CloudSearch

eventNameDescriptionSampleRule
anyCatch-all entry for CloudSearch rules that match the service but not a specific eventName.NN
BuildSuggestersIndexes the search suggestions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateDomainCreates a new search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DefineAnalysisSchemeConfigures an analysis scheme that can be applied to a text or text-array field to define language-specific text processing options. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DefineExpressionConfigures an Expression for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DefineIndexFieldConfigures an IndexField for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DefineRankExpressionConfigures a RankExpression for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DefineSuggesterConfigures a suggester for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteAnalysisSchemeDeletes an analysis scheme. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteDomainPermanently deletes a search domain and all of its data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteExpressionRemoves an Expression from the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteIndexFieldRemoves an IndexField from the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteRankExpressionRemoves a RankExpression from the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSuggesterDeletes a suggester. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeAnalysisSchemesGets the analysis schemes configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeAvailabilityOptionsGets the availability options configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDefaultSearchFieldGets the default search field configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDomainEndpointOptionsReturns the domain's endpoint options, specifically whether all requests to the domain must arrive over HTTPS. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDomainsGets information about the search domains owned by this account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeExpressionsGets the expressions configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeIndexFieldsGets information about the index fields configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeRankExpressionsGets the rank expressions configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeScalingParametersGets the scaling parameters configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeServiceAccessPoliciesGets information about the resource-based policies that control access to the domain's document and search services. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeStemmingOptionsGets the stemming dictionary configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeStopwordOptionsGets the stopwords configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeSuggestersGets the suggesters configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeSynonymOptionsGets the synonym dictionary configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
IndexDocumentsTells the search domain to start indexing its documents using the latest text processing options and IndexFields. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDomainNamesLists all search domains owned by an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAvailabilityOptionsConfigures the availability options for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDefaultSearchFieldConfigures the default search field for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDomainEndpointOptionsUpdates the domain's endpoint options, specifically whether all requests to the domain must arrive over HTTPS. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateScalingParametersConfigures scaling parameters for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateServiceAccessPoliciesConfigures the policies that control access to the domain's document and search services. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateStemmingOptionsConfigures a stemming dictionary for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateStopwordOptionsConfigures stopwords for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateSynonymOptionsConfigures a synonym dictionary for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: CloudSearch (catch-all)

#
Service
cloudsearch

Description

Catch-all entry for CloudSearch rules that match the service but not a specific eventName.

BuildSuggesters

#
Service
cloudsearch

Description

Indexes the search suggestions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateDomain

#
Service
cloudsearch

Description

Creates a new search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DefineAnalysisScheme

#
Service
cloudsearch

Description

Configures an analysis scheme that can be applied to a text or text-array field to define language-specific text processing options. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DefineExpression

#
Service
cloudsearch

Description

Configures an Expression for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DefineIndexField

#
Service
cloudsearch

Description

Configures an IndexField for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DefineRankExpression

#
Service
cloudsearch

Description

Configures a RankExpression for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DefineSuggester

#
Service
cloudsearch

Description

Configures a suggester for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteAnalysisScheme

#
Service
cloudsearch

Description

Deletes an analysis scheme. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteDomain

#
Service
cloudsearch

Description

Permanently deletes a search domain and all of its data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteExpression

#
Service
cloudsearch

Description

Removes an Expression from the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteIndexField

#
Service
cloudsearch

Description

Removes an IndexField from the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteRankExpression

#
Service
cloudsearch

Description

Removes a RankExpression from the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteSuggester

#
Service
cloudsearch

Description

Deletes a suggester. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeAnalysisSchemes

#
Service
cloudsearch

Description

Gets the analysis schemes configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeAvailabilityOptions

#
Service
cloudsearch

Description

Gets the availability options configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDefaultSearchField

#
Service
cloudsearch

Description

Gets the default search field configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDomainEndpointOptions

#
Service
cloudsearch

Description

Returns the domain's endpoint options, specifically whether all requests to the domain must arrive over HTTPS. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDomains

#
Service
cloudsearch

Description

Gets information about the search domains owned by this account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2b18af06-d3b5-46ac-869f-7c06476319c3",
  "eventSource": "cloudsearch.amazonaws.com",
  "eventName": "DescribeDomains",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e3513b97-4cd6-4a8e-ba33-1f1c4ebc528c",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/cloudsearch#1.27.4 m/E,i",
  "errorCode": "NotAuthorizedException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
  }
}

DescribeExpressions

#
Service
cloudsearch

Description

Gets the expressions configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeIndexFields

#
Service
cloudsearch

Description

Gets information about the index fields configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeRankExpressions

#
Service
cloudsearch

Description

Gets the rank expressions configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeScalingParameters

#
Service
cloudsearch

Description

Gets the scaling parameters configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeServiceAccessPolicies

#
Service
cloudsearch

Description

Gets information about the resource-based policies that control access to the domain's document and search services. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeStemmingOptions

#
Service
cloudsearch

Description

Gets the stemming dictionary configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeStopwordOptions

#
Service
cloudsearch

Description

Gets the stopwords configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeSuggesters

#
Service
cloudsearch

Description

Gets the suggesters configured for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeSynonymOptions

#
Service
cloudsearch

Description

Gets the synonym dictionary configured for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

IndexDocuments

#
Service
cloudsearch

Description

Tells the search domain to start indexing its documents using the latest text processing options and IndexFields. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDomainNames

#
Service
cloudsearch

Description

Lists all search domains owned by an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAvailabilityOptions

#
Service
cloudsearch

Description

Configures the availability options for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDefaultSearchField

#
Service
cloudsearch

Description

Configures the default search field for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDomainEndpointOptions

#
Service
cloudsearch

Description

Updates the domain's endpoint options, specifically whether all requests to the domain must arrive over HTTPS. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateScalingParameters

#
Service
cloudsearch

Description

Configures scaling parameters for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateServiceAccessPolicies

#
Service
cloudsearch

Description

Configures the policies that control access to the domain's document and search services. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateStemmingOptions

#
Service
cloudsearch

Description

Configures a stemming dictionary for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateStopwordOptions

#
Service
cloudsearch

Description

Configures stopwords for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateSynonymOptions

#
Service
cloudsearch

Description

Configures a synonym dictionary for the search domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.