AWS Cost Explorer Service

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Cost Explorer Service rules that match the service but not a specific eventName.NN
CreateAnomalyMonitorCreates a new cost anomaly detection monitor with the requested type and monitor specification. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateAnomalySubscriptionAdds an alert subscription to a cost anomaly detection monitor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateCostCategoryDefinitionCreates a new cost category with the requested name and rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteAnomalyMonitorDeletes a cost anomaly monitor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteAnomalySubscriptionDeletes a cost anomaly subscription. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteCostCategoryDefinitionDeletes a cost category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeCostCategoryDefinitionReturns the name, Amazon Resource Name (ARN), rules, definition, and effective dates of a cost category that's defined in the account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetAnomaliesRetrieves all of the cost anomalies detected on your account during the time period that's specified by the DateInterval object. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetAnomalyMonitorsRetrieves the cost anomaly monitor definitions for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetAnomalySubscriptionsRetrieves the cost anomaly subscription objects for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetApproximateUsageRecordsRetrieves estimated usage records for hourly granularity or resource-level data at daily granularity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetCommitmentPurchaseAnalysisRetrieves a commitment purchase analysis result based on the AnalysisId. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetCostAndUsageRetrieves cost and usage metrics for your account.YN
GetCostAndUsageComparisonsRetrieves cost and usage comparisons for your account between two periods within the last 13 months. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetCostAndUsageWithResourcesRetrieves cost and usage metrics with resources for your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetCostCategoriesRetrieves an array of cost category names and values incurred cost. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetCostComparisonDriversRetrieves key factors driving cost changes between two time periods within the last 13 months, such as usage changes, discount changes, and commitment-based savings. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetCostForecastRetrieves a forecast for how much Amazon Web Services predicts that you will spend over the forecast time period that you select, based on your past costs.YN
GetDimensionValuesRetrieves all available filter values for a specified filter over a period of time. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetReservationCoverageRetrieves the reservation coverage for your account, which you can use to see how much of your Amazon Elastic Compute Cloud, Amazon ElastiCache, Amazon Relational Database Service, or Amazon Redshift usage is covered by a reservation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetReservationPurchaseRecommendationGets recommendations for reservation purchases. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetReservationUtilizationRetrieves the reservation utilization for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetRightsizingRecommendationCreates recommendations that help you save cost by identifying idle and underutilized Amazon EC2 instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSavingsPlanPurchaseRecommendationDetailsRetrieves the details for a Savings Plan recommendation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSavingsPlansCoverageRetrieves the Savings Plans covered for your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSavingsPlansPurchaseRecommendationRetrieves the Savings Plans recommendations for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetSavingsPlansUtilizationRetrieves the Savings Plans utilization for your account across date ranges with daily or monthly granularity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSavingsPlansUtilizationDetailsRetrieves attribute data along with aggregate utilization and savings data for a given time period. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetTagsQueries for available tag keys and tag values for a specified period. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetUsageForecastRetrieves a forecast for how much Amazon Web Services predicts that you will use over the forecast time period that you select, based on your past usage. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListCommitmentPurchaseAnalysesLists the commitment purchase analyses for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCostAllocationTagBackfillHistoryRetrieves a list of your historical cost allocation tag backfill requests. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCostAllocationTagsGet a list of cost allocation tags. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCostCategoryDefinitionsReturns the name, Amazon Resource Name (ARN), NumberOfRules and effective dates of all cost categories defined in the account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCostCategoryResourceAssociationsReturns resource associations of all cost categories defined in the account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListSavingsPlansPurchaseRecommendationGenerationRetrieves a list of your historical recommendation generations within the past 30 days. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceReturns a list of resource tags associated with the resource specified by the Amazon Resource Name (ARN). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ProvideAnomalyFeedbackModifies the feedback property of a given cost anomaly. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartCommitmentPurchaseAnalysisSpecifies the parameters of a planned commitment purchase and starts the generation of the analysis. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
StartCostAllocationTagBackfillRequest a cost allocation tag backfill. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartSavingsPlansPurchaseRecommendationGenerationRequests a Savings Plans recommendation generation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceAn API operation for adding one or more tags (key-value pairs) to a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves one or more tags from a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAnomalyMonitorUpdates an existing cost anomaly monitor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAnomalySubscriptionUpdates an existing cost anomaly subscription. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateCostAllocationTagsStatusUpdates status for cost allocation tags in bulk, with maximum batch size of 20. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateCostCategoryDefinitionUpdates an existing cost category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetConsoleActionSetEnforcedGetConsoleActionSetEnforced recorded by CloudTrail for AWS Cost Explorer Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetPreferencesGetPreferences recorded by CloudTrail for AWS Cost Explorer Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN

any: AWS Cost Explorer Service (catch-all)

#
Service
ce

Description

Catch-all entry for AWS Cost Explorer Service rules that match the service but not a specific eventName.

CreateAnomalyMonitor

#
Service
ce

Description

Creates a new cost anomaly detection monitor with the requested type and monitor specification. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateAnomalySubscription

#
Service
ce

Description

Adds an alert subscription to a cost anomaly detection monitor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateCostCategoryDefinition

#
Service
ce

Description

Creates a new cost category with the requested name and rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteAnomalyMonitor

#
Service
ce

Description

Deletes a cost anomaly monitor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteAnomalySubscription

#
Service
ce

Description

Deletes a cost anomaly subscription. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteCostCategoryDefinition

#
Service
ce

Description

Deletes a cost category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeCostCategoryDefinition

#
Service
ce

Description

Returns the name, Amazon Resource Name (ARN), rules, definition, and effective dates of a cost category that's defined in the account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9b6aad83-fba1-4566-84ae-6a9b37e4d4dd",
  "eventSource": "ce.amazonaws.com",
  "eventName": "DescribeCostCategoryDefinition",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "399a4001-099e-4131-be6e-d2d64364a0df",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetAnomalies

#
Service
ce

Description

Retrieves all of the cost anomalies detected on your account during the time period that's specified by the DateInterval object. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "25c6c49b-1f1d-45ff-9758-c3ebe5fd1d26",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetAnomalies",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4482d362-9d17-4a2b-8c8e-4baab0ee388e",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetAnomalyMonitors

#
Service
ce

Description

Retrieves the cost anomaly monitor definitions for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "01045ca8-00a1-49f0-937b-4bf6f47034dc",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetAnomalyMonitors",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d913f804-6c0a-4c45-ad2b-fab80cb9b68b",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetAnomalySubscriptions

#
Service
ce

Description

Retrieves the cost anomaly subscription objects for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b2b189a1-e4bd-43a2-a51c-4a8f5bd753c4",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetAnomalySubscriptions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f439c9d1-15ea-4485-af8d-158265b04920",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetApproximateUsageRecords

#
Service
ce

Description

Retrieves estimated usage records for hourly granularity or resource-level data at daily granularity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetCommitmentPurchaseAnalysis

#
Service
ce

Description

Retrieves a commitment purchase analysis result based on the AnalysisId. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0cc99c01-3d03-457f-9ef3-660dfa35010f",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetCommitmentPurchaseAnalysis",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3c4ca725-1dd3-4ce3-bd08-a6bc8e87b06c",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetCostAndUsage

#
Service
ce

Description

Retrieves cost and usage metrics for your account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ce:GetCostAndUsage on resource: arn:aws:ce:us-east-1:192374575148:/GetCostAndUsage because no identity-based policy allows the ce:GetCostAndUsage action",
  "eventCategory": "Management",
  "eventID": "523dd8eb-f0f8-42ba-90ba-8028d6932d0f",
  "eventName": "GetCostAndUsage",
  "eventSource": "ce.amazonaws.com",
  "eventTime": "2024-08-18T10:35:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9d083f28-9a5a-41df-8423-d29628fd920a",
  "requestParameters": {
    "Granularity": "MONTHLY",
    "GroupBy": [
      {
        "Key": "SERVICE",
        "Type": "DIMENSION"
      },
      {
        "Key": "Environment",
        "Type": "TAG"
      }
    ],
    "Metrics": [
      "BlendedCost",
      "UnblendedCost",
      "UsageQuantity"
    ],
    "TimePeriod": {
      "End": "2017-10-01",
      "Start": "2017-09-01"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ce.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_bd0abf2e-af3a-45e8-a501-60ab86db3a6f cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ce.get-cost-and-usage",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

References #

GetCostAndUsageComparisons

#
Service
ce

Description

Retrieves cost and usage comparisons for your account between two periods within the last 13 months. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4e39cbca-35e6-4692-9a1f-b0a379cc2237",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetCostAndUsageComparisons",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "133ecf59-1f4f-445b-9774-50d2e5d2c845",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetCostAndUsageWithResources

#
Service
ce

Description

Retrieves cost and usage metrics with resources for your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetCostCategories

#
Service
ce

Description

Retrieves an array of cost category names and values incurred cost. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1190a66e-f443-4874-b9ec-a693e06bde7a",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetCostCategories",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e2013e08-1e6d-453a-9669-382a468dbcc9",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetCostComparisonDrivers

#
Service
ce

Description

Retrieves key factors driving cost changes between two time periods within the last 13 months, such as usage changes, discount changes, and commitment-based savings. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetCostForecast

#
Service
ce

Description

Retrieves a forecast for how much Amazon Web Services predicts that you will spend over the forecast time period that you select, based on your past costs.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "AssumedRole",
    "principalId": "AROA****************:User",
    "arn": "arn:aws:sts::123456789012:assumed-role/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b/AdanAlvarez",
    "accountId": "123456789012",
    "accessKeyId": "AKIA****************",
    "sessionContext": {
      "sessionIssuer": {
        "type": "Role",
        "principalId": "AROA****************:User",
        "arn": "arn:aws:iam::123456789012:role/aws-reserved/sso.amazonaws.com/us-east-2/AWSReservedSSO_AdministratorAccess_1b74cd717d47002b",
        "accountId": "123456789012",
        "userName": "AWSReservedSSO_AdministratorAccess_1b74cd717d47002b"
      },
      "attributes": {
        "creationDate": "2025-10-12T14:55:21Z",
        "mfaAuthenticated": "false"
      }
    },
    "inScopeOf": {}
  },
  "eventTime": "2025-10-12T14:55:33Z",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetCostForecast",
  "awsRegion": "us-east-1",
  "sourceIPAddress": "0.0.0.0",
  "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/0.0.0.0 Safari/537.36",
  "errorCode": "InternalFailure",
  "errorMessage": "We messed up somewhere, sorry. There was an internal error with the service.",
  "requestParameters": {
    "Filter": {
      "Not": {
        "Or": [
          {
            "Dimensions": {
              "Key": "RECORD_TYPE",
              "Values": [
                "Credit"
              ]
            }
          },
          {
            "Dimensions": {
              "Key": "RECORD_TYPE",
              "Values": [
                "Refund"
              ]
            }
          }
        ]
      }
    },
    "Granularity": "MONTHLY",
    "Metric": "NET_UNBLENDED_COST",
    "TimePeriod": {
      "Start": "2025-10-12",
      "End": "2025-11-01"
    }
  },
  "responseElements": null,
  "requestID": "32a1644b-5a7a-4fac-b9bc-24402127bc4f",
  "eventID": "08194c17-c516-4c6d-9a71-2814da709c18",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ce.us-east-1.amazonaws.com"
  }
}

References #

GetDimensionValues

#
Service
ce

Description

Retrieves all available filter values for a specified filter over a period of time. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "18016778-ff8f-483b-adfb-375f90b30675",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetDimensionValues",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "aff388c3-62d4-426c-8021-5d1b2ec22d69",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetReservationCoverage

#
Service
ce

Description

Retrieves the reservation coverage for your account, which you can use to see how much of your Amazon Elastic Compute Cloud, Amazon ElastiCache, Amazon Relational Database Service, or Amazon Redshift usage is covered by a reservation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetReservationPurchaseRecommendation

#
Service
ce

Description

Gets recommendations for reservation purchases. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "265a0960-668f-430f-900a-399993b9333c",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetReservationPurchaseRecommendation",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "2a8f66bf-9790-4779-a32e-02611f70d7ef",
  "userAgent": "trustedadvisor.amazonaws.com",
  "errorCode": "ValidationException"
}

GetReservationUtilization

#
Service
ce

Description

Retrieves the reservation utilization for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1c8b5760-7521-479b-b49d-f267ec54d570",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetReservationUtilization",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "6523bb33-1a5a-48f5-9944-5fb5eb54c5d2",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetRightsizingRecommendation

#
Service
ce

Description

Creates recommendations that help you save cost by identifying idle and underutilized Amazon EC2 instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSavingsPlanPurchaseRecommendationDetails

#
Service
ce

Description

Retrieves the details for a Savings Plan recommendation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSavingsPlansCoverage

#
Service
ce

Description

Retrieves the Savings Plans covered for your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSavingsPlansPurchaseRecommendation

#
Service
ce

Description

Retrieves the Savings Plans recommendations for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "31f22c02-166e-4785-a70e-c366df0ad500",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetSavingsPlansPurchaseRecommendation",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c45d6bb2-921b-4314-9430-323e5c24a1e1",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetSavingsPlansUtilization

#
Service
ce

Description

Retrieves the Savings Plans utilization for your account across date ranges with daily or monthly granularity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSavingsPlansUtilizationDetails

#
Service
ce

Description

Retrieves attribute data along with aggregate utilization and savings data for a given time period. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e3e8559b-7d3a-4f86-a55c-546536a73713",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetSavingsPlansUtilizationDetails",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f8a86744-f934-4cb4-8b41-ef87ee3f7690",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetTags

#
Service
ce

Description

Queries for available tag keys and tag values for a specified period. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetUsageForecast

#
Service
ce

Description

Retrieves a forecast for how much Amazon Web Services predicts that you will use over the forecast time period that you select, based on your past usage. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListCommitmentPurchaseAnalyses

#
Service
ce

Description

Lists the commitment purchase analyses for your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f7d7b483-c51f-4a29-869c-dd585b474444",
  "eventSource": "ce.amazonaws.com",
  "eventName": "ListCommitmentPurchaseAnalyses",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "edfe6fb4-23e3-4a61-89ce-7f2697f23cb7",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListCostAllocationTagBackfillHistory

#
Service
ce

Description

Retrieves a list of your historical cost allocation tag backfill requests. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4fea7a2f-a015-4ef7-8060-559c283f7f4e",
  "eventSource": "ce.amazonaws.com",
  "eventName": "ListCostAllocationTagBackfillHistory",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "93fab96a-cf60-499d-af35-9704a45b7025",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListCostAllocationTags

#
Service
ce

Description

Get a list of cost allocation tags. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "75dd26ee-928c-4580-885f-b2b30a6542cd",
  "eventSource": "ce.amazonaws.com",
  "eventName": "ListCostAllocationTags",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b7c944ab-0cbe-413f-bf95-86f0e0c9135d",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListCostCategoryDefinitions

#
Service
ce

Description

Returns the name, Amazon Resource Name (ARN), NumberOfRules and effective dates of all cost categories defined in the account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6044ff6a-b1df-4f6e-8dc8-43b8f48f856d",
  "eventSource": "ce.amazonaws.com",
  "eventName": "ListCostCategoryDefinitions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "89eff341-bf72-4d3f-9f33-d3c629277a3e",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListCostCategoryResourceAssociations

#
Service
ce

Description

Returns resource associations of all cost categories defined in the account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListSavingsPlansPurchaseRecommendationGeneration

#
Service
ce

Description

Retrieves a list of your historical recommendation generations within the past 30 days. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5343e224-aff8-467a-a960-7da29b538d34",
  "eventSource": "ce.amazonaws.com",
  "eventName": "ListSavingsPlansPurchaseRecommendationGeneration",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "068ffe5c-debc-4211-8c23-02351879c070",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListTagsForResource

#
Service
ce

Description

Returns a list of resource tags associated with the resource specified by the Amazon Resource Name (ARN). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ProvideAnomalyFeedback

#
Service
ce

Description

Modifies the feedback property of a given cost anomaly. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartCommitmentPurchaseAnalysis

#
Service
ce

Description

Specifies the parameters of a planned commitment purchase and starts the generation of the analysis. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "92c2f645-3623-446e-970b-8f6b2d4b1392",
  "eventSource": "ce.amazonaws.com",
  "eventName": "StartCommitmentPurchaseAnalysis",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "48bd8841-136c-472d-b668-e6c53225629a",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

StartCostAllocationTagBackfill

#
Service
ce

Description

Request a cost allocation tag backfill. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartSavingsPlansPurchaseRecommendationGeneration

#
Service
ce

Description

Requests a Savings Plans recommendation generation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
ce

Description

An API operation for adding one or more tags (key-value pairs) to a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
ce

Description

Removes one or more tags from a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAnomalyMonitor

#
Service
ce

Description

Updates an existing cost anomaly monitor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAnomalySubscription

#
Service
ce

Description

Updates an existing cost anomaly subscription. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateCostAllocationTagsStatus

#
Service
ce

Description

Updates status for cost allocation tags in bulk, with maximum batch size of 20. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateCostCategoryDefinition

#
Service
ce

Description

Updates an existing cost category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetConsoleActionSetEnforced

#
Service
ce

Description

GetConsoleActionSetEnforced recorded by CloudTrail for AWS Cost Explorer Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6d20d7d4-9017-4138-905d-15cde78a463d",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetConsoleActionSetEnforced",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "88883d3b-6793-4990-b12e-bcf0efeacbb3",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetPreferences

#
Service
ce

Description

GetPreferences recorded by CloudTrail for AWS Cost Explorer Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d2e76f02-24ad-4d25-bb28-944327495970",
  "eventSource": "ce.amazonaws.com",
  "eventName": "GetPreferences",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e2ff9279-fb11-4214-9a5b-7efe917b079a",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}