AWS Backup
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS Backup rules that match the service but not a specific eventName. | N | N |
| Delete | Deletes a backup plan, removing all scheduled backup rules and preventing future automatic backups under that plan. | Y | Y |
| Delete | Removes a resource assignment (selection) from a backup plan, stopping the plan from protecting the specified resources. | Y | Y |
| Associate | Associates an MPA approval team with a backup vault. | N | N |
| Cancel | Removes the specified legal hold on a recovery point. | Y | N |
| Create | Creates a backup plan using a backup plan name and backup rules. | Y | N |
| Create | Creates a JSON document that specifies a set of resources to assign to a backup plan. | Y | N |
| Create | Creates a logical container where backups are stored. | Y | N |
| Create | Creates a framework with one or more controls. | Y | N |
| Create | Creates a legal hold on a recovery point (backup). | Y | N |
| Create | Creates a logical container to where backups may be copied. | N | N |
| Create | Creates a report plan. | N | N |
| Create | Creates a restore access backup vault that provides temporary access to recovery points in a logically air-gapped backup vault, subject to MPA approval. | N | N |
| Create | Creates a restore testing plan. | Y | N |
| Create | This request can be sent after CreateRestoreTestingPlan request returns successfully. | Y | N |
| Create | Creates a tiering configuration. | N | N |
| Delete | Deletes the backup vault identified by its name. | Y | Y |
| Delete | Deletes the policy document that manages permissions on a backup vault. | Y | N |
| Delete | Deletes Backup Vault Lock from a backup vault specified by a backup vault name. | Y | Y |
| Delete | Deletes event notifications for the specified backup vault. | Y | N |
| Delete | Deletes the framework specified by a framework name. | Y | N |
| Delete | Deletes the recovery point specified by a recovery point ID. | Y | Y |
| Delete | Deletes the report plan specified by a report plan name. | Y | N |
| Delete | This request deletes the specified restore testing plan. | Y | N |
| Delete | Input the Restore Testing Plan name and Restore Testing Selection name. | Y | N |
| Delete | Deletes the tiering configuration specified by a tiering configuration name. | Y | N |
| Describe | Returns backup job details for the specified BackupJobId. | Y | N |
| Describe | Returns metadata about a backup vault specified by its name. | Y | N |
| Describe | Returns metadata associated with creating a copy of a resource. | Y | N |
| Describe | Returns the framework details for the specified FrameworkName. | Y | N |
| Describe | Describes whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator. | Y | N |
| Describe | Returns information about a saved resource, including the last time it was backed up, its Amazon Resource Name (ARN), and the Amazon Web Services service type of the saved resource. | Y | N |
| Describe | Returns metadata associated with a recovery point, including ID, status, encryption, and lifecycle. | Y | N |
| Describe | Returns the current service opt-in settings for the Region. | Y | N |
| Describe | Returns the details associated with creating a report as specified by its ReportJobId. | Y | N |
| Describe | Returns a list of all report plans for an Amazon Web Services account and Amazon Web Services Region. | Y | N |
| Describe | Returns metadata associated with a restore job that is specified by a job ID. | Y | N |
| Describe | Returns scan job details for the specified ScanJobID. | Y | N |
| Disassociate | Removes the association between an MPA approval team and a backup vault, disabling the MPA approval workflow for restore operations. | Y | N |
| Disassociate | Deletes the specified continuous backup recovery point from Backup and releases control of that continuous backup to the source service, such as Amazon RDS. | Y | N |
| Disassociate | This action to a specific child (nested) recovery point removes the relationship between the specified recovery point and its parent (composite) recovery point. | Y | N |
| Export | Returns the backup plan that is specified by the plan ID as a backup template. | Y | N |
| Get | Returns BackupPlan details for the specified BackupPlanId. | Y | N |
| Get | Returns a valid JSON document specifying a backup plan or an error. | Y | N |
| Get | Returns the template specified by its templateId as a backup plan. | Y | N |
| Get | Returns selection metadata and a document in JSON format that specifies a list of resources that are associated with a backup plan. | Y | N |
| Get | Returns the access policy document that is associated with the named backup vault. | Y | N |
| Get | Returns event notifications for the specified backup vault. | Y | N |
| Get | This action returns details for a specified legal hold. | Y | N |
| Get | Returns the malware scan results for a specified point in time within a continuous (point-in-time recovery) backup. | N | N |
| Get | This operation returns the metadata and details specific to the backup index associated with the specified recovery point. | Y | N |
| Get | Returns a set of metadata key-value pairs that were used to create the backup. | Y | N |
| Get | This request returns the metadata for the specified restore job. | Y | N |
| Get | This request returns the minimal required set of metadata needed to start a restore job with secure default settings. | Y | N |
| Get | Returns RestoreTestingPlan details for the specified RestoreTestingPlanName. | Y | N |
| Get | Returns RestoreTestingSelection, which displays resources and elements of the restore testing plan. | Y | N |
| Get | Returns the Amazon Web Services resource types supported by Backup. | Y | N |
| Get | Returns TieringConfiguration details for the specified TieringConfigurationName. | Y | N |
| List | Returns a list of existing backup jobs for an authenticated account for the last 30 days. | Y | N |
| List | This is a request for a summary of backup jobs created or running within the most recent 30 days. | Y | N |
| List | Lists the active backup plans for the account. | Y | N |
| List | Lists the backup plan templates. | Y | N |
| List | Returns version metadata of your backup plans, including Amazon Resource Names (ARNs), backup plan IDs, creation and deletion dates, plan names, and version IDs. | Y | N |
| List | Returns an array containing metadata of the resources associated with the target backup plan. | Y | N |
| List | Returns a list of recovery point storage containers along with information about them. | Y | N |
| List | Returns metadata about your copy jobs. | Y | N |
| List | This request obtains a list of copy jobs created or running within the the most recent 30 days. | Y | N |
| List | Returns a list of all frameworks for an Amazon Web Services account and Amazon Web Services Region. | Y | N |
| List | This operation returns a list of recovery points that have an associated index, belonging to the specified account. | Y | N |
| List | This action returns metadata about active and previous legal holds. | Y | N |
| List | Returns an array of resources successfully backed up by Backup, including the time the resource was saved, an Amazon Resource Name (ARN) of the resource, and a resource type. | Y | N |
| List | This request lists the protected resources corresponding to each backup vault. | Y | N |
| List | Returns detailed information about the recovery points stored in a backup vault. | Y | N |
| List | This action returns recovery point ARNs (Amazon Resource Names) of the specified legal hold. | Y | N |
| List | The information about the recovery points of the type specified by a resource Amazon Resource Name (ARN). | Y | N |
| List | Returns details about your report jobs. | Y | N |
| List | Returns a list of your report plans. | Y | N |
| List | Returns a list of restore access backup vaults associated with a specified backup vault. | Y | N |
| List | Returns a list of jobs that Backup initiated to restore a saved resource, including details about the recovery process. | Y | N |
| List | This returns restore jobs that contain the specified protected resource. | Y | N |
| List | This request obtains a summary of restore jobs created or running within the the most recent 30 days. | Y | N |
| List | Returns a list of restore testing plans. | Y | N |
| List | Returns a list of restore testing selections. | Y | N |
| List | Returns a list of existing scan jobs for an authenticated account for the last 30 days. | Y | N |
| List | This is a request for a summary of scan jobs created or running within the most recent 30 days. | Y | N |
| List | Returns the tags assigned to the resource, such as a target recovery point, backup plan, or backup vault. | Y | N |
| List | Returns a list of tiering configurations. | Y | N |
| Put | Sets a resource-based policy that is used to manage access permissions on the target backup vault. | Y | N |
| Put | Applies Backup Vault Lock to a backup vault, preventing attempts to delete any recovery point stored in or created in a backup vault. | N | N |
| Put | Turns on notifications on a backup vault for the specified topic and events. | Y | N |
| Put | This request allows you to send your independent self-run restore test validation results. | N | N |
| Revoke | Revokes access to a restore access backup vault, removing the ability to restore from its recovery points and permanently deleting the vault. | Y | N |
| Start | Starts an on-demand backup job for the specified resource. | N | N |
| Start | Starts a job to create a one-time copy of the specified resource. | N | N |
| Start | Starts an on-demand report job for the specified report plan. | N | N |
| Start | Recovers the saved resource identified by an Amazon Resource Name (ARN). | N | N |
| Start | Starts scanning jobs for specific resources. | N | N |
| Stop | Attempts to cancel a job to create a one-time backup of a resource. | Y | N |
| Tag | Assigns a set of key-value pairs to a resource. | Y | N |
| Untag | Removes a set of key-value pairs from a recovery point, backup plan, or backup vault identified by an Amazon Resource Name (ARN) This API is not supported for recovery points for resource types including Aurora, Amazon DocumentDB. | Y | N |
| Update | Updates the specified backup plan. | Y | N |
| Update | Updates the specified framework. | Y | N |
| Update | Updates whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator. | N | N |
| Update | This operation updates the settings of a recovery point index. | Y | N |
| Update | Sets the transition lifecycle of a recovery point. | Y | N |
| Update | Updates the current service opt-in settings for the Region. | N | N |
| Update | Updates the specified report plan. | Y | N |
| Update | This request will send changes to your specified restore testing plan. | Y | N |
| Update | Updates the specified restore testing selection. | Y | N |
| Update | This request will send changes to your specified tiering configuration. | Y | N |
| Authorize | AuthorizeRecoveryPointTagging recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Backup | BackupDeleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Backup | BackupJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Backup | BackupJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| COPY_ | COPY_JOB_COMPLETED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| COPY_ | COPY_JOB_STARTED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Copy | CopyJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Copy | CopyJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Recovery | RecoveryPointCreated recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Create | Creates a backup access point for an Amazon S3 recovery point. | N | N |
| Delete | Deletes a backup access point. | N | N |
| Describe | Returns metadata about a backup access point, including its status and the details of the underlying Amazon S3 access point. | N | N |
| List | Returns a list of the backup access points in your account and Region. | N | N |
| List | Returns the backup access points associated with the specified recovery point. | N | N |
| List | Returns the backup access points associated with the specified resource, such as an Amazon S3 bucket. | N | N |
any: AWS Backup (catch-all)
#Description
Catch-all entry for AWS Backup rules that match the service but not a specific eventName.
DeleteBackupPlan
#Description
Deletes a backup plan, removing all scheduled backup rules and preventing future automatic backups under that plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup plan ID",
"eventCategory": "Management",
"eventID": "9507a1ce-1dcf-4fd7-9206-6426d6ee490c",
"eventName": "DeleteBackupPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6af8828a-5b15-4811-9877-4112112a90b2",
"requestParameters": {
"backupPlanId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1490↳ also matches DeleteBackupSelection
DeleteBackupSelection
#Description
Removes a resource assignment (selection) from a backup plan, stopping the plan from protecting the specified resources.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup plan ID",
"eventCategory": "Management",
"eventID": "2240edef-0688-4066-b8d3-ecc21050096a",
"eventName": "DeleteBackupSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "14c17982-4404-46b7-8493-9e9b30ba5b3b",
"requestParameters": {
"backupPlanId": "dw-probe",
"selectionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1490↳ also matches DeleteBackupPlan
AssociateBackupVaultMpaApprovalTeam
#Description
Associates an MPA approval team with a backup vault.
CancelLegalHold
#Description
Removes the specified legal hold on a recovery point.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Can not find Legal Hold ARN.",
"eventCategory": "Management",
"eventID": "60ab5024-44f4-49d3-856f-b1234d3a9ab4",
"eventName": "CancelLegalHold",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eb38ac27-756a-425a-a77a-3bd811b1f8a7",
"requestParameters": {
"cancelDescription": "dw-probe",
"legalHoldId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateBackupPlan
#Description
Creates a backup plan using a backup plan name and backup rules.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ead0622e-78b6-4449-88c7-d0561899a44c",
"eventName": "CreateBackupPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "93cef107-bbd8-4a7f-8454-fafbcec68424",
"requestParameters": {
"backupPlan": {
"backupPlanName": "dwfixplanbz9vn61lmy",
"rules": [
{
"completionWindowMinutes": 180,
"lifecycle": {
"deleteAfterDays": 1
},
"ruleName": "dwfix-daily",
"scheduleExpression": "cron(0 12 * * ? *)",
"startWindowMinutes": 60,
"targetBackupVaultName": "dwfix-vault-bz9vn61lmy"
}
]
},
"backupPlanTags": "HIDDEN_DUE_TO_SECURITY_REASONS",
"creatorRequestId": "4cc66d2b-265f-4056-a40d-0c5d9a5041ce"
},
"responseElements": {
"backupPlanArn": "arn:aws:backup:us-west-1:123456789012:backup-plan:ab6eee5e-6a45-4730-bf39-724df73407b3",
"backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3",
"creationDate": "2026-06-29T21:01:38Z",
"versionId": "YzNlYzdhNzEtN2ViZi00MjgyLThhYmQtYWU1YzY1MTEwNWJj"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateBackupSelection
#Description
Creates a JSON document that specifies a set of resources to assign to a backup plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0614dcd7-9d69-46ab-90e5-99d9b07794c2",
"eventName": "CreateBackupSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "61974a11-eaf4-49b5-9619-94539953ccfe",
"requestParameters": {
"backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3",
"backupSelection": {
"iamRoleArn": "arn:aws:iam::123456789012:role/service-role/AWSBackupDefaultServiceRole",
"resources": [
"arn:aws:dynamodb:us-west-1:123456789012:table/dwfix-placeholder"
],
"selectionName": "dwfix-sel"
},
"creatorRequestId": "1aef2ed1-d791-438d-9818-ad4afd0ed4d0"
},
"responseElements": {
"backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3",
"creationDate": "2026-06-29T21:01:38Z",
"selectionId": "58849ff1-0c83-47c5-88de-dc4a96d55a6b"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateBackupVault
#Description
Creates a logical container where backups are stored.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "79b71214-0df6-4d5d-b378-30debb576350",
"eventName": "CreateBackupVault",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4ecfb09b-7384-4b22-8284-14321c7ad4a6",
"requestParameters": {
"backupVaultName": "dwfix-vault-bz9vn61lmy",
"backupVaultTags": "HIDDEN_DUE_TO_SECURITY_REASONS",
"creatorRequestId": "c4690368-9c56-42cd-9159-43a8ebb01bd5"
},
"responseElements": {
"backupVaultArn": "arn:aws:backup:us-west-1:123456789012:backup-vault:dwfix-vault-bz9vn61lmy",
"backupVaultName": "dwfix-vault-bz9vn61lmy",
"creationDate": "2026-06-29T21:01:38Z"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateFramework
#Description
Creates a framework with one or more controls.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b95600df-d086-403d-a157-0d308746ce90",
"eventName": "CreateFramework",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "748051be-426e-45f1-9c1b-259ff2a819f5",
"requestParameters": {
"frameworkControls": [
{
"controlInputParameters": [
{
"parameterName": "requiredFrequencyValue",
"parameterValue": "1"
},
{
"parameterName": "requiredFrequencyUnit",
"parameterValue": "days"
},
{
"parameterName": "requiredRetentionDays",
"parameterValue": "7"
}
],
"controlName": "BACKUP_PLAN_MIN_FREQUENCY_AND_MIN_RETENTION_CHECK"
}
],
"frameworkDescription": "dwfix sample-collection framework",
"frameworkName": "dwfixfwbz9vn61lmy",
"frameworkTags": {
"Project": "dwfix"
},
"idempotencyToken": "e2f554e0-3109-4716-9fa8-e33996b13166"
},
"responseElements": {
"frameworkArn": "arn:aws:backup:us-west-1:123456789012:framework:dwfixfwbz9vn61lmy-283fa74e-2aa1-439f-a812-d752c5192306",
"frameworkName": "dwfixfwbz9vn61lmy"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateLegalHold
#Description
Creates a legal hold on a recovery point (backup).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "MissingParameterValueException",
"errorMessage": "Missing Resource Selection.",
"eventCategory": "Management",
"eventID": "5267dcd4-3ce8-4a26-b506-1b8920676ac4",
"eventName": "CreateLegalHold",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6fe7dfc5-b92f-4cb7-a87d-93f0230aeb59",
"requestParameters": {
"description": "dwfix sample-collection legal hold - safe to cancel",
"idempotencyToken": "941f38d4-9ba3-4de0-ba20-993e2c6c09c2",
"title": "dwfix-hold-bz9vn61lmy"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateLogicallyAirGappedBackupVault
#Description
Creates a logical container to where backups may be copied.
CreateReportPlan
#Description
Creates a report plan.
CreateRestoreAccessBackupVault
#Description
Creates a restore access backup vault that provides temporary access to recovery points in a logically air-gapped backup vault, subject to MPA approval.
CreateRestoreTestingPlan
#Description
Creates a restore testing plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e9d63e95-6bc8-4238-ac4f-42b653523f55",
"eventName": "CreateRestoreTestingPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1221195d-f23c-4345-af5f-148904082011",
"requestParameters": {
"restoreTestingPlan": {
"recoveryPointSelection": {
"algorithm": "LATEST_WITHIN_WINDOW",
"includeVaults": [
"arn:aws:backup:us-west-1:123456789012:backup-vault:dwfix-vault-bz9vn61lmy"
],
"recoveryPointTypes": [
"SNAPSHOT"
],
"selectionWindowDays": 7
},
"restoreTestingPlanName": "dwfixrtpbz9vn61lmy",
"scheduleExpression": "cron(0 12 ? * 1 *)",
"startWindowHours": 8
},
"tags": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"responseElements": {
"creationTime": "2026-06-29T21:01:40Z",
"restoreTestingPlanArn": "arn:aws:backup:us-west-1:123456789012:restore-testing-plan:dwfixrtpbz9vn61lmy-178ba446-9fdd-4287-94bd-af24ed23d5a6",
"restoreTestingPlanName": "dwfixrtpbz9vn61lmy"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateRestoreTestingSelection
#Description
This request can be sent after CreateRestoreTestingPlan request returns successfully.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "be98f834-03a8-40d6-bf3f-975dbd6aec4f",
"eventName": "CreateRestoreTestingSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ee496ff3-9d49-4cac-9a26-149d2416e6a2",
"requestParameters": {
"restoreTestingPlanName": "dwfixrtpbz9vn61lmy",
"restoreTestingSelection": {
"iamRoleArn": "arn:aws:iam::123456789012:role/service-role/AWSBackupDefaultServiceRole",
"protectedResourceType": "DynamoDB",
"restoreTestingSelectionName": "dwfixrtsel"
}
},
"responseElements": {
"creationTime": "2026-06-29T21:01:40Z",
"restoreTestingPlanArn": "arn:aws:backup:us-west-1:123456789012:restore-testing-plan:dwfixrtpbz9vn61lmy-178ba446-9fdd-4287-94bd-af24ed23d5a6",
"restoreTestingPlanName": "dwfixrtpbz9vn61lmy",
"restoreTestingSelectionName": "dwfixrtsel"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTieringConfiguration
#Description
Creates a tiering configuration.
DeleteBackupVault
#Description
Deletes the backup vault identified by its name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "d22a9e7e-777a-4656-a8ef-a1c3ed2acb69",
"eventName": "DeleteBackupVault",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9c106e28-5a64-4361-8bdf-82d29684753c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1490, T1562↳ also matches DeleteBackupVaultLockConfiguration
DeleteBackupVaultAccessPolicy
#Description
Deletes the policy document that manages permissions on a backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "6b34f283-e0bb-477b-8c87-5090115ce353",
"eventName": "DeleteBackupVaultAccessPolicy",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "58f0b99c-ba63-470a-8e62-d3fdf0748b47",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBackupVaultLockConfiguration
#Description
Deletes Backup Vault Lock from a backup vault specified by a backup vault name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "941eb5d0-8429-46ab-8b07-d2a1103a1254",
"eventName": "DeleteBackupVaultLockConfiguration",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "50e443b9-4052-45f1-9a0d-d5af83d30302",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1490, T1562↳ also matches DeleteBackupVault
DeleteBackupVaultNotifications
#Description
Deletes event notifications for the specified backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "a13e734e-a047-4aa9-a4db-a2d65329efbc",
"eventName": "DeleteBackupVaultNotifications",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8f9ca09c-501f-4fe4-9802-8e13a75c086e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteFramework
#Description
Deletes the framework specified by a framework name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Framework ddddd not found in account 123456789012.",
"eventCategory": "Management",
"eventID": "73779cb6-71c0-4677-ad03-cbc7eeb20e07",
"eventName": "DeleteFramework",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5de0f17b-c6b6-4082-9163-feaba8423d95",
"requestParameters": {
"frameworkName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRecoveryPoint
#Description
Deletes the recovery point specified by a recovery point ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "89d6a500-e77f-4ab8-9bb5-b5ac4c2f1424",
"eventName": "DeleteRecoveryPoint",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "59f8696d-191f-47e2-bdc4-5c53d6d4b793",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1490
DeleteReportPlan
#Description
Deletes the report plan specified by a report plan name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Report plan ddddd not found in account 123456789012.",
"eventCategory": "Management",
"eventID": "44d499ab-6aa4-4faa-872f-2ac5c8d7fa36",
"eventName": "DeleteReportPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5e3184b8-1b58-49f1-bf13-ef32524da4e7",
"requestParameters": {
"reportPlanName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRestoreTestingPlan
#Description
This request deletes the specified restore testing plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "565f8895-e520-4d97-902b-fd07e9f9fec5",
"eventName": "DeleteRestoreTestingPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "93c06351-3e1c-46d0-bbc8-d04f5c0dac25",
"requestParameters": {
"restoreTestingPlanName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRestoreTestingSelection
#Description
Input the Restore Testing Plan name and Restore Testing Selection name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Restore testing plan does not exist.",
"eventCategory": "Management",
"eventID": "25f17e8c-c446-4ddd-8abb-4e365d529bef",
"eventName": "DeleteRestoreTestingSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5c254d1a-a229-4054-b6cf-148b876229be",
"requestParameters": {
"restoreTestingPlanName": "dw-probe",
"restoreTestingSelectionName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTieringConfiguration
#Description
Deletes the tiering configuration specified by a tiering configuration name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "f5eb3d53-b3a9-4004-a1c8-3497e0687419",
"eventName": "DeleteTieringConfiguration",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "619d6bd4-f423-423a-a26f-f070458b1950",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeBackupJob
#Description
Returns backup job details for the specified BackupJobId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The BackupJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
"eventCategory": "Management",
"eventID": "6c83b091-16a8-4691-97e9-b35ae0bd4e30",
"eventName": "DescribeBackupJob",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "65552fec-b8e9-46a9-a1e0-0d5463ae703f",
"requestParameters": {
"backupJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeBackupVault
#Description
Returns metadata about a backup vault specified by its name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "9554ea88-8798-470f-9570-01b9e0b54e64",
"eventName": "DescribeBackupVault",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "195cecf5-f154-4905-a71b-93fd37364766",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCopyJob
#Description
Returns metadata associated with creating a copy of a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The CopyJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
"eventCategory": "Management",
"eventID": "ab992d36-33c4-41e2-9ae9-f4d0c03f9749",
"eventName": "DescribeCopyJob",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0e087da8-0165-469d-9a58-4829d5e8f089",
"requestParameters": {
"copyJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeFramework
#Description
Returns the framework details for the specified FrameworkName.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Framework ddddd not found in account 123456789012.",
"eventCategory": "Management",
"eventID": "d50033cc-4510-440f-9c07-8890d0eac7e6",
"eventName": "DescribeFramework",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9921454e-dbcf-4777-961b-903b3cc9fa05",
"requestParameters": {
"frameworkName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeGlobalSettings
#Description
Describes whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidRequestException",
"errorMessage": "Your account is not a member of an organization.",
"eventCategory": "Management",
"eventID": "a72b3d44-1128-40f0-a19a-5a1756996c45",
"eventName": "DescribeGlobalSettings",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ede1e755-d017-4ac6-b00e-6d5f5a985582",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeProtectedResource
#Description
Returns information about a saved resource, including the last time it was backed up, its Amazon Resource Name (ARN), and the Amazon Web Services service type of the saved resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Cannot find protected resource",
"eventCategory": "Management",
"eventID": "b229fc67-77bb-4291-a208-8dc527c5c6f9",
"eventName": "DescribeProtectedResource",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "aecc062a-1035-483d-a294-945ec62599f5",
"requestParameters": {
"resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRecoveryPoint
#Description
Returns metadata associated with a recovery point, including ID, status, encryption, and lifecycle.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "99119cb4-5e56-4021-8a4c-0df8136af9d9",
"eventName": "DescribeRecoveryPoint",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "fb1cf4c3-441c-4342-8eea-4915e1fca139",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRegionSettings
#Description
Returns the current service opt-in settings for the Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2b2e11e0-f6fa-4481-94e1-a7f585d8b7f5",
"eventName": "DescribeRegionSettings",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6f0a20b4-9d70-4275-bf09-b26916208dfb",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeReportJob
#Description
Returns the details associated with creating a report as specified by its ReportJobId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid report job ID dw-probe. The report job ID must be a valid UUID.",
"eventCategory": "Management",
"eventID": "37658775-3b08-4f60-9930-e673732b6837",
"eventName": "DescribeReportJob",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "80477185-1027-4747-b00f-98ca1cc1aa53",
"requestParameters": {
"reportJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeReportPlan
#Description
Returns a list of all report plans for an Amazon Web Services account and Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Report plan ddddd not found in account 123456789012.",
"eventCategory": "Management",
"eventID": "cb8ea29c-e2be-4267-946d-795262ebe31c",
"eventName": "DescribeReportPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f5d710ac-09b0-4d9a-b352-12dbe498a55f",
"requestParameters": {
"reportPlanName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRestoreJob
#Description
Returns metadata associated with a restore job that is specified by a job ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The RestoreJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
"eventCategory": "Management",
"eventID": "58710861-89e4-4d89-9359-b36c54bc2dda",
"eventName": "DescribeRestoreJob",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "abfd2548-6429-4d18-bcc3-9bb19229fa7c",
"requestParameters": {
"restoreJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeScanJob
#Description
Returns scan job details for the specified ScanJobID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Scan Job Id is invalid",
"eventCategory": "Management",
"eventID": "62dda959-442d-48ae-903b-47c3561cd9a9",
"eventName": "DescribeScanJob",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a8f401d4-66ac-4b2e-961e-83d10c47fce4",
"requestParameters": {
"scanJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateBackupVaultMpaApprovalTeam
#Description
Removes the association between an MPA approval team and a backup vault, disabling the MPA approval workflow for restore operations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "6166c38f-56e4-4b33-a367-83d575c5bd20",
"eventName": "DisassociateBackupVaultMpaApprovalTeam",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "257cb44f-9bf0-469a-a1bd-a0fb813d7c39",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateRecoveryPoint
#Description
Deletes the specified continuous backup recovery point from Backup and releases control of that continuous backup to the source service, such as Amazon RDS.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "1cc82b8d-2df9-4eba-8259-f1af2c6e4e49",
"eventName": "DisassociateRecoveryPoint",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8ac15e0d-e69b-48fd-976e-aa7ea4a52d33",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateRecoveryPointFromParent
#Description
This action to a specific child (nested) recovery point removes the relationship between the specified recovery point and its parent (composite) recovery point.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "fbcd83c7-d95e-4d29-a397-b444d251294b",
"eventName": "DisassociateRecoveryPointFromParent",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ccb72e18-fad5-4bbf-bb23-0cf5d308b4ff",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ExportBackupPlanTemplate
#Description
Returns the backup plan that is specified by the plan ID as a backup template.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3b07dc2c-8add-446e-ad14-69e5bcac05c1",
"eventName": "ExportBackupPlanTemplate",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "16255240-762d-48d2-89ac-37c9245db9e8",
"requestParameters": {
"backupPlanId": "ab6eee5e-6a45-4730-bf39-724df73407b3"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBackupPlan
#Description
Returns BackupPlan details for the specified BackupPlanId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup plan ID",
"eventCategory": "Management",
"eventID": "ca76e96c-8fb4-45ec-bc0c-020a50119892",
"eventName": "GetBackupPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c0af4e54-de64-4ab2-8f64-bcd725dfc77f",
"requestParameters": {
"backupPlanId": "dw-probe",
"maxScheduledRunsPreview": 0
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBackupPlanFromJSON
#Description
Returns a valid JSON document specifying a backup plan or an error.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Failed to de-serialize backup plan template.",
"eventCategory": "Management",
"eventID": "6e74d7a1-0796-40c3-8f08-660c86a50287",
"eventName": "GetBackupPlanFromJSON",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "85fd0464-f00e-4e35-b0ce-6b398d688b1c",
"requestParameters": {
"backupPlanTemplateJson": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBackupPlanFromTemplate
#Description
Returns the template specified by its templateId as a backup plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup plan template ID",
"eventCategory": "Management",
"eventID": "5aa2c137-4d4b-442c-a878-96fdab1ed293",
"eventName": "GetBackupPlanFromTemplate",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f14bb997-df28-482e-be78-b5f520d53761",
"requestParameters": {
"backupPlanTemplateId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBackupSelection
#Description
Returns selection metadata and a document in JSON format that specifies a list of resources that are associated with a backup plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup selection ID",
"eventCategory": "Management",
"eventID": "859e12e9-1667-47d0-a10e-515f5a23d9cf",
"eventName": "GetBackupSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "eaaf7f09-4749-424c-b790-6ffb5866816a",
"requestParameters": {
"backupPlanId": "dw-probe",
"selectionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBackupVaultAccessPolicy
#Description
Returns the access policy document that is associated with the named backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "947c1b3a-3dac-45cc-8be3-a5827c76a14e",
"eventName": "GetBackupVaultAccessPolicy",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "27e3f583-309f-4220-bda8-b3befec8c55d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBackupVaultNotifications
#Description
Returns event notifications for the specified backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "647b2db8-a87c-4822-8c03-d7b8e717ef02",
"eventName": "GetBackupVaultNotifications",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "455091e4-38b4-49d2-b562-5f501e9e7316",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetLegalHold
#Description
This action returns details for a specified legal hold.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Can not find Legal Hold ARN.",
"eventCategory": "Management",
"eventID": "62a761da-cbad-4de5-90d1-b7358b188fcc",
"eventName": "GetLegalHold",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c28ec7ab-2334-42e6-9d4d-028cabed8919",
"requestParameters": {
"legalHoldId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetPITRMalwareScanResults
#Description
Returns the malware scan results for a specified point in time within a continuous (point-in-time recovery) backup.
GetRecoveryPointIndexDetails
#Description
This operation returns the metadata and details specific to the backup index associated with the specified recovery point.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "b035c45c-b17f-4287-8847-79b5e03d0617",
"eventName": "GetRecoveryPointIndexDetails",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f749ffb5-88c5-436d-a3ad-359d7370af3b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRecoveryPointRestoreMetadata
#Description
Returns a set of metadata key-value pairs that were used to create the backup.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "9faeabb4-c098-4bbe-9013-2c581368bd49",
"eventName": "GetRecoveryPointRestoreMetadata",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9a7582c2-dd3c-4659-b1e6-c6a8d2d071f5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRestoreJobMetadata
#Description
This request returns the metadata for the specified restore job.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The RestoreJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
"eventCategory": "Management",
"eventID": "caca1414-fbca-4296-b66f-ced97c8f8f1f",
"eventName": "GetRestoreJobMetadata",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3029f6ac-6f66-49a1-b9a3-bb31d8604a72",
"requestParameters": {
"restoreJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRestoreTestingInferredMetadata
#Description
This request returns the minimal required set of metadata needed to start a restore job with secure default settings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid ARN.",
"eventCategory": "Management",
"eventID": "da31b66e-da47-42d8-a25e-8eb61645889e",
"eventName": "GetRestoreTestingInferredMetadata",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2d94f9a2-4e49-4e21-9bd7-47f432be39d4",
"requestParameters": {
"backupVaultName": "dw-probe",
"recoveryPointArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRestoreTestingPlan
#Description
Returns RestoreTestingPlan details for the specified RestoreTestingPlanName.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Restore testing plan does not exist.",
"eventCategory": "Management",
"eventID": "56e8a2c8-5bf3-4b9d-b8de-5d2faf4f5079",
"eventName": "GetRestoreTestingPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "732ca995-115a-4ebe-b7cc-4fd93171fb7a",
"requestParameters": {
"restoreTestingPlanName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRestoreTestingSelection
#Description
Returns RestoreTestingSelection, which displays resources and elements of the restore testing plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Restore testing plan does not exist.",
"eventCategory": "Management",
"eventID": "df6d2a83-3fbf-48e2-9a81-2478b3c933b0",
"eventName": "GetRestoreTestingSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c8f799fd-9378-423a-bc72-f4f32332e863",
"requestParameters": {
"restoreTestingPlanName": "dw-probe",
"restoreTestingSelectionName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSupportedResourceTypes
#Description
Returns the Amazon Web Services resource types supported by Backup.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ebfdde5a-76e7-48d5-8df8-57411990749d",
"eventName": "GetSupportedResourceTypes",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e01219ba-1fb0-4ef5-8395-d52bb46b5825",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTieringConfiguration
#Description
Returns TieringConfiguration details for the specified TieringConfigurationName.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "0b27f3d5-8788-44b0-91a1-e0ac970f7e84",
"eventName": "GetTieringConfiguration",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0d1ff51e-7a51-4487-b220-db7b98e9ba83",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupJobs
#Description
Returns a list of existing backup jobs for an authenticated account for the last 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ed6a806d-8f45-49ce-a500-583329ac407c",
"eventName": "ListBackupJobs",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "14fdf920-ece8-4c83-a83b-51f10bc46568",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupJobSummaries
#Description
This is a request for a summary of backup jobs created or running within the most recent 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a283bb63-1937-41df-8a0c-f21f163dbb6d",
"eventName": "ListBackupJobSummaries",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b0bb1a7a-e823-4232-b5d3-8bef39111b8a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupPlans
#Description
Lists the active backup plans for the account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b1ba92fd-4cad-4b3f-8b79-93de1834c185",
"eventName": "ListBackupPlans",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bfbaaad0-ae87-49d2-abf8-7b1f7324dca8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupPlanTemplates
#Description
Lists the backup plan templates.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1982654d-b84e-4b53-9c15-86e2368ce0c8",
"eventName": "ListBackupPlanTemplates",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0f7a8fb5-4f3d-4782-b746-b3ea4b9e0e87",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupPlanVersions
#Description
Returns version metadata of your backup plans, including Amazon Resource Names (ARNs), backup plan IDs, creation and deletion dates, plan names, and version IDs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup plan ID",
"eventCategory": "Management",
"eventID": "8da42752-5e1e-4a7a-936a-44cc6ed8d243",
"eventName": "ListBackupPlanVersions",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d66b5458-1389-4f75-b4c5-a517c06d4992",
"requestParameters": {
"backupPlanId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupSelections
#Description
Returns an array containing metadata of the resources associated with the target backup plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Invalid Backup plan ID",
"eventCategory": "Management",
"eventID": "fb049a9f-16cd-427f-849c-2ea75a2af550",
"eventName": "ListBackupSelections",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c277ae1e-a69c-4c22-b31a-84f288bac5b5",
"requestParameters": {
"backupPlanId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListBackupVaults
#Description
Returns a list of recovery point storage containers along with information about them.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0ddb82a5-3c76-4fda-8236-e7ed93049657",
"eventName": "ListBackupVaults",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "976c86bc-841a-4e69-bf13-2b9171a6e455",
"requestParameters": {
"byShared": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListCopyJobs
#Description
Returns metadata about your copy jobs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "94f02afc-c212-47dd-8128-8045d1da2b5a",
"eventName": "ListCopyJobs",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "61a3f60d-8803-4462-a819-21cad32da5c7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListCopyJobSummaries
#Description
This request obtains a list of copy jobs created or running within the the most recent 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "259b06fa-854b-4d34-b198-59f01690f8e7",
"eventName": "ListCopyJobSummaries",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "22a1bd33-c5c1-4963-b6ae-1fed5583f9b8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListFrameworks
#Description
Returns a list of all frameworks for an Amazon Web Services account and Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6cb9cdf2-485e-45f3-aca8-41ae9628abd3",
"eventName": "ListFrameworks",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "01235869-7331-402c-9ef7-095188eb17bb",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListIndexedRecoveryPoints
#Description
This operation returns a list of recovery points that have an associated index, belonging to the specified account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "799e7375-e577-4f9d-b378-4ec284419b54",
"eventName": "ListIndexedRecoveryPoints",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "672c93a1-c9c2-4601-a58a-a49a57f79dc3",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListLegalHolds
#Description
This action returns metadata about active and previous legal holds.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cb5edf02-5ef4-4ae8-abab-9866fbb5bd64",
"eventName": "ListLegalHolds",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "70ba57fb-003f-4ca8-9c54-bf301b8d7ae5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListProtectedResources
#Description
Returns an array of resources successfully backed up by Backup, including the time the resource was saved, an Amazon Resource Name (ARN) of the resource, and a resource type.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7af2058f-5b4c-4563-99d3-d92e3af18ccf",
"eventName": "ListProtectedResources",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "020a08c0-216b-425f-bf12-31e14c335f53",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListProtectedResourcesByBackupVault
#Description
This request lists the protected resources corresponding to each backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "92fc87e5-c008-407b-85f5-46d301d634e2",
"eventName": "ListProtectedResourcesByBackupVault",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "75810d9d-557b-476a-8aac-4b7c0e41338d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRecoveryPointsByBackupVault
#Description
Returns detailed information about the recovery points stored in a backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "6b8e634b-9799-4a2b-8ca3-88c71680de13",
"eventName": "ListRecoveryPointsByBackupVault",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ecdd56ed-9bae-4bbf-b538-6366dedc97a0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRecoveryPointsByLegalHold
#Description
This action returns recovery point ARNs (Amazon Resource Names) of the specified legal hold.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Can not find Legal Hold ARN.",
"eventCategory": "Management",
"eventID": "6b7fafb3-e362-4368-bf56-c1c46b59b6ba",
"eventName": "ListRecoveryPointsByLegalHold",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1d80fd78-56a4-4071-8606-73cbd95bfcf3",
"requestParameters": {
"legalHoldId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRecoveryPointsByResource
#Description
The information about the recovery points of the type specified by a resource Amazon Resource Name (ARN).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The resource is not supported",
"eventCategory": "Management",
"eventID": "372b62ab-3520-4a55-bab4-69106c7adc91",
"eventName": "ListRecoveryPointsByResource",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "67570a20-96bb-4552-8b53-6dfd2ea5a250",
"requestParameters": {
"managedByAWSBackupOnly": false,
"resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListReportJobs
#Description
Returns details about your report jobs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "308767af-2739-48ea-89d4-73628a3b55a9",
"eventName": "ListReportJobs",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "aab03637-bd71-492c-89d5-a8c0a9cbb67c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListReportPlans
#Description
Returns a list of your report plans.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "245c3005-838e-45c0-9ccb-259222769704",
"eventName": "ListReportPlans",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "10b8c380-b704-4282-8370-5ddbff412ace",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRestoreAccessBackupVaults
#Description
Returns a list of restore access backup vaults associated with a specified backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "83fadc90-29c6-4596-b10f-fc56fdf183b8",
"eventName": "ListRestoreAccessBackupVaults",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a265cec3-ce5d-4cba-9ad6-2d96d5321ab9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRestoreJobs
#Description
Returns a list of jobs that Backup initiated to restore a saved resource, including details about the recovery process.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "15246923-8359-41e7-a60f-c52a39f58223",
"eventName": "ListRestoreJobs",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "293da690-30d4-4f1f-9932-0dc96c6db5f7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRestoreJobsByProtectedResource
#Description
This returns restore jobs that contain the specified protected resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f3634321-b288-4820-b4de-c31f070e805d",
"eventName": "ListRestoreJobsByProtectedResource",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e6543260-6047-4866-8544-bf4b8875d010",
"requestParameters": {
"resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRestoreJobSummaries
#Description
This request obtains a summary of restore jobs created or running within the the most recent 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c7bd7a93-0807-42e6-bfcf-a6e7ee460d68",
"eventName": "ListRestoreJobSummaries",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "32f97a2e-7d9e-4fb8-946d-35cdc87f3122",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRestoreTestingPlans
#Description
Returns a list of restore testing plans.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5c50a491-4376-48a9-9b62-4f89b1163ae6",
"eventName": "ListRestoreTestingPlans",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1b0ed01d-481b-441b-88f3-9e430f47ffab",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListRestoreTestingSelections
#Description
Returns a list of restore testing selections.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Restore testing plan does not exist.",
"eventCategory": "Management",
"eventID": "d79f78c7-69b4-499d-9062-ccf04d6e2757",
"eventName": "ListRestoreTestingSelections",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:42:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a87d0e66-3228-4f6d-a61d-f6fe9cc14b71",
"requestParameters": {
"restoreTestingPlanName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListScanJobs
#Description
Returns a list of existing scan jobs for an authenticated account for the last 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "aec0eb56-2d08-4cdd-853c-15e82ddc47fb",
"eventName": "ListScanJobs",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c4af8106-3cdd-42ac-b2f9-56dbf7ef10be",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListScanJobSummaries
#Description
This is a request for a summary of scan jobs created or running within the most recent 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Input MalwareScanner must be specified.",
"eventCategory": "Management",
"eventID": "ae32fa28-d661-4ea0-91fb-25dad2809d9b",
"eventName": "ListScanJobSummaries",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "062206ee-2114-4ddf-bf15-b6a3cc49fb51",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListTieringConfigurations
#Description
Returns a list of tiering configurations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "176b04d0-bbbf-45eb-8c3d-aca8814d19bd",
"eventName": "ListTieringConfigurations",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T18:31:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5703f9dd-f01a-4e79-953f-8ea0f46ab3b7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBackupVaultAccessPolicy
#Description
Sets a resource-based policy that is used to manage access permissions on the target backup vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "Policy statement action out of service scope!",
"eventCategory": "Management",
"eventID": "28ad446e-7847-41d4-9abe-e43579345d82",
"eventName": "PutBackupVaultAccessPolicy",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bd3f4d5f-fae1-452a-ad58-6e96c7e5c7bf",
"requestParameters": {
"backupVaultName": "dwfix-vault-bz9vn61lmy",
"policy": {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowAccountRoot",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:root"
},
"Action": "backup:*",
"Resource": "*"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBackupVaultLockConfiguration
#Description
Applies Backup Vault Lock to a backup vault, preventing attempts to delete any recovery point stored in or created in a backup vault.
PutBackupVaultNotifications
#Description
Turns on notifications on a backup vault for the specified topic and events.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "91bab691-6bee-49d7-8bea-a0adef54c7a4",
"eventName": "PutBackupVaultNotifications",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9b22b34c-77f6-4529-8c68-2182a7e55294",
"requestParameters": {
"backupVaultEvents": [
"BACKUP_JOB_STARTED",
"BACKUP_JOB_COMPLETED",
"RESTORE_JOB_STARTED",
"RESTORE_JOB_COMPLETED"
],
"backupVaultName": "dwfix-vault-bz9vn61lmy",
"sNSTopicArn": "arn:aws:sns:us-west-1:123456789012:dwfix-nonexistent-topic-bz9vn61lmy"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutRestoreValidationResult
#Description
This request allows you to send your independent self-run restore test validation results.
RevokeRestoreAccessBackupVault
#Description
Revokes access to a restore access backup vault, removing the ability to restore from its recovery points and permanently deleting the vault.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "f177d21d-a5a5-4a44-aee3-a78a54cc411e",
"eventName": "RevokeRestoreAccessBackupVault",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5c65f545-5a84-4b62-87bd-4056b01497cd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartBackupJob
#Description
Starts an on-demand backup job for the specified resource.
StartCopyJob
#Description
Starts a job to create a one-time copy of the specified resource.
StartReportJob
#Description
Starts an on-demand report job for the specified report plan.
StartRestoreJob
#Description
Recovers the saved resource identified by an Amazon Resource Name (ARN).
StartScanJob
#Description
Starts scanning jobs for specific resources.
StopBackupJob
#Description
Attempts to cancel a job to create a one-time backup of a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "The BackupJobID must be a Universally Unique Identifier (UUID) in this format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. Recheck the ID and try again.",
"eventCategory": "Management",
"eventID": "18741e0f-f005-4065-9ca9-b68f011cf395",
"eventName": "StopBackupJob",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "65f57c10-b7b3-41e7-b127-7bba555ad35a",
"requestParameters": {
"backupJobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TagResource
#Description
Assigns a set of key-value pairs to a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "375abbf7-a123-4ae2-a54b-0f1e128d05de",
"eventName": "TagResource",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T21:01:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "05c1feb5-be09-46a8-95a5-06c2e08d90ba",
"requestParameters": {
"resourceArn": "arn:aws:backup:us-west-1:123456789012:backup-vault:dwfix-vault-bz9vn61lmy",
"tags": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagResource
#Description
Removes a set of key-value pairs from a recovery point, backup plan, or backup vault identified by an Amazon Resource Name (ARN) This API is not supported for recovery points for resource types including Aurora, Amazon DocumentDB.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Cannot find recovery point",
"eventCategory": "Management",
"eventID": "7660e3ba-bb60-40ce-ae87-582a58c1aff1",
"eventName": "UntagResource",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "23aadfda-7bb7-48b9-9fea-fb3d38bf5275",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateBackupPlan
#Description
Updates the specified backup plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterValueException",
"errorMessage": "A Backup vault does not exist",
"eventCategory": "Management",
"eventID": "f40d2ea4-c447-49b1-8505-f145112188d7",
"eventName": "UpdateBackupPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7eaf5661-25b2-4e7a-95b6-34b1642e4162",
"requestParameters": {
"backupPlan": {
"backupPlanName": "dw-probe",
"rules": [
{
"ruleName": "dw-probe",
"targetBackupVaultName": "dw-probe"
}
]
},
"backupPlanId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateFramework
#Description
Updates the specified framework.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Framework ddddd not found in account 123456789012.",
"eventCategory": "Management",
"eventID": "91728a98-5799-4f38-97e0-b8a863eb31af",
"eventName": "UpdateFramework",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3d2ec6dd-e41f-4aa0-8ec3-4667935cf484",
"requestParameters": {
"frameworkName": "ddddd",
"idempotencyToken": "6b91d7cb-9fe4-4f30-9fbc-a682bb1c0cc2"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateGlobalSettings
#Description
Updates whether the Amazon Web Services account has enabled different cross-account management options, including cross-account backup, multi-party approval, and delegated administrator.
UpdateRecoveryPointIndexSettings
#Description
This operation updates the settings of a recovery point index.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "840caebc-e6f7-4721-b3d8-c6789e57633e",
"eventName": "UpdateRecoveryPointIndexSettings",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6a3f22d5-b563-4f1c-a4e4-68e19dae43be",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateRecoveryPointLifecycle
#Description
Sets the transition lifecycle of a recovery point.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "e93e3a87-10de-454c-afcf-76d561d51434",
"eventName": "UpdateRecoveryPointLifecycle",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e59ea024-be89-4a5d-b8c8-d50987d45d46",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateRegionSettings
#Description
Updates the current service opt-in settings for the Region.
UpdateReportPlan
#Description
Updates the specified report plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Report plan ddddd not found in account 123456789012.",
"eventCategory": "Management",
"eventID": "2c78c09f-40b9-42ca-94ff-63823c1bdffe",
"eventName": "UpdateReportPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b27bb1da-7bfb-4227-86b1-a3aac5e08a67",
"requestParameters": {
"idempotencyToken": "f66538a6-d026-4e15-a6ab-e7e5b51390ef",
"reportPlanName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateRestoreTestingPlan
#Description
This request will send changes to your specified restore testing plan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Restore testing plan does not exist.",
"eventCategory": "Management",
"eventID": "be505984-c9a4-4c5e-ba80-176930290db0",
"eventName": "UpdateRestoreTestingPlan",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9b1f3ecc-1579-4c6b-bef4-176c1e29e756",
"requestParameters": {
"restoreTestingPlan": {},
"restoreTestingPlanName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateRestoreTestingSelection
#Description
Updates the specified restore testing selection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Restore testing plan does not exist.",
"eventCategory": "Management",
"eventID": "162eb16f-18c2-40e1-9b86-4811d9b93a8e",
"eventName": "UpdateRestoreTestingSelection",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "11ca4eef-f183-4927-bb54-76a221a10e2a",
"requestParameters": {
"restoreTestingPlanName": "dw-probe",
"restoreTestingSelection": {},
"restoreTestingSelectionName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTieringConfiguration
#Description
This request will send changes to your specified tiering configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Insufficient privileges to perform this action.",
"eventCategory": "Management",
"eventID": "66323dec-f10d-46a8-9e6d-293598a055c7",
"eventName": "UpdateTieringConfiguration",
"eventSource": "backup.amazonaws.com",
"eventTime": "2026-06-29T19:21:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4cd6f3dd-f0a6-4d4c-84a3-6e25cd0f442a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "backup.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BackupDeleted
#Description
BackupDeleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "0070aa7d-c9a2-491a-8d9b-c37b2bdbaed8",
"eventSource": "backup.amazonaws.com",
"eventName": "BackupDeleted",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
BackupJobCompleted
#Description
BackupJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "28c99464-152c-4ace-a3f9-b9b7e7266ae1",
"eventSource": "backup.amazonaws.com",
"eventName": "BackupJobCompleted",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
BackupJobStarted
#Description
BackupJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "69ac8cf0-04c7-4830-b5cf-9fe40e68dbe9",
"eventSource": "backup.amazonaws.com",
"eventName": "BackupJobStarted",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
COPY_JOB_COMPLETED
#Description
COPY_JOB_COMPLETED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "089a6937-b45c-45eb-804f-88d8d817ca16",
"eventSource": "backup.amazonaws.com",
"eventName": "COPY_JOB_COMPLETED",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
COPY_JOB_STARTED
#Description
COPY_JOB_STARTED recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ee3c7d77-4786-4871-9089-80fc8015ccc0",
"eventSource": "backup.amazonaws.com",
"eventName": "COPY_JOB_STARTED",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
CopyJobCompleted
#Description
CopyJobCompleted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "69f61732-58ea-48bb-9cb6-d7468a98331d",
"eventSource": "backup.amazonaws.com",
"eventName": "CopyJobCompleted",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
CopyJobStarted
#Description
CopyJobStarted recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d0d29b30-5843-4334-b949-3083970e7785",
"eventSource": "backup.amazonaws.com",
"eventName": "CopyJobStarted",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
RecoveryPointCreated
#Description
RecoveryPointCreated recorded by CloudTrail for AWS Backup. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "59d51e4c-a26f-4cf4-9c5e-6e1f4ab93e78",
"eventSource": "backup.amazonaws.com",
"eventName": "RecoveryPointCreated",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "backup.amazonaws.com"
}
CreateBackupAccessPoint
#Description
Creates a backup access point for an Amazon S3 recovery point.
DeleteBackupAccessPoint
#Description
Deletes a backup access point.
DescribeBackupAccessPoint
#Description
Returns metadata about a backup access point, including its status and the details of the underlying Amazon S3 access point.
ListBackupAccessPoints
#Description
Returns a list of the backup access points in your account and Region.
ListBackupAccessPointsByRecoveryPoint
#Description
Returns the backup access points associated with the specified recovery point.
ListBackupAccessPointsByResource
#Description
Returns the backup access points associated with the specified resource, such as an Amazon S3 bucket.