Elastic Container Service
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Elastic Container Service rules that match the service but not a specific eventName. | N | N |
| Describe | Describes a task definition registered to Amazon ECS, returning its family, revision, container definitions, and configuration. | Y | Y |
| Register | Registers a new task definition from the supplied family and containerDefinitions, creating a new revision in Amazon ECS. | Y | Y |
| Run | Starts a new task on a specified cluster using the specified task definition. | N | Y |
| Continue | Continues or rolls back an Amazon ECS service deployment that is paused at a lifecycle hook. | N | N |
| Create | Creates a capacity provider. | N | N |
| Create | Creates a new Amazon ECS cluster. | Y | N |
| Create | Creates a new daemon in the specified cluster and capacity providers. | N | N |
| Create | Creates an Express service that simplifies deploying containerized web applications on Amazon ECS with managed Amazon Web Services infrastructure. | N | N |
| Create | Runs and maintains your desired number of tasks from a specified task definition. | Y | Y |
| Create | Create a task set in the specified cluster and service. | N | N |
| Delete | Disables an account setting for a specified user, role, or the root user for an account. | Y | N |
| Delete | Deletes one or more custom attributes from an Amazon ECS resource. | Y | N |
| Delete | Deletes the specified capacity provider. | Y | N |
| Delete | Deletes the specified cluster. | Y | N |
| Delete | Deletes the specified daemon. | Y | N |
| Delete | Deletes the specified daemon task definition. | Y | N |
| Delete | Deletes an Express service and removes all associated Amazon Web Services resources. | Y | N |
| Delete | Deletes a specified service within a cluster. | Y | N |
| Delete | Deletes one or more task definitions. | Y | N |
| Delete | Deletes a specified task set within a service. | Y | N |
| Deregister | Deregisters an Amazon ECS container instance from the specified cluster. | Y | N |
| Deregister | Deregisters the specified task definition by family and revision. | Y | N |
| Describe | Describes one or more of your capacity providers. | Y | N |
| Describe | Describes one or more of your clusters. | Y | N |
| Describe | Describes one or more container instances. | Y | N |
| Describe | Describes the specified daemon. | Y | N |
| Describe | Describes one or more of your daemon deployments. | Y | N |
| Describe | Describes one or more of your daemon revisions. | Y | N |
| Describe | Describes a daemon task definition. | Y | N |
| Describe | Retrieves detailed information about an Express service, including current status, configuration, managed infrastructure, and service revisions. | Y | N |
| Describe | Describes one or more of your service deployments. | Y | N |
| Describe | Describes one or more service revisions. | Y | N |
| Describe | Describes the specified services running in your cluster. | Y | N |
| Describe | Describes a specified task or tasks. | Y | N |
| Describe | Describes the task sets in the specified cluster and service. | Y | N |
| Discover | This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent. | Y | N |
| Execute | Runs a command remotely on a container within a task. | N | N |
| Get | Retrieves the protection status of tasks in an Amazon ECS service. | Y | N |
| List | Lists the account settings for a specified principal. | Y | N |
| List | Lists the attributes for Amazon ECS resources within a specified target type and cluster. | Y | N |
| List | Returns a list of existing clusters. | Y | N |
| List | Returns a list of container instances in a specified cluster. | Y | N |
| List | Returns a list of daemon deployments for a specified daemon. | Y | N |
| List | Returns a list of daemons. | Y | N |
| List | Returns a list of daemon task definitions that are registered to your account. | Y | N |
| List | This operation lists all the service deployments that meet the specified filter criteria. | Y | N |
| List | Returns a list of services. | Y | N |
| List | This operation lists all of the services that are associated with a Cloud Map namespace. | Y | N |
| List | List the tags for an Amazon ECS resource. | Y | N |
| List | Returns a list of task definition families that are registered to your account. | Y | N |
| List | Returns a list of task definitions that are registered to your account. | Y | N |
| List | Returns a list of tasks. | Y | N |
| Put | Modifies an account setting. | Y | N |
| Put | Modifies an account setting for all users on an account for whom no individual account setting has been specified. | Y | N |
| Put | Create or update an attribute on an Amazon ECS resource. | N | N |
| Put | Modifies the available capacity providers and the default capacity provider strategy for a cluster. | Y | N |
| Register | This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent. | N | N |
| Register | Registers a new daemon task definition from the supplied family and containerDefinitions. | N | N |
| Start | Starts a new task from the specified task definition on the specified container instance or instances. | N | Y |
| Stop | Stops an ongoing service deployment. | Y | N |
| Stop | Stops a running task. | Y | N |
| Submit | This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent. | N | N |
| Submit | This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent. | N | N |
| Submit | This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent. | N | N |
| Tag | Associates the specified tags to a resource with the specified resourceArn. | Y | N |
| Untag | Deletes specified tags from a resource. | Y | N |
| Update | Modifies the parameters for a capacity provider. | Y | N |
| Update | Updates the cluster. | Y | N |
| Update | Modifies the settings to use for a cluster. | Y | N |
| Update | Updates the Amazon ECS container agent on a specified container instance. | Y | N |
| Update | Modifies the status of an Amazon ECS container instance. | Y | N |
| Update | Updates the specified daemon. | Y | N |
| Update | Updates an existing Express service configuration. | Y | N |
| Update | Modifies the parameters of a service. | Y | N |
| Update | Modifies which task set in a service is the primary task set. | Y | N |
| Update | Updates the protection status of a task. | Y | N |
| Update | Modifies a task set. | Y | N |
| Task | TaskCreated recorded by CloudTrail for Amazon Elastic Container Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
any: Elastic Container Service (catch-all)
#Description
Catch-all entry for Elastic Container Service rules that match the service but not a specific eventName.
DescribeTaskDefinition
#Description
Describes a task definition registered to Amazon ECS, returning its family, revision, container definitions, and configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClientException",
"errorMessage": "Unable to describe task definition.",
"eventCategory": "Management",
"eventID": "b1e0cc2b-eb76-4331-aa95-60e70558665e",
"eventName": "DescribeTaskDefinition",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "311d5b27-b119-4798-95cb-1d68c3a5b106",
"requestParameters": {
"taskDefinition": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1525↳ also matches RegisterTaskDefinition, RunTask
RegisterTaskDefinition
#Description
Registers a new task definition from the supplied family and containerDefinitions, creating a new revision in Amazon ECS.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8c65bfd5-1a78-4de4-ad9e-d83f9f0f9615",
"eventName": "RegisterTaskDefinition",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T20:07:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ecd7b6ad-36f5-40e5-96ad-9a5a50e71b84",
"requestParameters": {
"containerDefinitions": [
{
"cpu": 0,
"essential": true,
"image": "busybox",
"memory": 128,
"name": "dw"
}
],
"dryrun": false,
"family": "dwfix-td"
},
"responseElements": {
"taskDefinition": {
"compatibilities": [
"EXTERNAL",
"EC2"
],
"containerDefinitions": [
{
"cpu": 0,
"environment": "HIDDEN_DUE_TO_SECURITY_REASONS",
"essential": true,
"image": "busybox",
"memory": 128,
"mountPoints": [],
"name": "dw",
"portMappings": [],
"systemControls": [],
"volumesFrom": []
}
],
"family": "dwfix-td",
"placementConstraints": [],
"registeredAt": "2026-06-29T20:07:28Z",
"registeredBy": "arn:aws:iam::123456789012:user/sample-user",
"revision": 1,
"status": "ACTIVE",
"taskDefinitionArn": "arn:aws:ecs:us-west-1:123456789012:task-definition/dwfix-td:1",
"volumes": []
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1525↳ also matches DescribeTaskDefinition, RunTask Elastic #
T1496↳ also matches RunTask, CreateService, StartTask
RunTask
#Description
Starts a new task on a specified cluster using the specified task definition.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4e582835-af26-4b8e-9042-0fefd60e4b52",
"eventSource": "ecs.amazonaws.com",
"eventName": "RunTask",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "b4f0bf93-b55b-4bf1-b44c-bc3d440da231",
"userAgent": "events.amazonaws.com"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1525↳ also matches DescribeTaskDefinition, RegisterTaskDefinition Elastic #
T1496↳ also matches RegisterTaskDefinition, CreateService, StartTask
ContinueServiceDeployment
#Description
Continues or rolls back an Amazon ECS service deployment that is paused at a lifecycle hook.
CreateCapacityProvider
#Description
Creates a capacity provider.
CreateCluster
#Description
Creates a new Amazon ECS cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7c7bb44d-412d-4e32-a8f0-50a9efbf53e5",
"eventName": "CreateCluster",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T20:07:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1db0d811-2d97-4270-96f2-9f91503e1fa8",
"requestParameters": {
"clusterName": "dwfix-cluster"
},
"responseElements": {
"cluster": {
"activeServicesCount": 0,
"capacityProviders": [],
"clusterArn": "arn:aws:ecs:us-west-1:123456789012:cluster/dwfix-cluster",
"clusterName": "dwfix-cluster",
"defaultCapacityProviderStrategy": [],
"pendingTasksCount": 0,
"registeredContainerInstancesCount": 0,
"runningTasksCount": 0,
"settings": [
{
"name": "containerInsights",
"value": "disabled"
}
],
"statistics": [],
"status": "ACTIVE",
"tags": []
},
"clusterCount": 1
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDaemon
#Description
Creates a new daemon in the specified cluster and capacity providers.
CreateExpressGatewayService
#Description
Creates an Express service that simplifies deploying containerized web applications on Amazon ECS with managed Amazon Web Services infrastructure.
CreateService
#Description
Runs and maintains your desired number of tasks from a specified task definition.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "07982dee-31aa-4d48-b8e3-d4a5795defac",
"eventName": "CreateService",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T21:00:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a45b8f12-63f7-42fa-8a43-c7def279e671",
"requestParameters": {
"cluster": "dwfix-ecs-cluster",
"desiredCount": 0,
"dryrun": false,
"enableECSManagedTags": false,
"enableExecuteCommand": false,
"serviceName": "dwfix-svc",
"taskDefinition": "dwfix-task"
},
"responseElements": {
"service": {
"availabilityZoneRebalancing": "ENABLED",
"clusterArn": "arn:aws:ecs:us-west-1:123456789012:cluster/dwfix-ecs-cluster",
"createdAt": "2026-06-29T21:00:52Z",
"createdBy": "arn:aws:iam::123456789012:user/sample-user",
"currentServiceRevisions": [
{
"arn": "arn:aws:ecs:us-west-1:123456789012:service-revision/dwfix-ecs-cluster/dwfix-svc/8700944245995359981",
"pendingTaskCount": 0,
"requestedTaskCount": 0,
"runningTaskCount": 0
}
],
"deploymentConfiguration": {
"bakeTimeInMinutes": 0,
"deploymentCircuitBreaker": {
"enable": false,
"resetOnHealthyTask": true,
"rollback": false,
"thresholdConfiguration": {
"type": "BOUNDED_PERCENT",
"value": 50
}
},
"maximumPercent": 200,
"minimumHealthyPercent": 100,
"strategy": "ROLLING"
},
"deploymentController": {
"type": "ECS"
},
"deployments": [
{
"createdAt": "2026-06-29T21:00:52Z",
"desiredCount": 0,
"failedLaunchTaskCount": 0,
"failedTasks": 0,
"id": "ecs-svc/8700944245995359981",
"launchType": "EC2",
"pendingCount": 0,
"replacedTaskCount": 0,
"rolloutState": "IN_PROGRESS",
"rolloutStateReason": "ECS deployment ecs-svc/8700944245995359981 in progress.",
"runningCount": 0,
"scale": {
"unit": "PERCENT",
"value": 0.0
},
"stabilityStatus": "STABILIZING",
"status": "PRIMARY",
"taskDefinition": "arn:aws:ecs:us-west-1:123456789012:task-definition/dwfix-task:1",
"totalFailedTasks": 0,
"updatedAt": "2026-06-29T21:00:52Z"
}
],
"desiredCount": 0,
"enableECSManagedTags": false,
"enableExecuteCommand": false,
"events": [],
"extendDeploymentTimePeriod": 0,
"healthCheckGracePeriodSeconds": 0,
"launchType": "EC2",
"loadBalancers": [],
"pendingCount": 0,
"placementConstraints": [],
"placementStrategy": [],
"propagateTags": "NONE",
"resourceManagementType": "CUSTOMER",
"runningCount": 0,
"schedulingStrategy": "REPLICA",
"serviceArn": "arn:aws:ecs:us-west-1:123456789012:service/dwfix-ecs-cluster/dwfix-svc",
"serviceName": "dwfix-svc",
"serviceRegistries": [],
"status": "ACTIVE",
"taskDefinition": "arn:aws:ecs:us-west-1:123456789012:task-definition/dwfix-task:1",
"version": 0
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1496↳ also matches RegisterTaskDefinition, RunTask, StartTask
CreateTaskSet
#Description
Create a task set in the specified cluster and service.
DeleteAccountSetting
#Description
Disables an account setting for a specified user, role, or the root user for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Referenced setting doesn't exist",
"eventCategory": "Management",
"eventID": "7c3e90db-90b3-404d-800e-fd9c105a2169",
"eventName": "DeleteAccountSetting",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "334bbdde-7eb0-485b-805d-d879bd3f5073",
"requestParameters": {
"dryrun": false,
"name": "serviceLongArnFormat"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteAttributes
#Description
Deletes one or more custom attributes from an Amazon ECS resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Blank target Id found.",
"eventCategory": "Management",
"eventID": "434b8ea0-8f0d-4efb-a5c9-9c5ae81b4da7",
"eventName": "DeleteAttributes",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "665bf62c-6395-42ac-ac86-ac732dfbb631",
"requestParameters": {
"attributes": [
{
"name": "dw-probe"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCapacityProvider
#Description
Deletes the specified capacity provider.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClientException",
"errorMessage": "Failed to get info for provided CapacityProvider",
"eventCategory": "Management",
"eventID": "2cbed8a5-0ca3-41ee-8eaa-16f311ca1ecd",
"eventName": "DeleteCapacityProvider",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "54708813-e649-4ad0-b602-553ec070f94e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCluster
#Description
Deletes the specified cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "05258c0f-daa8-443b-a997-bff9b75e8d2e",
"eventName": "DeleteCluster",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c383c74c-24a0-497a-82f7-31ed43d8f66d",
"requestParameters": {
"cluster": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDaemon
#Description
Deletes the specified daemon.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Daemon ARN is invalid",
"eventCategory": "Management",
"eventID": "8316e21f-9540-49c4-af53-9e86879718d9",
"eventName": "DeleteDaemon",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5b17fb64-00fe-43e2-bd81-455e7a30c0ad",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDaemonTaskDefinition
#Description
Deletes the specified daemon task definition.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Daemon Task Definition is invalid",
"eventCategory": "Management",
"eventID": "bd7e49bb-6fe5-4d30-8de9-aab90fa78ae1",
"eventName": "DeleteDaemonTaskDefinition",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3825eaf6-546c-44d8-a706-fc1023445872",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteExpressGatewayService
#Description
Deletes an Express service and removes all associated Amazon Web Services resources.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "ServiceArn is not valid: ARNs must start with 'arn:': dw-probe",
"eventCategory": "Management",
"eventID": "1dc4d35e-90e6-48ee-bb67-e47fc414583a",
"eventName": "DeleteExpressGatewayService",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a3a77d63-948c-4a82-a010-c8f48d1f0b2c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteService
#Description
Deletes a specified service within a cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "17aa50e3-80f7-4fbe-944f-71639c9dad9e",
"eventName": "DeleteService",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "471a6f71-d9a4-49d9-846f-b50c66951e47",
"requestParameters": {
"service": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTaskDefinitions
#Description
Deletes one or more task definitions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b0a03a20-057a-4000-b915-90e78cbd2eda",
"eventName": "DeleteTaskDefinitions",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4c436049-b3ef-4dcc-bbf3-0763105d4b78",
"requestParameters": {
"taskDefinitions": [
"dw-probe"
]
},
"responseElements": {
"failures": [
{
"arn": "dw-probe",
"reason": "The specified task definition identifier is invalid. Specify a valid name or ARN and try again."
}
],
"taskDefinitions": []
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTaskSet
#Description
Deletes a specified task set within a service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "TaskSet must match ^ecs-svc/\\d{19}$, but was dw-probe",
"eventCategory": "Management",
"eventID": "02efa6de-6b33-4299-9cf8-a4e087f87c15",
"eventName": "DeleteTaskSet",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "57ad4ece-38d2-4ede-ab94-84cd188fb45f",
"requestParameters": {
"cluster": "dw-probe",
"dryrun": false,
"service": "dw-probe",
"taskSet": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterContainerInstance
#Description
Deregisters an Amazon ECS container instance from the specified cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "564defc2-cbd9-4d8c-83d5-c9b712137144",
"eventName": "DeregisterContainerInstance",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "414918fe-a8a8-411d-a75d-7a61a4aea239",
"requestParameters": {
"containerInstance": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterTaskDefinition
#Description
Deregisters the specified task definition by family and revision.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Revision is missing",
"eventCategory": "Management",
"eventID": "590e49ef-601c-4125-a92a-cde2dc33f7fa",
"eventName": "DeregisterTaskDefinition",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a710d6ab-daa4-415a-82ce-bc9cd490aa47",
"requestParameters": {
"dryrun": false,
"taskDefinition": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityProviders
#Description
Describes one or more of your capacity providers.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ecs:DescribeCapacityProviders on resource: arn:aws:ecs:us-east-1:811596193553:capacity-provider/*",
"eventID": "b77a1dc0-d737-4108-9cde-a9e8e57c2b30",
"eventName": "DescribeCapacityProviders",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2020-06-10T05:32:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "517912bd1-2d9a-45e8-9e6c-e779f361395c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeClusters
#Description
Describes one or more of your clusters.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "7dabd9b1-8297-44bd-a4cc-cd0803841f87",
"eventName": "DescribeClusters",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2020-09-29T17:41:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e539c3fb-be87-4dde-9dc6-d122bfaae012",
"requestParameters": {
"clusters": [
"integrates-cluster"
]
},
"responseElements": null,
"sourceIPAddress": "60.219.252.71",
"userAgent": "aws-cli/1.18.40 Python/3.7.6 Linux/5.8.0-kali1-amd64 botocore/1.15.40",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeContainerInstances
#Description
Describes one or more container instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "33e690f7-a050-49bc-a9f6-76d31165def8",
"eventName": "DescribeContainerInstances",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "86250ce2-d1c1-4466-b52f-8cf1d238054b",
"requestParameters": {
"containerInstances": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDaemon
#Description
Describes the specified daemon.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Invalid daemon ARN: The Daemon ARN is invalid.",
"eventCategory": "Management",
"eventID": "3b87c0b4-4924-4e4e-b764-ac70bce7ea90",
"eventName": "DescribeDaemon",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "22b155cd-9bbe-4822-ad23-c7c8b9cc9622",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDaemonDeployments
#Description
Describes one or more of your daemon deployments.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Daemon ARN is invalid",
"eventCategory": "Management",
"eventID": "71c53b91-1cc2-4e88-be0f-a4ba21fc1002",
"eventName": "DescribeDaemonDeployments",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "64f30994-477a-40c1-a1cd-20abaf5f6215",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDaemonRevisions
#Description
Describes one or more of your daemon revisions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Daemon ARN is invalid",
"eventCategory": "Management",
"eventID": "bfdfa8ae-38dd-4d66-901d-ec72f1ee0494",
"eventName": "DescribeDaemonRevisions",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "75791c54-e6e3-43d0-9f88-9dc5bb65bf9b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDaemonTaskDefinition
#Description
Describes a daemon task definition.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "arn:aws:ecs:us-west-1:123456789012:daemon-task-definition/dw-probe:* is an invalid identifier.",
"eventCategory": "Management",
"eventID": "1eb94f2c-6e1b-4790-b0bb-bc2d943ade80",
"eventName": "DescribeDaemonTaskDefinition",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d2382030-b681-41e7-ac1c-5d37393347b4",
"requestParameters": {
"daemonTaskDefinition": "dw-probe",
"dryrun": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeExpressGatewayService
#Description
Retrieves detailed information about an Express service, including current status, configuration, managed infrastructure, and service revisions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "ServiceArn is not valid: ARNs must start with 'arn:': dw-probe",
"eventCategory": "Management",
"eventID": "7d2e627e-bdc9-4bf3-98ac-3abe89c5bf7c",
"eventName": "DescribeExpressGatewayService",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "86b60993-ba76-4590-a9ff-7e565877944a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeServiceDeployments
#Description
Describes one or more of your service deployments.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Service ARN provided is invalid.",
"eventCategory": "Management",
"eventID": "d42eb6b3-518c-47c4-b646-7b165b803ddf",
"eventName": "DescribeServiceDeployments",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3a1deced-6b95-4c11-bc62-2656d108f0bf",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeServiceRevisions
#Description
Describes one or more service revisions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Service ARN provided is invalid.",
"eventCategory": "Management",
"eventID": "a01afe75-fa54-4fa9-aca0-2cfa3646d581",
"eventName": "DescribeServiceRevisions",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5df83229-19a1-4f9f-a0af-e7e783137391",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeServices
#Description
Describes the specified services running in your cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "4b683b02-dafc-4f06-b3b9-21bc4b3b4181",
"eventName": "DescribeServices",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d4106f2a-b79b-4f9f-98e0-4ebb9326d58c",
"requestParameters": {
"services": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTasks
#Description
Describes a specified task or tasks.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "6c170979-c1cb-46eb-a9f5-b973b9ae684e",
"eventName": "DescribeTasks",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "fd8da77f-62a4-43ed-a288-4e5e1bd6fc01",
"requestParameters": {
"tasks": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTaskSets
#Description
Describes the task sets in the specified cluster and service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "TaskSets cannot be empty.",
"eventCategory": "Management",
"eventID": "e6e1b512-54ea-4301-b394-3ae7e986f355",
"eventName": "DescribeTaskSets",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "154f6534-2e7b-4e97-bc50-083579abb654",
"requestParameters": {
"cluster": "dw-probe",
"dryrun": false,
"service": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DiscoverPollEndpoint
#Description
This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: ecs:DiscoverPollEndpoint on resource: *",
"eventID": "ce7f634f-8022-465d-8f9b-858c8b4b9dd0",
"eventName": "DiscoverPollEndpoint",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2019-07-01T18:07:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e59a7af1-aa90-4007-8d19-b3ffcd32d6f9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.52.31.206",
"userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ExecuteCommand
#Description
Runs a command remotely on a container within a task.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4719a671-746a-41cf-9103-3186f92ae8e1",
"eventSource": "ecs.amazonaws.com",
"eventName": "ExecuteCommand",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "6373ab4e-25be-4bec-b7ec-8a3c57aa759f",
"userAgent": "aws-cli/2.36.9 md/awscrt#0.36.0 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.6 md/pyimpl#CPython m/r,Z,s,b,E cfg/retry-mode#standard md/installer#source sid/e8a8b2780908 md/prompt#off md/command#ecs.execute-command",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
}
}
GetTaskProtection
#Description
Retrieves the protection status of tasks in an Amazon ECS service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Tasks cannot be empty.",
"eventCategory": "Management",
"eventID": "cce27ba5-9b52-4e81-80f8-ec018c78de02",
"eventName": "GetTaskProtection",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03e88781-b8ca-4778-b85e-2875643470c1",
"requestParameters": {
"cluster": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAccountSettings
#Description
Lists the account settings for a specified principal.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "87b514926-22a2-4871-a9f2-d79b335fda25",
"eventName": "ListAccountSettings",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2019-04-19T16:48:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "fc1a9a83-62c2-11e9-b5d0-562119b9fb2a3",
"requestParameters": {
"effectiveSettings": false,
"maxResults": 0
},
"responseElements": {
"settings": []
},
"sourceIPAddress": "231.255.215.126",
"userAgent": "aws-cli/1.16.130 Python/2.7.15rc1 Linux/4.15.0-47-generic botocore/1.12.120",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListAttributes
#Description
Lists the attributes for Amazon ECS resources within a specified target type and cluster.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a is not authorized to perform: ecs:ListAttributes on resource: arn:aws:ecs:us-east-1:811596193553:cluster/default",
"eventID": "60fc5914-d939-4345-afe8-227442e27b418",
"eventName": "ListAttributes",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2020-06-11T22:12:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c619856ca-0322-423a-92f0-b41031",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "aws-cli/1.18.69 Python/3.8.3 Linux/5.4.0-2-amd64 botocore/1.16.26",
"userIdentity": {
"accessKeyId": "ASIAZIBB65UBUK3VOAC5",
"accountId": "811596193553",
"arn": "arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a",
"principalId": "AROACW5CSA8C8WHOB3O7Q:i-aa2d3b42e5c6e801a",
"sessionContext": {
"attributes": {
"creationDate": "2020-06-11T20:53:09Z",
"mfaAuthenticated": "false"
},
"ec2RoleDelivery": "1.0",
"sessionIssuer": {
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:role/flaws",
"principalId": "AROACW5CSA8C8WHOB3O7Q",
"type": "Role",
"userName": "flaws"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
ListClusters
#Description
Returns a list of existing clusters.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "bc44e1ec-ca0e-4733-8d9d-82aac08e9cbd",
"eventName": "ListClusters",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2021-07-07T18:45:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "bdd0c007-f639-4f15-a480-35e1e08941f3",
"requestParameters": {
"maxResults": 100
},
"responseElements": null,
"sourceIPAddress": "213.205.197.211",
"userAgent": "console.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37ZMAX6DUQ",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
ListContainerInstances
#Description
Returns a list of container instances in a specified cluster.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "InternalFailure",
"errorMessage": "An unknown error occurred",
"eventID": "49a9dfa0-9a4a-41c9-8dbd-e87007350f0e",
"eventName": "ListContainerInstances",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2018-10-17T20:15:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "420249b57-d249-11e8-957c-f80a39444a44",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListDaemonDeployments
#Description
Returns a list of daemon deployments for a specified daemon.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Daemon ARN is invalid",
"eventCategory": "Management",
"eventID": "08a2ca07-87b6-4928-b38f-eeb31aea3721",
"eventName": "ListDaemonDeployments",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c02c7605-05ff-4803-813b-37de6f0641ac",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListDaemons
#Description
Returns a list of daemons.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "58230dd3-cc46-4deb-b874-36fbdb490cea",
"eventName": "ListDaemons",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:31:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "56a08f09-750e-4b27-a0bf-948cb2cd1b60",
"requestParameters": {
"dryrun": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListDaemonTaskDefinitions
#Description
Returns a list of daemon task definitions that are registered to your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0f6f3230-8a2a-4da1-88eb-af5f12e48ef2",
"eventName": "ListDaemonTaskDefinitions",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:31:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e6b5e809-d35d-4a9c-b6ef-2dcf28eb8dbf",
"requestParameters": {
"dryrun": false,
"status": "ACTIVE"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListServiceDeployments
#Description
This operation lists all the service deployments that meet the specified filter criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "1dcd1739-3297-4ca3-bcbb-e6721c1d9fc1",
"eventName": "ListServiceDeployments",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1adf2772-9ffc-4195-9b03-b86ddfac6773",
"requestParameters": {
"service": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListServices
#Description
Returns a list of services.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ClientException",
"errorMessage": "Cluster not found.",
"eventID": "46b1e314-ec1c-40fa-864a-6758b10a425f",
"eventName": "ListServices",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2019-08-29T05:01:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "aca10a93-18ff-40b6-abeb-cc3369e403b1",
"requestParameters": {
"cluster": "level3"
},
"responseElements": null,
"sourceIPAddress": "90.7.123.193",
"userAgent": "aws-cli/1.16.152 Python/2.7.15 Darwin/18.5.0 botocore/1.12.142",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListServicesByNamespace
#Description
This operation lists all of the services that are associated with a Cloud Map namespace.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Invalid Request",
"eventCategory": "Management",
"eventID": "2f3490d1-d432-4167-9a0a-9ea87b52107a",
"eventName": "ListServicesByNamespace",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T18:43:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2f72c5ce-f5bb-451c-99f3-f09e8e99bfcb",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListTaskDefinitionFamilies
#Description
Returns a list of task definition families that are registered to your account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "524186-31a3-4e8b-b1c7-fab22bc0b69d",
"eventName": "ListTaskDefinitionFamilies",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2018-10-17T20:15:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "65edf85d-d249-11e8-8391-1574daafb174",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListTaskDefinitions
#Description
Returns a list of task definitions that are registered to your account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "50a7298b-488d-4f70-b05c-75c73f58f595",
"eventName": "ListTaskDefinitions",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2018-10-17T20:15:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "68879e-d249-11e8-8391-1574daafb174",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListTasks
#Description
Returns a list of tasks.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventCategory": "Management",
"eventID": "e6c7bcf0-8f2c-4099-a12f-823d52573d21",
"eventName": "ListTasks",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2021-04-13T13:31:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "760111141337",
"requestID": "cd8bf989-f3f2-44b6-8ddf-7151a7f6ae3f",
"requestParameters": {
"cluster": "arn:aws:ecs:us-west-2:760111141337:cluster/default"
},
"responseElements": null,
"sourceIPAddress": "95.9.125.40",
"userAgent": "Boto3/1.14.6 Python/3.9.4 Darwin/20.3.0 Botocore/1.17.6",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLIXX7QSZR",
"accountId": "760111141337",
"arn": "arn:aws:iam::760111141337:user/cloudmapper",
"principalId": "AIDAYTOGP2RLK32EB7QZV",
"type": "IAMUser",
"userName": "cloudmapper"
}
}
References #
PutAccountSetting
#Description
Modifies an account setting.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Invalid setting 'value'",
"eventCategory": "Management",
"eventID": "e5dd9bb0-2981-4056-bae7-b5e0197a7e78",
"eventName": "PutAccountSetting",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T21:00:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7158af48-f0a9-42df-b424-db571362f3f2",
"requestParameters": {
"name": "tagResourceAuthorization",
"value": "enabled"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutAccountSettingDefault
#Description
Modifies an account setting for all users on an account for whom no individual account setting has been specified.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Invalid setting 'value'",
"eventCategory": "Management",
"eventID": "a8bdd9fd-7c55-4aa1-a93c-7626929d9e39",
"eventName": "PutAccountSettingDefault",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T21:00:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "39243815-463a-48d3-b90d-34888d2b991f",
"requestParameters": {
"name": "tagResourceAuthorization",
"value": "enabled"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutAttributes
#Description
Create or update an attribute on an Amazon ECS resource.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e6f2afc3-810c-48ae-afa7-0234497c60ea",
"eventSource": "ecs.amazonaws.com",
"eventName": "PutAttributes",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "b7539f2b-2827-46d9-997d-47def540bc5c",
"userAgent": "aws-sdk-java/2.46.11 md/io#sync md/http#Apache5 ua/2.1 api/ECS#2.46.x os/Linux#6.1.176-223.369.amzn2023.x86_64 lang/java#25.0.3 md/OpenJDK_64-Bit_Server_VM#25.0.3+9-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
}
}
PutClusterCapacityProviders
#Description
Modifies the available capacity providers and the default capacity provider strategy for a cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Unable to assume the service linked role. Please verify that the ECS service linked role exists.",
"eventCategory": "Management",
"eventID": "60105d0d-2459-4887-9462-7efaeae10f37",
"eventName": "PutClusterCapacityProviders",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T20:07:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8703165b-3288-4d0a-88eb-1fc09d0e128f",
"requestParameters": {
"capacityProviders": [],
"cluster": "dwfix-cluster",
"defaultCapacityProviderStrategy": [],
"dryrun": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RegisterContainerInstance
#Description
This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4f6b713b-778b-412a-9a55-8cbfd1677a1b",
"eventSource": "ecs.amazonaws.com",
"eventName": "RegisterContainerInstance",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "5ccdc635-5ced-44bd-aafc-c1415a3c8853",
"userAgent": "Amazon ECS Agent - v1.34.0 (ca7e020f) (windows) (+http://aws.amazon.com/ecs/)",
"errorCode": "AccessDenied",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
}
}
RegisterDaemonTaskDefinition
#Description
Registers a new daemon task definition from the supplied family and containerDefinitions.
StartTask
#Description
Starts a new task from the specified task definition on the specified container instance or instances.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "91dcb6e1-4697-48fe-bd7c-71ea782f5ed5",
"eventSource": "ecs.amazonaws.com",
"eventName": "StartTask",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "33a1cd16-b713-4ba3-9313-d88f8375e75c",
"userAgent": "aws-sdk-java/2.46.11 md/io#sync md/http#Apache5 ua/2.1 api/ECS#2.46.x os/Linux#6.1.176-223.369.amzn2023.x86_64 lang/java#25.0.3 md/OpenJDK_64-Bit_Server_VM#25.0.3+9-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1496↳ also matches RegisterTaskDefinition, RunTask, CreateService
StopServiceDeployment
#Description
Stops an ongoing service deployment.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The ServiceDeployment ARN is invalid.",
"eventCategory": "Management",
"eventID": "246f7238-8018-473d-9a6d-30573a3f96e3",
"eventName": "StopServiceDeployment",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e044d85c-9f24-43d8-9f5e-2fdfa322e313",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StopTask
#Description
Stops a running task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "f1f95d54-2da1-48fe-b13b-d87f593dddb3",
"eventName": "StopTask",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ee3cd25f-4191-4e27-863c-e5a690b0be8d",
"requestParameters": {
"task": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SubmitAttachmentStateChanges
#Description
This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.
SubmitContainerStateChange
#Description
This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.
SubmitTaskStateChange
#Description
This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "c4a81364-9c5e-4249-a1d6-c4fb4c0a204d",
"eventSource": "ecs.amazonaws.com",
"eventName": "SubmitTaskStateChange",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "0d1fdc3d-8e16-44c1-8a16-3f817918fec1",
"userAgent": "Amazon ECS Agent - v1.105.1 (8dfceca6) (windows; WINDOWS_SERVER_2025_CORE) (+http://aws.amazon.com/ecs/)",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
}
}
TagResource
#Description
Associates the specified tags to a resource with the specified resourceArn.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "fbeeebe5-4ec6-48e4-be68-8044d99b0a5b",
"eventName": "TagResource",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T20:07:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7bf62895-7dde-45c3-aca6-c1f89dc12ab4",
"requestParameters": {
"resourceArn": "arn:aws:ecs:us-west-1:123456789012:cluster/dwfix-cluster",
"tags": [
{
"key": "dw",
"value": "f"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagResource
#Description
Deletes specified tags from a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The ARN provided is invalid.",
"eventCategory": "Management",
"eventID": "77afc919-194d-4567-a04e-ae88154355c2",
"eventName": "UntagResource",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b10d7b58-5191-4b4f-8346-67a469d711ee",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateCapacityProvider
#Description
Modifies the parameters for a capacity provider.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "One of autoScalingGroupProvider or managedInstancesProvider must be specified.",
"eventCategory": "Management",
"eventID": "b0914053-ca95-4ffd-82ca-0d5e0febfd2e",
"eventName": "UpdateCapacityProvider",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "45334fef-4177-4b51-b948-1a648e2a619e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateCluster
#Description
Updates the cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "7677cbf2-54dd-45fa-85ed-2441b4eecd95",
"eventName": "UpdateCluster",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5e0e13b6-c4c1-46e0-ace5-27bc1d09ec65",
"requestParameters": {
"cluster": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateClusterSettings
#Description
Modifies the settings to use for a cluster.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "051893f9-6fcc-4759-9f7b-f46a83a402c0",
"eventName": "UpdateClusterSettings",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1cee5e1e-5409-4036-9d7c-82f9dca0f752",
"requestParameters": {
"cluster": "dw-probe",
"settings": [
{}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateContainerAgent
#Description
Updates the Amazon ECS container agent on a specified container instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "ContainerInstanceId must match ^[a-f0-9-]{1,36}$",
"eventCategory": "Management",
"eventID": "badd2cfd-c6c2-423f-80a9-10e51ad3ef21",
"eventName": "UpdateContainerAgent",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "30223df6-c429-41ec-9f92-ca538dfdb68d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateContainerInstancesState
#Description
Modifies the status of an Amazon ECS container instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "d613c559-1441-4788-a60d-cb9f2dfdc79c",
"eventName": "UpdateContainerInstancesState",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "843eef47-f963-44cf-83cb-7fc4fcddd273",
"requestParameters": {
"containerInstances": [
"dw-probe"
],
"status": "ACTIVE"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateDaemon
#Description
Updates the specified daemon.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Invalid daemon ARN: The Daemon ARN is invalid.",
"eventCategory": "Management",
"eventID": "ac3a0772-4e3f-4ba7-a213-69d7eecfc1c6",
"eventName": "UpdateDaemon",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ff9155c7-8bda-4d39-b6b9-6b9f72a08565",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateExpressGatewayService
#Description
Updates an existing Express service configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "The Service ARN provided is invalid.",
"eventCategory": "Management",
"eventID": "3f958c0e-b59a-4721-bc4e-3c226c57acc3",
"eventName": "UpdateExpressGatewayService",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "84498646-2fec-405b-a8cb-babec62ab62c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateService
#Description
Modifies the parameters of a service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "abec09c4-9537-4301-a001-1fc2fe7a8879",
"eventName": "UpdateService",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ec3cfb78-5c32-401b-b4d0-d214105abf4a",
"requestParameters": {
"dryrun": false,
"forceNewDeployment": false,
"service": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateServicePrimaryTaskSet
#Description
Modifies which task set in a service is the primary task set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "PrimaryTaskSet must match ^ecs-svc/\\d{19}$, but was dw-probe",
"eventCategory": "Management",
"eventID": "0826f4fa-07c0-4ccf-8b4c-1fd313b819f1",
"eventName": "UpdateServicePrimaryTaskSet",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fa6f8d9d-b4b1-43b2-ab5e-163b0516aca4",
"requestParameters": {
"cluster": "dw-probe",
"primaryTaskSet": "dw-probe",
"service": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTaskProtection
#Description
Updates the protection status of a task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ClusterNotFoundException",
"errorMessage": "Cluster not found.",
"eventCategory": "Management",
"eventID": "ceed55c1-0424-46ae-9c1e-202ddb858a11",
"eventName": "UpdateTaskProtection",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cb1adfe7-ff2a-4eee-8b34-78d4a47bb163",
"requestParameters": {
"cluster": "dw-probe",
"protectionEnabled": false,
"tasks": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTaskSet
#Description
Modifies a task set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "TaskSet must match ^ecs-svc/\\d{19}$, but was dw-probe",
"eventCategory": "Management",
"eventID": "ee45f349-c355-43b9-8db6-bc1955be76cc",
"eventName": "UpdateTaskSet",
"eventSource": "ecs.amazonaws.com",
"eventTime": "2026-06-29T19:23:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d8e1df86-f06c-4fc6-ae18-c564559d56e6",
"requestParameters": {
"cluster": "dw-probe",
"dryrun": false,
"scale": {
"value": 0.0
},
"service": "dw-probe",
"taskSet": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TaskCreated
#Description
TaskCreated recorded by CloudTrail for Amazon Elastic Container Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "83f0b2a3-1716-40dc-830b-e682109d1fc6",
"eventSource": "ecs.amazonaws.com",
"eventName": "TaskCreated",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"requestID": "b48dd815-0f71-4559-9c09-69b72a57c36f",
"userAgent": "ecs.amazonaws.com"
}