AWS DataSync

eventNameDescriptionSampleRule
anyCatch-all entry for AWS DataSync rules that match the service but not a specific eventName.NN
CancelTaskExecutionStops an DataSync task execution that's in progress. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateAgentActivates an DataSync agent that you deploy in your storage environment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationAzureBlobCreates a transfer location for a Microsoft Azure Blob Storage container. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationEfsCreates a transfer location for an Amazon EFS file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationFsxLustreCreates a transfer location for an Amazon FSx for Lustre file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationFsxOntapCreates a transfer location for an Amazon FSx for NetApp ONTAP file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationFsxOpenZfsCreates a transfer location for an Amazon FSx for OpenZFS file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationFsxWindowsCreates a transfer location for an Amazon FSx for Windows File Server file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationHdfsCreates a transfer location for a Hadoop Distributed File System (HDFS). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationNfsCreates a transfer location for a Network File System (NFS) file server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationObjectStorageCreates a transfer location for an object storage system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationS3Creates a transfer location for an Amazon S3 bucket. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLocationSmbCreates a transfer location for a Server Message Block (SMB) file server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateTaskConfigures a task, which defines where and how DataSync transfers your data.YY
DeleteAgentRemoves an DataSync agent resource from your Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteLocationDeletes a transfer location resource from DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteTaskDeletes a transfer task resource from DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeAgentReturns information about an DataSync agent, such as its name, service endpoint type, and status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationAzureBlobProvides details about how an DataSync transfer location for Microsoft Azure Blob Storage is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationEfsProvides details about how an DataSync transfer location for an Amazon EFS file system is configured. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeLocationFsxLustreProvides details about how an DataSync transfer location for an Amazon FSx for Lustre file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationFsxOntapProvides details about how an DataSync transfer location for an Amazon FSx for NetApp ONTAP file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationFsxOpenZfsProvides details about how an DataSync transfer location for an Amazon FSx for OpenZFS file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationFsxWindowsProvides details about how an DataSync transfer location for an Amazon FSx for Windows File Server file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationHdfsProvides details about how an DataSync transfer location for a Hadoop Distributed File System (HDFS) is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationNfsProvides details about how an DataSync transfer location for a Network File System (NFS) file server is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationObjectStorageProvides details about how an DataSync transfer location for an object storage system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationS3Provides details about how an DataSync transfer location for an S3 bucket is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLocationSmbProvides details about how an DataSync transfer location for a Server Message Block (SMB) file server is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeTaskProvides information about a task, which defines where and how DataSync transfers your data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeTaskExecutionProvides information about an execution of your DataSync task. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListAgentsReturns a list of DataSync agents that belong to an Amazon Web Services account in the Amazon Web Services Region specified in the request. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListLocationsReturns a list of source and destination locations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceReturns all the tags associated with an Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTaskExecutionsReturns a list of executions for an DataSync transfer task. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTasksReturns a list of the DataSync tasks you created. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartTaskExecutionStarts an DataSync transfer task. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceApplies a tag to an Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves tags from an Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAgentUpdates the name of an DataSync agent. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationAzureBlobModifies the following configurations of the Microsoft Azure Blob Storage transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationEfsModifies the following configuration parameters of the Amazon EFS transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationFsxLustreModifies the following configuration parameters of the Amazon FSx for Lustre transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationFsxOntapModifies the following configuration parameters of the Amazon FSx for NetApp ONTAP transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationFsxOpenZfsModifies the following configuration parameters of the Amazon FSx for OpenZFS transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationFsxWindowsModifies the following configuration parameters of the Amazon FSx for Windows File Server transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationHdfsModifies the following configuration parameters of the Hadoop Distributed File System (HDFS) transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationNfsModifies the following configuration parameters of the Network File System (NFS) transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationObjectStorageModifies the following configuration parameters of the object storage transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationS3Modifies the following configuration parameters of the Amazon S3 transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLocationSmbModifies the following configuration parameters of the Server Message Block (SMB) transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTaskUpdates the configuration of a task, which defines where and how DataSync transfers your data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTaskExecutionUpdates the configuration of a running DataSync task execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: AWS DataSync (catch-all)

#
Service
datasync

Description

Catch-all entry for AWS DataSync rules that match the service but not a specific eventName.

CancelTaskExecution

#
Service
datasync

Description

Stops an DataSync task execution that's in progress. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateAgent

#
Service
datasync

Description

Activates an DataSync agent that you deploy in your storage environment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationAzureBlob

#
Service
datasync

Description

Creates a transfer location for a Microsoft Azure Blob Storage container. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationEfs

#
Service
datasync

Description

Creates a transfer location for an Amazon EFS file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationFsxLustre

#
Service
datasync

Description

Creates a transfer location for an Amazon FSx for Lustre file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationFsxOntap

#
Service
datasync

Description

Creates a transfer location for an Amazon FSx for NetApp ONTAP file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationFsxOpenZfs

#
Service
datasync

Description

Creates a transfer location for an Amazon FSx for OpenZFS file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationFsxWindows

#
Service
datasync

Description

Creates a transfer location for an Amazon FSx for Windows File Server file system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationHdfs

#
Service
datasync

Description

Creates a transfer location for a Hadoop Distributed File System (HDFS). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationNfs

#
Service
datasync

Description

Creates a transfer location for a Network File System (NFS) file server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationObjectStorage

#
Service
datasync

Description

Creates a transfer location for an object storage system. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationS3

#
Service
datasync

Description

Creates a transfer location for an Amazon S3 bucket. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLocationSmb

#
Service
datasync

Description

Creates a transfer location for a Server Message Block (SMB) file server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateTask

#
Service
datasync

Description

Configures a task, which defines where and how DataSync transfers your data.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "def4cd05-f845-4aec-bc96-07d6ce420d16",
  "eventName": "CreateTask",
  "eventSource": "datasync.amazonaws.com",
  "eventTime": "2023-03-14T22:05:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "de5f4282-aa2b-49b8-8d1b-c3bdb11e2fba",
  "requestParameters": {
    "cloudWatchLogGroupArn": "arn:aws:logs:us-west-2:111111111111:log-group:/aws/datasync",
    "destinationLocationArn": "arn:aws:datasync:us-west-1:111111111111:location/loc-0b94cf657c358ef06",
    "excludes": [],
    "includes": [],
    "options": {
      "logLevel": "BASIC",
      "verifyMode": "ONLY_FILES_TRANSFERRED"
    },
    "schedule": {
      "scheduleExpression": "cron(6 * * * ? *)"
    },
    "sourceLocationArn": "arn:aws:datasync:us-west-2:111111111111:location/loc-0921d426f7955d416",
    "tags": []
  },
  "responseElements": {
    "taskArn": "arn:aws:datasync:us-west-2:111111111111:task/task-0c77dc0d4b0792ce6"
  },
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "1.1.1.1",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLOB2GM111",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com",
    "principalId": "AROAYTOGP2RLDF6WQQQQQ:abc@acme.com",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-03-14T21:53:15Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
        "principalId": "AROAYTOGP2RLDF6WQQQQQ",
        "type": "Role",
        "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • AWS Exfiltration via DataSync Task source: The following analytic detects the creation of an AWS DataSync task, which could indicate potential data exfiltration. It leverages AWS CloudTrail logs to identify the CreateTask event from the DataSync service. This activity is…T1119

References #

DeleteAgent

#
Service
datasync

Description

Removes an DataSync agent resource from your Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteLocation

#
Service
datasync

Description

Deletes a transfer location resource from DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteTask

#
Service
datasync

Description

Deletes a transfer task resource from DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeAgent

#
Service
datasync

Description

Returns information about an DataSync agent, such as its name, service endpoint type, and status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationAzureBlob

#
Service
datasync

Description

Provides details about how an DataSync transfer location for Microsoft Azure Blob Storage is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationEfs

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an Amazon EFS file system is configured. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ee96289d-243d-4bd4-ad02-09ec1820e3ee",
  "eventSource": "datasync.amazonaws.com",
  "eventName": "DescribeLocationEfs",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7b799143-7b45-469b-a455-4a027b4930ff",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/datasync#1.57.1 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

DescribeLocationFsxLustre

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an Amazon FSx for Lustre file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationFsxOntap

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an Amazon FSx for NetApp ONTAP file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationFsxOpenZfs

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an Amazon FSx for OpenZFS file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationFsxWindows

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an Amazon FSx for Windows File Server file system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationHdfs

#
Service
datasync

Description

Provides details about how an DataSync transfer location for a Hadoop Distributed File System (HDFS) is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationNfs

#
Service
datasync

Description

Provides details about how an DataSync transfer location for a Network File System (NFS) file server is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationObjectStorage

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an object storage system is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationS3

#
Service
datasync

Description

Provides details about how an DataSync transfer location for an S3 bucket is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLocationSmb

#
Service
datasync

Description

Provides details about how an DataSync transfer location for a Server Message Block (SMB) file server is configured. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeTask

#
Service
datasync

Description

Provides information about a task, which defines where and how DataSync transfers your data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeTaskExecution

#
Service
datasync

Description

Provides information about an execution of your DataSync task. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListAgents

#
Service
datasync

Description

Returns a list of DataSync agents that belong to an Amazon Web Services account in the Amazon Web Services Region specified in the request. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3d68f44e-1126-4587-8e4c-6828bd704cc4",
  "eventSource": "datasync.amazonaws.com",
  "eventName": "ListAgents",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "2828457e-d738-422e-a003-ab810ea94239",
  "userAgent": "config.amazonaws.com"
}

ListLocations

#
Service
datasync

Description

Returns a list of source and destination locations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f380df85-5aa8-4bcc-bb86-d6dbb015fd64",
  "eventSource": "datasync.amazonaws.com",
  "eventName": "ListLocations",
  "awsRegion": "ap-southeast-4",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7fe3e91d-cfe9-4d17-a9d1-f341ecbeb577",
  "userAgent": "config.amazonaws.com"
}

ListTagsForResource

#
Service
datasync

Description

Returns all the tags associated with an Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTaskExecutions

#
Service
datasync

Description

Returns a list of executions for an DataSync transfer task. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f5ac70b2-46fb-493c-a7ca-d3b1ed000d9e",
  "eventSource": "datasync.amazonaws.com",
  "eventName": "ListTaskExecutions",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f50459be-00f6-48ec-8f88-0b8515c4022d",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListTasks

#
Service
datasync

Description

Returns a list of the DataSync tasks you created. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartTaskExecution

#
Service
datasync

Description

Starts an DataSync transfer task. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
datasync

Description

Applies a tag to an Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
datasync

Description

Removes tags from an Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAgent

#
Service
datasync

Description

Updates the name of an DataSync agent. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationAzureBlob

#
Service
datasync

Description

Modifies the following configurations of the Microsoft Azure Blob Storage transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationEfs

#
Service
datasync

Description

Modifies the following configuration parameters of the Amazon EFS transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationFsxLustre

#
Service
datasync

Description

Modifies the following configuration parameters of the Amazon FSx for Lustre transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationFsxOntap

#
Service
datasync

Description

Modifies the following configuration parameters of the Amazon FSx for NetApp ONTAP transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationFsxOpenZfs

#
Service
datasync

Description

Modifies the following configuration parameters of the Amazon FSx for OpenZFS transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationFsxWindows

#
Service
datasync

Description

Modifies the following configuration parameters of the Amazon FSx for Windows File Server transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationHdfs

#
Service
datasync

Description

Modifies the following configuration parameters of the Hadoop Distributed File System (HDFS) transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationNfs

#
Service
datasync

Description

Modifies the following configuration parameters of the Network File System (NFS) transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationObjectStorage

#
Service
datasync

Description

Modifies the following configuration parameters of the object storage transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationS3

#
Service
datasync

Description

Modifies the following configuration parameters of the Amazon S3 transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLocationSmb

#
Service
datasync

Description

Modifies the following configuration parameters of the Server Message Block (SMB) transfer location that you're using with DataSync. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTask

#
Service
datasync

Description

Updates the configuration of a task, which defines where and how DataSync transfers your data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTaskExecution

#
Service
datasync

Description

Updates the configuration of a running DataSync task execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.