AWS billingconsole
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS billingconsole rules that match the service but not a specific eventName. | N | N |
| AWSPayment | AWSPaymentPortalService.DescribePaymentsDashboard recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| AWSPayment | AWSPaymentPortalService.GetAccountPreferences recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| AWSPayment | AWSPaymentPortalService.GetPaymentsDue recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetBillingNotifications recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetIAMAccessPreference recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetPaymentPreference recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetPublicSectorCustomerContract recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetSellerOfRecord recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListRegions recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
any: AWS billingconsole (catch-all)
#Description
Catch-all entry for AWS billingconsole rules that match the service but not a specific eventName.
AWSPaymentPortalService.DescribePaymentsDashboard
#Description
AWSPaymentPortalService.DescribePaymentsDashboard recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f701fd0f-3ad3-4580-84c7-1e1c027a8d71",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "AWSPaymentPortalService.DescribePaymentsDashboard",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "d8960f7d-c4c6-4693-a716-ee5eae94561c",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
AWSPaymentPortalService.GetAccountPreferences
#Description
AWSPaymentPortalService.GetAccountPreferences recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "82a978d4-1601-4003-b3ae-2ff2e6915fab",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "AWSPaymentPortalService.GetAccountPreferences",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "04a222c5-6f26-4292-899a-25bbe9b413a1",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
AWSPaymentPortalService.GetPaymentsDue
#Description
AWSPaymentPortalService.GetPaymentsDue recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "3e07cba8-f950-4e74-97f3-b93aef6051b0",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "AWSPaymentPortalService.GetPaymentsDue",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "66dc95a4-ef8a-4b77-a863-4a14aee8d171",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
GetBillingNotifications
#Description
GetBillingNotifications recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b091730f-62d3-43bf-8acb-e79c732bbc2e",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "GetBillingNotifications",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "6aab3655-3add-4624-822c-256d48cc8634",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"tlsDetails": {
"clientProvidedHostHeader": "example.aws.dev"
}
}
GetIAMAccessPreference
#Description
GetIAMAccessPreference recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "28a31cbf-160b-48ca-9b02-988e72d0ad52",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "GetIAMAccessPreference",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "f6cf4871-c5e7-4e3d-b7ab-ee01cd90a8b3",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"errorCode": "AccessDenied",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "AES256-SHA",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
GetPaymentPreference
#Description
GetPaymentPreference recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "fe38ddcf-119f-4fbb-ba7e-cf2ba2c28644",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "GetPaymentPreference",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "30075fd9-025a-4da6-a087-d760181a7e06",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
GetPublicSectorCustomerContract
#Description
GetPublicSectorCustomerContract recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ebf39a68-9506-4aa8-989c-36d2f03f6f95",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "GetPublicSectorCustomerContract",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "6e50fb89-7093-47f6-b187-bdbee352840d",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"errorCode": "AccessDenied",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
GetSellerOfRecord
#Description
GetSellerOfRecord recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "333d70a9-20b6-4f8d-a00c-c177ec827888",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "GetSellerOfRecord",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "14d8baac-e438-4ea8-9357-00d77e05c819",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"errorCode": "AccessDenied",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}
ListRegions
#Description
ListRegions recorded by CloudTrail for AWS billingconsole. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b51b9aca-4667-4e23-9452-42cd471d4ff9",
"eventSource": "billingconsole.amazonaws.com",
"eventName": "ListRegions",
"awsRegion": "us-east-1",
"eventType": "AwsConsoleAction",
"readOnly": true,
"managementEvent": true,
"requestID": "5028bd02-e9fc-4bdd-a9ca-e22f5df8c362",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.aws.amazon.com"
}
}