Bedrock AgentCore
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Bedrock AgentCore rules that match the service but not a specific eventName. | N | N |
| Batch | Creates multiple memory records in a single batch operation for the specified memory with custom content. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Batch | Deletes multiple memory records in a single batch operation from the specified memory. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Batch | Updates multiple memory records with custom content in a single batch operation within the specified memory. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Complete | Confirms the user authentication session for obtaining OAuth2.0 tokens for a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates an A/B test for comparing agent configurations. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates an event in an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Create a new payment instrument for a connector. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Create a new payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an A/B test and its associated gateway rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a batch evaluation and its associated results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes an event from an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a memory record from an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a payment instrument. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a recommendation and its associated results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Evaluate | Performs on-demand evaluation of agent traces using a specified evaluator. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves detailed information about an A/B test, including its configuration, status, and statistical results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves the A2A agent card associated with an AgentCore Runtime agent. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves detailed information about a batch evaluation, including its status, configuration, results, and any error details. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves detailed information about a specific browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves detailed information about a specific code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves information about a specific event in an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves a specific memory record from an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Get a payment instrument by ID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Get the balance of a payment instrument. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Get a payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves detailed information about a recommendation, including its configuration, status, and results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves the API key associated with an API key credential provider. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Returns the OAuth 2.0 token of the provided resource. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Generates authentication tokens for payment providers that use vendor-specific authentication mechanisms. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Obtains a workload access token for agentic workloads not acting on behalf of a user. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Obtains a workload access token for agentic workloads acting on behalf of a user, using a JWT token. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Obtains a workload access token for agentic workloads acting on behalf of a user, using the user's ID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Invoke | Sends a request to an agent or tool hosted in an Amazon Bedrock AgentCore Runtime and receives responses in real-time. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Invoke | Executes a command in a runtime session container and streams the output back to the caller. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Invoke | Invokes an operating system-level action on a browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Invoke | Executes code within an active code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Invoke | Operation to invoke a Harness. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists all A/B tests in the account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists all actors in an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists all batch evaluations in the account, providing summary information about each evaluation's status and configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Retrieves a list of browser sessions in Amazon Bedrock AgentCore that match the specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Retrieves a list of code interpreter sessions in Amazon Bedrock AgentCore that match the specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists events in an AgentCore Memory resource based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists all long-term memory extraction jobs that are eligible to be started with optional filtering. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists memory records in an AgentCore Memory resource based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | List payment instruments for a manager. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | List payment sessions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists all recommendations in the account, with optional filtering by status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists sessions in an AgentCore Memory resource based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Process | Processes a payment using a payment instrument within a payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Retrieve | Searches for and retrieves memory records from an AgentCore Memory resource based on specified search criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Save | Saves the current state of a browser session as a reusable profile in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Search | Searches for registry records using semantic, lexical, or hybrid queries. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Start | Starts a batch evaluation job that evaluates agent performance across multiple sessions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Start | Creates and initializes a browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Start | Creates and initializes a code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Start | Starts a memory extraction job that processes events that failed extraction previously in an AgentCore Memory resource and produces structured memory records. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Start | Starts a recommendation job that analyzes agent traces and generates optimization suggestions for system prompts or tool descriptions to improve agent performance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Stop | Stops a running batch evaluation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Stop | Terminates an active browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Stop | Terminates an active code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Stop | Stops a session that is running in an running AgentCore Runtime agent. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates an A/B test's configuration, including variants, traffic allocation, evaluation settings, or execution status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates a browser stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | CreateAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Create | CreateAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Create | CreateMemory recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Create | CreateWorkloadIdentity recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Delete | DeleteAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Delete | DeleteAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Delete | DeleteMemory recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Delete | DeleteWorkloadIdentity recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetBrowser recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetGateway recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetGatewayTarget recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetMemory recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetOnlineEvaluationConfig recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetPolicyEngine recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | GetWorkloadIdentity recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListAgentRuntimeEndpoints recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListAgentRuntimes recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListAgentRuntimeVersions recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListBrowsers recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListCodeInterpreters recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListEvaluators recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListGatewayTargets recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListHarnesses recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListMemories recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListOnlineEvaluationConfigs recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListPolicyEngines recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | ListWorkloadIdentities recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Update | UpdateAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Update | UpdateAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Delete | Deletes a session associated with a capacity provider in Amazon Bedrock AgentCore and makes the session unavailable for further use. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
any: Bedrock AgentCore (catch-all)
#Description
Catch-all entry for Bedrock AgentCore rules that match the service but not a specific eventName.
BatchCreateMemoryRecords
#Description
Creates multiple memory records in a single batch operation for the specified memory with custom content. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
BatchDeleteMemoryRecords
#Description
Deletes multiple memory records in a single batch operation from the specified memory. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
BatchUpdateMemoryRecords
#Description
Updates multiple memory records with custom content in a single batch operation within the specified memory. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CompleteResourceTokenAuth
#Description
Confirms the user authentication session for obtaining OAuth2.0 tokens for a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateABTest
#Description
Creates an A/B test for comparing agent configurations. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateEvent
#Description
Creates an event in an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreatePaymentInstrument
#Description
Create a new payment instrument for a connector. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreatePaymentSession
#Description
Create a new payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteABTest
#Description
Deletes an A/B test and its associated gateway rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteBatchEvaluation
#Description
Deletes a batch evaluation and its associated results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteEvent
#Description
Deletes an event from an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteMemoryRecord
#Description
Deletes a memory record from an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePaymentInstrument
#Description
Deletes a payment instrument. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePaymentSession
#Description
Deletes a payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeleteRecommendation
#Description
Deletes a recommendation and its associated results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
Evaluate
#Description
Performs on-demand evaluation of agent traces using a specified evaluator. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetABTest
#Description
Retrieves detailed information about an A/B test, including its configuration, status, and statistical results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetAgentCard
#Description
Retrieves the A2A agent card associated with an AgentCore Runtime agent. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetBatchEvaluation
#Description
Retrieves detailed information about a batch evaluation, including its status, configuration, results, and any error details. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetBrowserSession
#Description
Retrieves detailed information about a specific browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetCodeInterpreterSession
#Description
Retrieves detailed information about a specific code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetEvent
#Description
Retrieves information about a specific event in an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetMemoryRecord
#Description
Retrieves a specific memory record from an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetPaymentInstrument
#Description
Get a payment instrument by ID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetPaymentInstrumentBalance
#Description
Get the balance of a payment instrument. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetPaymentSession
#Description
Get a payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetRecommendation
#Description
Retrieves detailed information about a recommendation, including its configuration, status, and results. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetResourceApiKey
#Description
Retrieves the API key associated with an API key credential provider. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f39c0211-0af1-42b3-995f-613e2509bb05",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetResourceApiKey",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "025f8831-b364-4bb4-9ba2-45cfccfca7f7",
"userAgent": "bedrock-agentcore.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::APIKeyCredentialProvider",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:token-vault/EXAMPLE"
}
]
}
GetResourceOauth2Token
#Description
Returns the OAuth 2.0 token of the provided resource. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b9526cf2-38fe-446a-b512-a4ac7d787bc2",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetResourceOauth2Token",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "20a48a16-04a0-456d-9f18-f35b2fec7c64",
"userAgent": "bedrock-agentcore.amazonaws.com"
}
GetResourcePaymentToken
#Description
Generates authentication tokens for payment providers that use vendor-specific authentication mechanisms. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetWorkloadAccessToken
#Description
Obtains a workload access token for agentic workloads not acting on behalf of a user. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "382d7d4e-56df-4559-ad85-e261caa28f79",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetWorkloadAccessToken",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "a63af226-6d72-47bb-824d-53f87c3688e0",
"userAgent": "bedrock-agentcore.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::WorkloadIdentity",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:workload-identity-directory/EXAMPLE"
}
]
}
GetWorkloadAccessTokenForJWT
#Description
Obtains a workload access token for agentic workloads acting on behalf of a user, using a JWT token. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "9cf5ed2f-c819-42d8-814d-639cd19b4820",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetWorkloadAccessTokenForJWT",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "fefe6d8e-62a6-4bd7-8c2a-1e712029177f",
"userAgent": "bedrock-agentcore.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::WorkloadIdentity",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:workload-identity-directory/EXAMPLE"
}
]
}
GetWorkloadAccessTokenForUserId
#Description
Obtains a workload access token for agentic workloads acting on behalf of a user, using the user's ID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
InvokeAgentRuntime
#Description
Sends a request to an agent or tool hosted in an Amazon Bedrock AgentCore Runtime and receives responses in real-time. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
InvokeAgentRuntimeCommand
#Description
Executes a command in a runtime session container and streams the output back to the caller. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
InvokeBrowser
#Description
Invokes an operating system-level action on a browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
InvokeCodeInterpreter
#Description
Executes code within an active code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
InvokeHarness
#Description
Operation to invoke a Harness. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListABTests
#Description
Lists all A/B tests in the account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListActors
#Description
Lists all actors in an AgentCore Memory resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListBatchEvaluations
#Description
Lists all batch evaluations in the account, providing summary information about each evaluation's status and configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListBrowserSessions
#Description
Retrieves a list of browser sessions in Amazon Bedrock AgentCore that match the specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListCodeInterpreterSessions
#Description
Retrieves a list of code interpreter sessions in Amazon Bedrock AgentCore that match the specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListEvents
#Description
Lists events in an AgentCore Memory resource based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListMemoryExtractionJobs
#Description
Lists all long-term memory extraction jobs that are eligible to be started with optional filtering. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListMemoryRecords
#Description
Lists memory records in an AgentCore Memory resource based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListPaymentInstruments
#Description
List payment instruments for a manager. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListPaymentSessions
#Description
List payment sessions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListRecommendations
#Description
Lists all recommendations in the account, with optional filtering by status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ListSessions
#Description
Lists sessions in an AgentCore Memory resource based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
ProcessPayment
#Description
Processes a payment using a payment instrument within a payment session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
RetrieveMemoryRecords
#Description
Searches for and retrieves memory records from an AgentCore Memory resource based on specified search criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
SaveBrowserSessionProfile
#Description
Saves the current state of a browser session as a reusable profile in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
SearchRegistryRecords
#Description
Searches for registry records using semantic, lexical, or hybrid queries. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StartBatchEvaluation
#Description
Starts a batch evaluation job that evaluates agent performance across multiple sessions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StartBrowserSession
#Description
Creates and initializes a browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StartCodeInterpreterSession
#Description
Creates and initializes a code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StartMemoryExtractionJob
#Description
Starts a memory extraction job that processes events that failed extraction previously in an AgentCore Memory resource and produces structured memory records. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StartRecommendation
#Description
Starts a recommendation job that analyzes agent traces and generates optimization suggestions for system prompts or tool descriptions to improve agent performance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StopBatchEvaluation
#Description
Stops a running batch evaluation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StopBrowserSession
#Description
Terminates an active browser session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StopCodeInterpreterSession
#Description
Terminates an active code interpreter session in Amazon Bedrock AgentCore. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
StopRuntimeSession
#Description
Stops a session that is running in an running AgentCore Runtime agent. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateABTest
#Description
Updates an A/B test's configuration, including variants, traffic allocation, evaluation settings, or execution status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
UpdateBrowserStream
#Description
Updates a browser stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
CreateAgentRuntime
#Description
CreateAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "539431a6-8d10-4b92-a530-5a24596ac7ca",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "CreateAgentRuntime",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "2a40960b-da53-4422-9741-92e712ac98ee",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
CreateAgentRuntimeEndpoint
#Description
CreateAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "716fdf5d-ea3b-4e64-bb39-d43329b7d0a1",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "CreateAgentRuntimeEndpoint",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "4b8b9880-d1e5-49cc-a58e-6157a84fc18c",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::RuntimeEndpoint",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
CreateMemory
#Description
CreateMemory recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "66024e64-606b-46d7-91ae-8c5a7107d8a5",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "CreateMemory",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "8e5c9906-a439-4e00-9943-aec54cfdf5cd",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Memory",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:memory/EXAMPLE"
}
]
}
CreateWorkloadIdentity
#Description
CreateWorkloadIdentity recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e843af11-6948-49d1-92e9-c7c5c10727da",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "CreateWorkloadIdentity",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "d83e8aba-533b-4db7-96b5-21640e65a76c",
"userAgent": "bedrock-agentcore.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::WorkloadIdentity",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:workload-identity-directory/EXAMPLE"
}
]
}
DeleteAgentRuntime
#Description
DeleteAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ae4d2dc7-4fa9-4f42-9b88-e2858c6ccff6",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "DeleteAgentRuntime",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "192853a1-0530-49dc-86cc-85b4f7d10b97",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
DeleteAgentRuntimeEndpoint
#Description
DeleteAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "50e85a2f-e3db-48d3-8fa3-6dace5e9cb70",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "DeleteAgentRuntimeEndpoint",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "45a5bc9b-bf11-4ff8-a51b-9fd21d8ab79d",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::RuntimeEndpoint",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
DeleteMemory
#Description
DeleteMemory recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d70bacd7-ad88-46f3-b880-7037bbaa8e12",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "DeleteMemory",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "e8a09f58-6b18-4258-b9e4-0c4803356b6d",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Memory",
"ARN": "arn:aws:bedrockagentcore:us-east-1:123456789012:EXAMPLE"
}
]
}
DeleteWorkloadIdentity
#Description
DeleteWorkloadIdentity recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "18ef4377-7e4f-42cd-a9f8-f33cb28d92d4",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "DeleteWorkloadIdentity",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "710fce2c-546a-4e6e-9256-b846747c7ddb",
"userAgent": "bedrock-agentcore.amazonaws.com"
}
GetAgentRuntime
#Description
GetAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "01b27580-009f-4f87-aa65-06a4ba1edf43",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetAgentRuntime",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "c514091f-a6ec-4004-8d6f-ccfcc538929a",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
GetAgentRuntimeEndpoint
#Description
GetAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "cf54b22a-c9f3-4b07-aeab-5a7406f4cf51",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetAgentRuntimeEndpoint",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "9d586673-4d1f-43ce-8b73-5d4cd3e5cea1",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:eu-west-1:123456789012:runtime/EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::RuntimeEndpoint",
"ARN": "arn:aws:bedrock-agentcore:eu-west-1:123456789012:runtime/EXAMPLE"
}
]
}
GetBrowser
#Description
GetBrowser recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "222ebc85-efd0-4c34-a849-89d03643b6e9",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetBrowser",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "aa554907-3b96-469c-b1f7-4972c12e389f",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::BrowserCustom",
"ARN": "arn:aws:bedrock-agentcore:eu-west-1:123456789012:browser-custom/EXAMPLE"
}
]
}
GetGateway
#Description
GetGateway recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4316e536-2828-4ac5-9ab3-2fe793f36a9a",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetGateway",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "04957104-b9db-477b-9234-bb5f1d8dc1bd",
"userAgent": "config.amazonaws.com"
}
GetGatewayTarget
#Description
GetGatewayTarget recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "c8059604-06e3-44ed-824f-1e7c763136ed",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetGatewayTarget",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "03655fcd-42c5-420b-8aba-302d6b90ed79",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/E,i"
}
GetMemory
#Description
GetMemory recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b2efd395-997b-4536-a537-6cea0802ef24",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetMemory",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "cb2c8d0a-336b-446c-9d88-5e557a570c93",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g"
}
GetOnlineEvaluationConfig
#Description
GetOnlineEvaluationConfig recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "929fefb4-9b90-4116-b635-f5ec7f7a4e32",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetOnlineEvaluationConfig",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "4111f7ac-824c-421d-8e53-8e82d017cf35",
"userAgent": "config.amazonaws.com"
}
GetPolicyEngine
#Description
GetPolicyEngine recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "98d2384e-f6b1-4ad7-bef8-23d5a9654bc6",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetPolicyEngine",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "a55de681-db3f-4f9b-b01f-6944cfe0f345",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/E,i"
}
GetWorkloadIdentity
#Description
GetWorkloadIdentity recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "dccd2bea-1cf3-4f82-a3ec-4a534fb2aae4",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "GetWorkloadIdentity",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "dd39f3cf-a5f2-4915-a5c9-0c800d747a62",
"userAgent": "config.amazonaws.com"
}
ListAgentRuntimeEndpoints
#Description
ListAgentRuntimeEndpoints recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "aebc6f0b-c8ef-4eb9-bef1-ac328b3bbfc5",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListAgentRuntimeEndpoints",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "ffaf6c1e-0fe8-4f11-9955-43dd5309e5da",
"userAgent": "config.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
ListAgentRuntimes
#Description
ListAgentRuntimes recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "7a82b5b1-c4cb-485b-88a2-2a6e333a1d8d",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListAgentRuntimes",
"awsRegion": "ap-northeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "b4c1234f-3ce2-488c-b5b6-5b5e1a66c608",
"userAgent": "config.amazonaws.com"
}
ListAgentRuntimeVersions
#Description
ListAgentRuntimeVersions recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ed19517d-2c8d-47ae-9a4d-fbeaeb845666",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListAgentRuntimeVersions",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "5dd07ef4-592c-4741-a0db-9181726c1d19",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/C,E,i",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/EXAMPLE"
}
]
}
ListBrowsers
#Description
ListBrowsers recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e820d17f-5b58-4441-8664-386ec8db01b3",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListBrowsers",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "48caf330-91da-4d6b-a88a-7190b5d3f979",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/C,E,i"
}
ListCodeInterpreters
#Description
ListCodeInterpreters recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "88c96b9b-ac3e-46ed-8e71-7adba4d8f0f6",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListCodeInterpreters",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "fd417a11-6834-427a-bdc1-81d4312b8c34",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/C,E,i"
}
ListEvaluators
#Description
ListEvaluators recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b6222999-be54-4517-b0c9-11a84cc03fa7",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListEvaluators",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "75b35e29-9f15-4fdd-a62c-994c774a0e99",
"userAgent": "config.amazonaws.com"
}
ListGatewayTargets
#Description
ListGatewayTargets recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ae1c4d47-c48e-4304-b8ef-2f4447bbbdf8",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListGatewayTargets",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "59feba78-71f5-48b5-9d4c-115f3ded92fb",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/C,E,i"
}
ListHarnesses
#Description
ListHarnesses recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "be90873a-10c0-4835-88b7-0cc1cee4fd7a",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListHarnesses",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "75d7ab2d-175f-4f83-8969-cab830c7ee0d",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:us-east-1:123456789012:harness/EXAMPLE"
}
]
}
ListMemories
#Description
ListMemories recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "89f13eaa-295b-4f09-a1d1-fff18935b07a",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListMemories",
"awsRegion": "eu-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "ded8787c-0ca2-419f-bea5-bbff1c02ca70",
"userAgent": "config.amazonaws.com"
}
ListOnlineEvaluationConfigs
#Description
ListOnlineEvaluationConfigs recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d809ddef-ab64-4a6d-8b12-f3f230aab944",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListOnlineEvaluationConfigs",
"awsRegion": "eu-central-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "f75d699e-81df-407a-9b88-ed4cd948f54b",
"userAgent": "config.amazonaws.com"
}
ListPolicyEngines
#Description
ListPolicyEngines recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "2e498f93-d077-4f7b-8207-09f599442be7",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListPolicyEngines",
"awsRegion": "ap-southeast-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "70a8c725-f36e-4c48-97aa-6e4af0e75ead",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.28.1 m/C,E,i"
}
ListWorkloadIdentities
#Description
ListWorkloadIdentities recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "efc3205b-d0cf-48d5-85f8-72048b76814b",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "ListWorkloadIdentities",
"awsRegion": "sa-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "818e3df1-9acb-4540-a031-a16bf64b13ee",
"userAgent": "config.amazonaws.com"
}
UpdateAgentRuntime
#Description
UpdateAgentRuntime recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a44bf6b0-d3cd-4fbf-884d-215d41311ced",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "UpdateAgentRuntime",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "9f5626ab-558c-41c9-870d-820a12264b3a",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:eu-west-1:123456789012:runtime/EXAMPLE"
}
]
}
UpdateAgentRuntimeEndpoint
#Description
UpdateAgentRuntimeEndpoint recorded by CloudTrail for Amazon Bedrock AgentCore. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "69944afe-9d43-4ee8-9e8f-da98c619a6a4",
"eventSource": "bedrock-agentcore.amazonaws.com",
"eventName": "UpdateAgentRuntimeEndpoint",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "5584e1a2-d60d-4aaa-aa1f-687c1b64c51a",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.49.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.41.12 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/bedrockagentcorecontrol#1.42.3 m/g",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::Runtime",
"ARN": "arn:aws:bedrock-agentcore:eu-west-1:123456789012:runtime/EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::BedrockAgentCore::RuntimeEndpoint",
"ARN": "arn:aws:bedrock-agentcore:eu-west-1:123456789012:runtime/EXAMPLE"
}
]
}
DeleteCapacityProviderSession
#Description
Deletes a session associated with a capacity provider in Amazon Bedrock AgentCore and makes the session unavailable for further use. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.