Backup recovery point via DeleteRecoveryPoint. A recovery point is a stored backup of a protected resource (EBS, RDS, DynamoDB, EFS, S3, and others). Deleting recovery points removes the ability to restore the associated data and is a core anti-recovery technique used in ransomware and data-destruction attacks to ensure victims cannot recover without paying or rebuilding. Routine lifecycle expirations are performed by the AWS Backup service itself; deletion by a non-service principal is rare and should be reviewed.T1490

DeleteReportPlan

#
Service
backup

Description

Deletes the report plan specified by a report plan name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Report plan ddddd not found in account 123456789012.",
  "eventCategory": "Management",
  "eventID": "44d499ab-6aa4-4faa-872f-2ac5c8d7fa36",
  "eventName": "DeleteReportPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5e3184b8-1b58-49f1-bf13-ef32524da4e7",
  "requestParameters": {
    "reportPlanName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRestoreTestingPlan

#
Service
backup

Description

This request deletes the specified restore testing plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "565f8895-e520-4d97-902b-fd07e9f9fec5",
  "eventName": "DeleteRestoreTestingPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "93c06351-3e1c-46d0-bbc8-d04f5c0dac25",
  "requestParameters": {
    "restoreTestingPlanName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRestoreTestingSelection

#
Service
backup

Description

Input the Restore Testing Plan name and Restore Testing Selection name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Restore testing plan does not exist.",
  "eventCategory": "Management",
  "eventID": "25f17e8c-c446-4ddd-8abb-4e365d529bef",
  "eventName": "DeleteRestoreTestingSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5c254d1a-a229-4054-b6cf-148b876229be",
  "requestParameters": {
    "restoreTestingPlanName": "dw-probe",
    "restoreTestingSelectionName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTieringConfiguration

#
Service
backup

Description

Deletes the tiering configuration specified by a tiering configuration name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "f5eb3d53-b3a9-4004-a1c8-3497e0687419",
  "eventName": "DeleteTieringConfiguration",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "619d6bd4-f423-423a-a26f-f070458b1950",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeBackupJob

#
Service
backup

Description

Returns backup job details for the specified BackupJobId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The BackupJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
  "eventCategory": "Management",
  "eventID": "6c83b091-16a8-4691-97e9-b35ae0bd4e30",
  "eventName": "DescribeBackupJob",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "65552fec-b8e9-46a9-a1e0-0d5463ae703f",
  "requestParameters": {
    "backupJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeBackupVault

#
Service
backup

Description

Returns metadata about a backup vault specified by its name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "9554ea88-8798-470f-9570-01b9e0b54e64",
  "eventName": "DescribeBackupVault",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "195cecf5-f154-4905-a71b-93fd37364766",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCopyJob

#
Service
backup

Description

Returns metadata associated with creating a copy of a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The CopyJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
  "eventCategory": "Management",
  "eventID": "ab992d36-33c4-41e2-9ae9-f4d0c03f9749",
  "eventName": "DescribeCopyJob",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0e087da8-0165-469d-9a58-4829d5e8f089",
  "requestParameters": {
    "copyJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeFramework

#
Service
backup

Description

Returns the framework details for the specified FrameworkName.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Framework ddddd not found in account 123456789012.",
  "eventCategory": "Management",
  "eventID": "d50033cc-4510-440f-9c07-8890d0eac7e6",
  "eventName": "DescribeFramework",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9921454e-dbcf-4777-961b-903b3cc9fa05",
  "requestParameters": {
    "frameworkName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeGlobalSettings

#
Service
backup

Description

Describes whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidRequestException",
  "errorMessage": "Your account is not a member of an organization.",
  "eventCategory": "Management",
  "eventID": "a72b3d44-1128-40f0-a19a-5a1756996c45",
  "eventName": "DescribeGlobalSettings",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ede1e755-d017-4ac6-b00e-6d5f5a985582",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeProtectedResource

#
Service
backup

Description

Returns information about a saved resource, including the last time it was backed up, its Amazon Resource Name (ARN), and the Amazon Web Services service type of the saved resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Cannot find protected resource",
  "eventCategory": "Management",
  "eventID": "b229fc67-77bb-4291-a208-8dc527c5c6f9",
  "eventName": "DescribeProtectedResource",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "aecc062a-1035-483d-a294-945ec62599f5",
  "requestParameters": {
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRecoveryPoint

#
Service
backup

Description

Returns metadata associated with a recovery point, including ID, status, encryption, and lifecycle.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "99119cb4-5e56-4021-8a4c-0df8136af9d9",
  "eventName": "DescribeRecoveryPoint",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "fb1cf4c3-441c-4342-8eea-4915e1fca139",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRegionSettings

#
Service
backup

Description

Returns the current service opt-in settings for the Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2b2e11e0-f6fa-4481-94e1-a7f585d8b7f5",
  "eventName": "DescribeRegionSettings",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6f0a20b4-9d70-4275-bf09-b26916208dfb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeReportJob

#
Service
backup

Description

Returns the details associated with creating a report as specified by its ReportJobId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid report job ID dw-probe. The report job ID must be a valid UUID.",
  "eventCategory": "Management",
  "eventID": "37658775-3b08-4f60-9930-e673732b6837",
  "eventName": "DescribeReportJob",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "80477185-1027-4747-b00f-98ca1cc1aa53",
  "requestParameters": {
    "reportJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeReportPlan

#
Service
backup

Description

Returns a list of all report plans for an Amazon Web Services account and Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Report plan ddddd not found in account 123456789012.",
  "eventCategory": "Management",
  "eventID": "cb8ea29c-e2be-4267-946d-795262ebe31c",
  "eventName": "DescribeReportPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f5d710ac-09b0-4d9a-b352-12dbe498a55f",
  "requestParameters": {
    "reportPlanName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRestoreJob

#
Service
backup

Description

Returns metadata associated with a restore job that is specified by a job ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The RestoreJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
  "eventCategory": "Management",
  "eventID": "58710861-89e4-4d89-9359-b36c54bc2dda",
  "eventName": "DescribeRestoreJob",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "abfd2548-6429-4d18-bcc3-9bb19229fa7c",
  "requestParameters": {
    "restoreJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeScanJob

#
Service
backup

Description

Returns scan job details for the specified ScanJobID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Scan Job Id is invalid",
  "eventCategory": "Management",
  "eventID": "62dda959-442d-48ae-903b-47c3561cd9a9",
  "eventName": "DescribeScanJob",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a8f401d4-66ac-4b2e-961e-83d10c47fce4",
  "requestParameters": {
    "scanJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateBackupVaultMpaApprovalTeam

#
Service
backup

Description

Removes the association between an MPA approval team and a backup vault, disabling the MPA approval workflow for restore operations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "6166c38f-56e4-4b33-a367-83d575c5bd20",
  "eventName": "DisassociateBackupVaultMpaApprovalTeam",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "257cb44f-9bf0-469a-a1bd-a0fb813d7c39",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateRecoveryPoint

#
Service
backup

Description

Deletes the specified continuous backup recovery point from Backup and releases control of that continuous backup to the source service, such as Amazon RDS.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "1cc82b8d-2df9-4eba-8259-f1af2c6e4e49",
  "eventName": "DisassociateRecoveryPoint",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8ac15e0d-e69b-48fd-976e-aa7ea4a52d33",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateRecoveryPointFromParent

#
Service
backup

Description

This action to a specific child (nested) recovery point removes the relationship between the specified recovery point and its parent (composite) recovery point.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "fbcd83c7-d95e-4d29-a397-b444d251294b",
  "eventName": "DisassociateRecoveryPointFromParent",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ccb72e18-fad5-4bbf-bb23-0cf5d308b4ff",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ExportBackupPlanTemplate

#
Service
backup

Description

Returns the backup plan that is specified by the plan ID as a backup template.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3b07dc2c-8add-446e-ad14-69e5bcac05c1",
  "eventName": "ExportBackupPlanTemplate",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "16255240-762d-48d2-89ac-37c9245db9e8",
  "requestParameters": {
    "backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBackupPlan

#
Service
backup

Description

Returns BackupPlan details for the specified BackupPlanId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup plan ID",
  "eventCategory": "Management",
  "eventID": "ca76e96c-8fb4-45ec-bc0c-020a50119892",
  "eventName": "GetBackupPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c0af4e54-de64-4ab2-8f64-bcd725dfc77f",
  "requestParameters": {
    "backupPlanId": "dw-probe",
    "maxScheduledRunsPreview": 0
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBackupPlanFromJSON

#
Service
backup

Description

Returns a valid JSON document specifying a backup plan or an error.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Failed to de-serialize backup plan template.",
  "eventCategory": "Management",
  "eventID": "6e74d7a1-0796-40c3-8f08-660c86a50287",
  "eventName": "GetBackupPlanFromJSON",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "85fd0464-f00e-4e35-b0ce-6b398d688b1c",
  "requestParameters": {
    "backupPlanTemplateJson": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBackupPlanFromTemplate

#
Service
backup

Description

Returns the template specified by its templateId as a backup plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup plan template ID",
  "eventCategory": "Management",
  "eventID": "5aa2c137-4d4b-442c-a878-96fdab1ed293",
  "eventName": "GetBackupPlanFromTemplate",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f14bb997-df28-482e-be78-b5f520d53761",
  "requestParameters": {
    "backupPlanTemplateId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBackupSelection

#
Service
backup

Description

Returns selection metadata and a document in JSON format that specifies a list of resources that are associated with a backup plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup selection ID",
  "eventCategory": "Management",
  "eventID": "859e12e9-1667-47d0-a10e-515f5a23d9cf",
  "eventName": "GetBackupSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "eaaf7f09-4749-424c-b790-6ffb5866816a",
  "requestParameters": {
    "backupPlanId": "dw-probe",
    "selectionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBackupVaultAccessPolicy

#
Service
backup

Description

Returns the access policy document that is associated with the named backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "947c1b3a-3dac-45cc-8be3-a5827c76a14e",
  "eventName": "GetBackupVaultAccessPolicy",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "27e3f583-309f-4220-bda8-b3befec8c55d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBackupVaultNotifications

#
Service
backup

Description

Returns event notifications for the specified backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "647b2db8-a87c-4822-8c03-d7b8e717ef02",
  "eventName": "GetBackupVaultNotifications",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "455091e4-38b4-49d2-b562-5f501e9e7316",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetLegalHold

#
Service
backup

Description

This action returns details for a specified legal hold.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Can not find Legal Hold ARN.",
  "eventCategory": "Management",
  "eventID": "62a761da-cbad-4de5-90d1-b7358b188fcc",
  "eventName": "GetLegalHold",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c28ec7ab-2334-42e6-9d4d-028cabed8919",
  "requestParameters": {
    "legalHoldId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetPITRMalwareScanResults

#
Service
backup

Description

Returns the malware scan results for a specified point in time within a continuous (point-in-time recovery) backup.

GetRecoveryPointIndexDetails

#
Service
backup

Description

This operation returns the metadata and details specific to the backup index associated with the specified recovery point.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "b035c45c-b17f-4287-8847-79b5e03d0617",
  "eventName": "GetRecoveryPointIndexDetails",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f749ffb5-88c5-436d-a3ad-359d7370af3b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRecoveryPointRestoreMetadata

#
Service
backup

Description

Returns a set of metadata key-value pairs that were used to create the backup.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "9faeabb4-c098-4bbe-9013-2c581368bd49",
  "eventName": "GetRecoveryPointRestoreMetadata",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9a7582c2-dd3c-4659-b1e6-c6a8d2d071f5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRestoreJobMetadata

#
Service
backup

Description

This request returns the metadata for the specified restore job.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The RestoreJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
  "eventCategory": "Management",
  "eventID": "caca1414-fbca-4296-b66f-ced97c8f8f1f",
  "eventName": "GetRestoreJobMetadata",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3029f6ac-6f66-49a1-b9a3-bb31d8604a72",
  "requestParameters": {
    "restoreJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRestoreTestingInferredMetadata

#
Service
backup

Description

This request returns the minimal required set of metadata needed to start a restore job with secure default settings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid ARN.",
  "eventCategory": "Management",
  "eventID": "da31b66e-da47-42d8-a25e-8eb61645889e",
  "eventName": "GetRestoreTestingInferredMetadata",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2d94f9a2-4e49-4e21-9bd7-47f432be39d4",
  "requestParameters": {
    "backupVaultName": "dw-probe",
    "recoveryPointArn": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRestoreTestingPlan

#
Service
backup

Description

Returns RestoreTestingPlan details for the specified RestoreTestingPlanName.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Restore testing plan does not exist.",
  "eventCategory": "Management",
  "eventID": "56e8a2c8-5bf3-4b9d-b8de-5d2faf4f5079",
  "eventName": "GetRestoreTestingPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "732ca995-115a-4ebe-b7cc-4fd93171fb7a",
  "requestParameters": {
    "restoreTestingPlanName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRestoreTestingSelection

#
Service
backup

Description

Returns RestoreTestingSelection, which displays resources and elements of the restore testing plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Restore testing plan does not exist.",
  "eventCategory": "Management",
  "eventID": "df6d2a83-3fbf-48e2-9a81-2478b3c933b0",
  "eventName": "GetRestoreTestingSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c8f799fd-9378-423a-bc72-f4f32332e863",
  "requestParameters": {
    "restoreTestingPlanName": "dw-probe",
    "restoreTestingSelectionName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSupportedResourceTypes

#
Service
backup

Description

Returns the Amazon Web Services resource types supported by Backup.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ebfdde5a-76e7-48d5-8df8-57411990749d",
  "eventName": "GetSupportedResourceTypes",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e01219ba-1fb0-4ef5-8395-d52bb46b5825",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTieringConfiguration

#
Service
backup

Description

Returns TieringConfiguration details for the specified TieringConfigurationName.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "0b27f3d5-8788-44b0-91a1-e0ac970f7e84",
  "eventName": "GetTieringConfiguration",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0d1ff51e-7a51-4487-b220-db7b98e9ba83",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupJobs

#
Service
backup

Description

Returns a list of existing backup jobs for an authenticated account for the last 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ed6a806d-8f45-49ce-a500-583329ac407c",
  "eventName": "ListBackupJobs",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "14fdf920-ece8-4c83-a83b-51f10bc46568",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupJobSummaries

#
Service
backup

Description

This is a request for a summary of backup jobs created or running within the most recent 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a283bb63-1937-41df-8a0c-f21f163dbb6d",
  "eventName": "ListBackupJobSummaries",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b0bb1a7a-e823-4232-b5d3-8bef39111b8a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupPlans

#
Service
backup

Description

Lists the active backup plans for the account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b1ba92fd-4cad-4b3f-8b79-93de1834c185",
  "eventName": "ListBackupPlans",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bfbaaad0-ae87-49d2-abf8-7b1f7324dca8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupPlanTemplates

#
Service
backup

Description

Lists the backup plan templates.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1982654d-b84e-4b53-9c15-86e2368ce0c8",
  "eventName": "ListBackupPlanTemplates",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0f7a8fb5-4f3d-4782-b746-b3ea4b9e0e87",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupPlanVersions

#
Service
backup

Description

Returns version metadata of your backup plans, including Amazon Resource Names (ARNs), backup plan IDs, creation and deletion dates, plan names, and version IDs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup plan ID",
  "eventCategory": "Management",
  "eventID": "8da42752-5e1e-4a7a-936a-44cc6ed8d243",
  "eventName": "ListBackupPlanVersions",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d66b5458-1389-4f75-b4c5-a517c06d4992",
  "requestParameters": {
    "backupPlanId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupSelections

#
Service
backup

Description

Returns an array containing metadata of the resources associated with the target backup plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Invalid Backup plan ID",
  "eventCategory": "Management",
  "eventID": "fb049a9f-16cd-427f-849c-2ea75a2af550",
  "eventName": "ListBackupSelections",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c277ae1e-a69c-4c22-b31a-84f288bac5b5",
  "requestParameters": {
    "backupPlanId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListBackupVaults

#
Service
backup

Description

Returns a list of recovery point storage containers along with information about them.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0ddb82a5-3c76-4fda-8236-e7ed93049657",
  "eventName": "ListBackupVaults",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "976c86bc-841a-4e69-bf13-2b9171a6e455",
  "requestParameters": {
    "byShared": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListCopyJobs

#
Service
backup

Description

Returns metadata about your copy jobs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "94f02afc-c212-47dd-8128-8045d1da2b5a",
  "eventName": "ListCopyJobs",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "61a3f60d-8803-4462-a819-21cad32da5c7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListCopyJobSummaries

#
Service
backup

Description

This request obtains a list of copy jobs created or running within the the most recent 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "259b06fa-854b-4d34-b198-59f01690f8e7",
  "eventName": "ListCopyJobSummaries",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "22a1bd33-c5c1-4963-b6ae-1fed5583f9b8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListFrameworks

#
Service
backup

Description

Returns a list of all frameworks for an Amazon Web Services account and Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6cb9cdf2-485e-45f3-aca8-41ae9628abd3",
  "eventName": "ListFrameworks",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "01235869-7331-402c-9ef7-095188eb17bb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListIndexedRecoveryPoints

#
Service
backup

Description

This operation returns a list of recovery points that have an associated index, belonging to the specified account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "799e7375-e577-4f9d-b378-4ec284419b54",
  "eventName": "ListIndexedRecoveryPoints",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "672c93a1-c9c2-4601-a58a-a49a57f79dc3",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListLegalHolds

#
Service
backup

Description

This action returns metadata about active and previous legal holds.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cb5edf02-5ef4-4ae8-abab-9866fbb5bd64",
  "eventName": "ListLegalHolds",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "70ba57fb-003f-4ca8-9c54-bf301b8d7ae5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListProtectedResources

#
Service
backup

Description

Returns an array of resources successfully backed up by Backup, including the time the resource was saved, an Amazon Resource Name (ARN) of the resource, and a resource type.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7af2058f-5b4c-4563-99d3-d92e3af18ccf",
  "eventName": "ListProtectedResources",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "020a08c0-216b-425f-bf12-31e14c335f53",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListProtectedResourcesByBackupVault

#
Service
backup

Description

This request lists the protected resources corresponding to each backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "92fc87e5-c008-407b-85f5-46d301d634e2",
  "eventName": "ListProtectedResourcesByBackupVault",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "75810d9d-557b-476a-8aac-4b7c0e41338d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRecoveryPointsByBackupVault

#
Service
backup

Description

Returns detailed information about the recovery points stored in a backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "6b8e634b-9799-4a2b-8ca3-88c71680de13",
  "eventName": "ListRecoveryPointsByBackupVault",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ecdd56ed-9bae-4bbf-b538-6366dedc97a0",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRecoveryPointsByLegalHold

#
Service
backup

Description

This action returns recovery point ARNs (Amazon Resource Names) of the specified legal hold.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Can not find Legal Hold ARN.",
  "eventCategory": "Management",
  "eventID": "6b7fafb3-e362-4368-bf56-c1c46b59b6ba",
  "eventName": "ListRecoveryPointsByLegalHold",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1d80fd78-56a4-4071-8606-73cbd95bfcf3",
  "requestParameters": {
    "legalHoldId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRecoveryPointsByResource

#
Service
backup

Description

The information about the recovery points of the type specified by a resource Amazon Resource Name (ARN).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The resource is not supported",
  "eventCategory": "Management",
  "eventID": "372b62ab-3520-4a55-bab4-69106c7adc91",
  "eventName": "ListRecoveryPointsByResource",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "67570a20-96bb-4552-8b53-6dfd2ea5a250",
  "requestParameters": {
    "managedByAWSBackupOnly": false,
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListReportJobs

#
Service
backup

Description

Returns details about your report jobs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "308767af-2739-48ea-89d4-73628a3b55a9",
  "eventName": "ListReportJobs",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "aab03637-bd71-492c-89d5-a8c0a9cbb67c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListReportPlans

#
Service
backup

Description

Returns a list of your report plans.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "245c3005-838e-45c0-9ccb-259222769704",
  "eventName": "ListReportPlans",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "10b8c380-b704-4282-8370-5ddbff412ace",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRestoreAccessBackupVaults

#
Service
backup

Description

Returns a list of restore access backup vaults associated with a specified backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "83fadc90-29c6-4596-b10f-fc56fdf183b8",
  "eventName": "ListRestoreAccessBackupVaults",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a265cec3-ce5d-4cba-9ad6-2d96d5321ab9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRestoreJobs

#
Service
backup

Description

Returns a list of jobs that Backup initiated to restore a saved resource, including details about the recovery process.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "15246923-8359-41e7-a60f-c52a39f58223",
  "eventName": "ListRestoreJobs",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "293da690-30d4-4f1f-9932-0dc96c6db5f7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRestoreJobsByProtectedResource

#
Service
backup

Description

This returns restore jobs that contain the specified protected resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f3634321-b288-4820-b4de-c31f070e805d",
  "eventName": "ListRestoreJobsByProtectedResource",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e6543260-6047-4866-8544-bf4b8875d010",
  "requestParameters": {
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRestoreJobSummaries

#
Service
backup

Description

This request obtains a summary of restore jobs created or running within the the most recent 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c7bd7a93-0807-42e6-bfcf-a6e7ee460d68",
  "eventName": "ListRestoreJobSummaries",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "32f97a2e-7d9e-4fb8-946d-35cdc87f3122",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRestoreTestingPlans

#
Service
backup

Description

Returns a list of restore testing plans.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "5c50a491-4376-48a9-9b62-4f89b1163ae6",
  "eventName": "ListRestoreTestingPlans",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1b0ed01d-481b-441b-88f3-9e430f47ffab",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListRestoreTestingSelections

#
Service
backup

Description

Returns a list of restore testing selections.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Restore testing plan does not exist.",
  "eventCategory": "Management",
  "eventID": "d79f78c7-69b4-499d-9062-ccf04d6e2757",
  "eventName": "ListRestoreTestingSelections",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a87d0e66-3228-4f6d-a61d-f6fe9cc14b71",
  "requestParameters": {
    "restoreTestingPlanName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListScanJobs

#
Service
backup

Description

Returns a list of existing scan jobs for an authenticated account for the last 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "aec0eb56-2d08-4cdd-853c-15e82ddc47fb",
  "eventName": "ListScanJobs",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c4af8106-3cdd-42ac-b2f9-56dbf7ef10be",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListScanJobSummaries

#
Service
backup

Description

This is a request for a summary of scan jobs created or running within the most recent 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Input MalwareScanner must be specified.",
  "eventCategory": "Management",
  "eventID": "ae32fa28-d661-4ea0-91fb-25dad2809d9b",
  "eventName": "ListScanJobSummaries",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "062206ee-2114-4ddf-bf15-b6a3cc49fb51",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTags

#
Service
backup

Description

Returns the tags assigned to the resource, such as a target recovery point, backup plan, or backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Cannot find recovery point",
  "eventCategory": "Management",
  "eventID": "d2d76792-4be3-49ea-9414-b7c4a8ad7e85",
  "eventName": "ListTags",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:42:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0d3a9b9b-4331-4316-ae54-bfd59cdf2b8c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTieringConfigurations

#
Service
backup

Description

Returns a list of tiering configurations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "176b04d0-bbbf-45eb-8c3d-aca8814d19bd",
  "eventName": "ListTieringConfigurations",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T18:31:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5703f9dd-f01a-4e79-953f-8ea0f46ab3b7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBackupVaultAccessPolicy

#
Service
backup

Description

Sets a resource-based policy that is used to manage access permissions on the target backup vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Policy statement action out of service scope!",
  "eventCategory": "Management",
  "eventID": "28ad446e-7847-41d4-9abe-e43579345d82",
  "eventName": "PutBackupVaultAccessPolicy",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bd3f4d5f-fae1-452a-ad58-6e96c7e5c7bf",
  "requestParameters": {
    "backupVaultName": "dwfix-vault-bz9vn61lmy",
    "policy": {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "AllowAccountRoot",
          "Effect": "Allow",
          "Principal": {
            "AWS": "arn:aws:iam::123456789012:root"
          },
          "Action": "backup:*",
          "Resource": "*"
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBackupVaultLockConfiguration

#
Service
backup

Description

Applies Backup Vault Lock to a backup vault, preventing attempts to delete any recovery point stored in or created in a backup vault.

PutBackupVaultNotifications

#
Service
backup

Description

Turns on notifications on a backup vault for the specified topic and events.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "91bab691-6bee-49d7-8bea-a0adef54c7a4",
  "eventName": "PutBackupVaultNotifications",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9b22b34c-77f6-4529-8c68-2182a7e55294",
  "requestParameters": {
    "backupVaultEvents": [
      "BACKUP_JOB_STARTED",
      "BACKUP_JOB_COMPLETED",
      "RESTORE_JOB_STARTED",
      "RESTORE_JOB_COMPLETED"
    ],
    "backupVaultName": "dwfix-vault-bz9vn61lmy",
    "sNSTopicArn": "arn:aws:sns:us-west-1:123456789012:dwfix-nonexistent-topic-bz9vn61lmy"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutRestoreValidationResult

#
Service
backup

Description

This request allows you to send your independent self-run restore test validation results.

RevokeRestoreAccessBackupVault

#
Service
backup

Description

Revokes access to a restore access backup vault, removing the ability to restore from its recovery points and permanently deleting the vault.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "f177d21d-a5a5-4a44-aee3-a78a54cc411e",
  "eventName": "RevokeRestoreAccessBackupVault",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5c65f545-5a84-4b62-87bd-4056b01497cd",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartBackupJob

#
Service
backup

Description

Starts an on-demand backup job for the specified resource.

StartCopyJob

#
Service
backup

Description

Starts a job to create a one-time copy of the specified resource.

StartReportJob

#
Service
backup

Description

Starts an on-demand report job for the specified report plan.

StartRestoreJob

#
Service
backup

Description

Recovers the saved resource identified by an Amazon Resource Name (ARN).

StartScanJob

#
Service
backup

Description

Starts scanning jobs for specific resources.

StopBackupJob

#
Service
backup

Description

Attempts to cancel a job to create a one-time backup of a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "The BackupJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
  "eventCategory": "Management",
  "eventID": "18741e0f-f005-4065-9ca9-b68f011cf395",
  "eventName": "StopBackupJob",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "65f57c10-b7b3-41e7-b127-7bba555ad35a",
  "requestParameters": {
    "backupJobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TagResource

#
Service
backup

Description

Assigns a set of key-value pairs to a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "375abbf7-a123-4ae2-a54b-0f1e128d05de",
  "eventName": "TagResource",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T21:01:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "05c1feb5-be09-46a8-95a5-06c2e08d90ba",
  "requestParameters": {
    "resourceArn": "arn:aws:backup:us-west-1:123456789012:backup-vault:dwfix-vault-bz9vn61lmy",
    "tags": "HIDDEN_DUE_TO_SECURITY_REASONS"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UntagResource

#
Service
backup

Description

Removes a set of key-value pairs from a recovery point, backup plan, or backup vault identified by an Amazon Resource Name (ARN) This API is not supported for recovery points for resource types including Aurora, Amazon DocumentDB.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Cannot find recovery point",
  "eventCategory": "Management",
  "eventID": "7660e3ba-bb60-40ce-ae87-582a58c1aff1",
  "eventName": "UntagResource",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "23aadfda-7bb7-48b9-9fea-fb3d38bf5275",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateBackupPlan

#
Service
backup

Description

Updates the specified backup plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "A Backup vault does not exist",
  "eventCategory": "Management",
  "eventID": "f40d2ea4-c447-49b1-8505-f145112188d7",
  "eventName": "UpdateBackupPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7eaf5661-25b2-4e7a-95b6-34b1642e4162",
  "requestParameters": {
    "backupPlan": {
      "backupPlanName": "dw-probe",
      "rules": [
        {
          "ruleName": "dw-probe",
          "targetBackupVaultName": "dw-probe"
        }
      ]
    },
    "backupPlanId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateFramework

#
Service
backup

Description

Updates the specified framework.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Framework ddddd not found in account 123456789012.",
  "eventCategory": "Management",
  "eventID": "91728a98-5799-4f38-97e0-b8a863eb31af",
  "eventName": "UpdateFramework",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3d2ec6dd-e41f-4aa0-8ec3-4667935cf484",
  "requestParameters": {
    "frameworkName": "ddddd",
    "idempotencyToken": "6b91d7cb-9fe4-4f30-9fbc-a682bb1c0cc2"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateGlobalSettings

#
Service
backup

Description

Updates whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator.

UpdateRecoveryPointIndexSettings

#
Service
backup

Description

This operation updates the settings of a recovery point index.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "840caebc-e6f7-4721-b3d8-c6789e57633e",
  "eventName": "UpdateRecoveryPointIndexSettings",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6a3f22d5-b563-4f1c-a4e4-68e19dae43be",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRecoveryPointLifecycle

#
Service
backup

Description

Sets the transition lifecycle of a recovery point.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "e93e3a87-10de-454c-afcf-76d561d51434",
  "eventName": "UpdateRecoveryPointLifecycle",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e59ea024-be89-4a5d-b8c8-d50987d45d46",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRegionSettings

#
Service
backup

Description

Updates the current service opt-in settings for the Region.

UpdateReportPlan

#
Service
backup

Description

Updates the specified report plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Report plan ddddd not found in account 123456789012.",
  "eventCategory": "Management",
  "eventID": "2c78c09f-40b9-42ca-94ff-63823c1bdffe",
  "eventName": "UpdateReportPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b27bb1da-7bfb-4227-86b1-a3aac5e08a67",
  "requestParameters": {
    "idempotencyToken": "f66538a6-d026-4e15-a6ab-e7e5b51390ef",
    "reportPlanName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRestoreTestingPlan

#
Service
backup

Description

This request will send changes to your specified restore testing plan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Restore testing plan does not exist.",
  "eventCategory": "Management",
  "eventID": "be505984-c9a4-4c5e-ba80-176930290db0",
  "eventName": "UpdateRestoreTestingPlan",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9b1f3ecc-1579-4c6b-bef4-176c1e29e756",
  "requestParameters": {
    "restoreTestingPlan": {},
    "restoreTestingPlanName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRestoreTestingSelection

#
Service
backup

Description

Updates the specified restore testing selection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Restore testing plan does not exist.",
  "eventCategory": "Management",
  "eventID": "162eb16f-18c2-40e1-9b86-4811d9b93a8e",
  "eventName": "UpdateRestoreTestingSelection",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "11ca4eef-f183-4927-bb54-76a221a10e2a",
  "requestParameters": {
    "restoreTestingPlanName": "dw-probe",
    "restoreTestingSelection": {},
    "restoreTestingSelectionName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateTieringConfiguration

#
Service
backup

Description

This request will send changes to your specified tiering configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Insufficient privileges to perform this action.",
  "eventCategory": "Management",
  "eventID": "66323dec-f10d-46a8-9e6d-293598a055c7",
  "eventName": "UpdateTieringConfiguration",
  "eventSource": "backup.amazonaws.com",
  "eventTime": "2026-06-29T19:21:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4cd6f3dd-f0a6-4d4c-84a3-6e25cd0f442a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AuthorizeRecoveryPointTagging

#
Service
backup

Description

AuthorizeRecoveryPointTagging recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b3942999-3d8e-4034-bf45-fc50a27ed996",
  "eventSource": "backup.amazonaws.com",
  "eventName": "AuthorizeRecoveryPointTagging",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "d5c7d243-3f58-405f-b53d-bde7ab461606",
  "userAgent": "backup.amazonaws.com"
}

BackupDeleted

#
Service
backup

Description

BackupDeleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0070aa7d-c9a2-491a-8d9b-c37b2bdbaed8",
  "eventSource": "backup.amazonaws.com",
  "eventName": "BackupDeleted",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

BackupJobCompleted

#
Service
backup

Description

BackupJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "28c99464-152c-4ace-a3f9-b9b7e7266ae1",
  "eventSource": "backup.amazonaws.com",
  "eventName": "BackupJobCompleted",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

BackupJobStarted

#
Service
backup

Description

BackupJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "69ac8cf0-04c7-4830-b5cf-9fe40e68dbe9",
  "eventSource": "backup.amazonaws.com",
  "eventName": "BackupJobStarted",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

COPY_JOB_COMPLETED

#
Service
backup

Description

COPY_JOB_COMPLETED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "089a6937-b45c-45eb-804f-88d8d817ca16",
  "eventSource": "backup.amazonaws.com",
  "eventName": "COPY_JOB_COMPLETED",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

COPY_JOB_STARTED

#
Service
backup

Description

COPY_JOB_STARTED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ee3c7d77-4786-4871-9089-80fc8015ccc0",
  "eventSource": "backup.amazonaws.com",
  "eventName": "COPY_JOB_STARTED",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

CopyJobCompleted

#
Service
backup

Description

CopyJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "69f61732-58ea-48bb-9cb6-d7468a98331d",
  "eventSource": "backup.amazonaws.com",
  "eventName": "CopyJobCompleted",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

CopyJobStarted

#
Service
backup

Description

CopyJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d0d29b30-5843-4334-b949-3083970e7785",
  "eventSource": "backup.amazonaws.com",
  "eventName": "CopyJobStarted",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

RecoveryPointCreated

#
Service
backup

Description

RecoveryPointCreated recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "59d51e4c-a26f-4cf4-9c5e-6e1f4ab93e78",
  "eventSource": "backup.amazonaws.com",
  "eventName": "RecoveryPointCreated",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "backup.amazonaws.com"
}

CreateBackupAccessPoint

#
Service
backup

Description

Creates a backup access point for an Amazon S3 recovery point.

DeleteBackupAccessPoint

#
Service
backup

Description

Deletes a backup access point.

DescribeBackupAccessPoint

#
Service
backup

Description

Returns metadata about a backup access point, including its status and the details of the underlying Amazon S3 access point.

ListBackupAccessPoints

#
Service
backup

Description

Returns a list of the backup access points in your account and Region.

ListBackupAccessPointsByRecoveryPoint

#
Service
backup

Description

Returns the backup access points associated with the specified recovery point.

ListBackupAccessPointsByResource

#
Service
backup

Description

Returns the backup access points associated with the specified resource, such as an Amazon S3 bucket.