ElastiCache

eventNameDescriptionSampleRule
anyCatch-all entry for ElastiCache rules that match the service but not a specific eventName.NN
AuthorizeCacheSecurityGroupIngressGrants ingress network access to a cache security group for the specified EC2 security group.NY
CreateCacheSecurityGroupCreates a new cache security group to control network access for EC2-Classic ElastiCache clusters.NY
DeleteCacheSecurityGroupDeletes an existing cache security group, provided no clusters are currently associated with it.YY
RevokeCacheSecurityGroupIngressRemoves a previously authorized ingress rule from a cache security group for the specified EC2 security group.YY
AddTagsToResourceA tag is a key-value pair where the key and value are case-sensitive.YN
BatchApplyUpdateActionApply the service update.NN
BatchStopUpdateActionStop the service update.NN
CompleteMigrationComplete the migration of data.NN
CopyServerlessCacheSnapshotCreates a copy of an existing serverless cache’s snapshot.NN
CopySnapshotThe CopySnapshot operation makes a copy of an existing snapshot.YN
CreateCacheClusterThe CreateCacheCluster operation creates a cache cluster.YN
CreateCacheParameterGroupThe CreateCacheParameterGroup operation creates a new cache parameter group.YN
CreateCacheSubnetGroupThe CreateCacheSubnetGroup operation creates a new cache subnet group.YN
CreateGlobalReplicationGroupGlobal Datastore offers fully managed, fast, reliable and secure cross-region replication.NN
CreateReplicationGroupThe CreateReplicationGroup operation creates a replication group.NN
CreateServerlessCacheCreates a serverless cache.NN
CreateServerlessCacheSnapshotThis API creates a copy of an entire ServerlessCache at a specific moment in time.NN
CreateSnapshotThe CreateSnapshot operation creates a copy of an entire cache cluster at a specific moment in time.YN
CreateUserFor Valkey engine version 7.2 onwards and Redis OSS 6.0 to 7.1: Creates a user.YN
CreateUserGroupFor Valkey engine version 7.2 onwards and Redis OSS 6.0 to 7.1: Creates a user group.YN
DecreaseNodeGroupsInGlobalReplicationGroupDecreases the number of node groups in a Global datastoreNN
DecreaseReplicaCountDynamically decreases the number of replicas in a Valkey or Redis OSS (cluster mode disabled) replication group or the number of replica nodes in one or more node groups (shards) of a Valkey or Redis OSS (cluster mode enabled) replication g.NN
DeleteCacheClusterThe DeleteCacheCluster operation deletes a previously provisioned cache cluster.YN
DeleteCacheParameterGroupThe DeleteCacheParameterGroup operation deletes the specified cache parameter group.YN
DeleteCacheSubnetGroupThe DeleteCacheSubnetGroup operation deletes a cache subnet group.YN
DeleteGlobalReplicationGroupDeleting a Global datastore is a two-step process: First, you must DisassociateGlobalReplicationGroup to remove the secondary clusters in the Global datastore.YN
DeleteReplicationGroupThe DeleteReplicationGroup operation deletes an existing cluster.YN
DeleteServerlessCacheDeletes a specified existing serverless cache.YN
DeleteServerlessCacheSnapshotDeletes an existing serverless cache snapshot.YN
DeleteSnapshotThe DeleteSnapshot operation deletes an existing snapshot.YN
DeleteUserFor Valkey engine version 7.2 onwards and Redis OSS 6.0 onwards: Deletes a user.YN
DeleteUserGroupFor Valkey engine version 7.2 onwards and Redis OSS 6.0 onwards: Deletes a user group.YN
DescribeCacheClustersThe DescribeCacheClusters operation returns information about all provisioned cache clusters if no cache cluster identifier is specified, or about a specific cache cluster if a cache cluster identifier is supplied.YN
DescribeCacheEngineVersionsThe DescribeCacheEngineVersions operation returns a list of the available cache engines and their versions.YN
DescribeCacheParameterGroupsThe DescribeCacheParameterGroups operation returns a list of cache parameter group descriptions.YN
DescribeCacheParametersThe DescribeCacheParameters operation returns the detailed parameter list for a particular cache parameter group.YN
DescribeCacheSecurityGroupsThe DescribeCacheSecurityGroups operation returns a list of cache security group descriptions.YN
DescribeCacheSubnetGroupsThe DescribeCacheSubnetGroups operation returns a list of cache subnet group descriptions.YN
DescribeEngineDefaultParametersThe DescribeEngineDefaultParameters operation returns the default engine and system parameter information for the specified cache engine.YN
DescribeEventsThe DescribeEvents operation returns events related to cache clusters, cache security groups, and cache parameter groups.YN
DescribeGlobalReplicationGroupsReturns information about a particular global replication group.YN
DescribeReplicationGroupsThe DescribeReplicationGroups operation returns information about a particular replication group.YN
DescribeReservedCacheNodesThe DescribeReservedCacheNodes operation returns information about reserved cache nodes for this account, or about a specified reserved cache node.YN
DescribeReservedCacheNodesOfferingsThe DescribeReservedCacheNodesOfferings operation lists available reserved cache node offerings.YN
DescribeServerlessCachesReturns information about a specific serverless cache.YN
DescribeServerlessCacheSnapshotsReturns information about serverless cache snapshots.YN
DescribeServiceUpdatesReturns details of the service updatesYN
DescribeSnapshotsThe DescribeSnapshots operation returns information about cache cluster snapshots.YN
DescribeUpdateActionsReturns details of the update actionsYN
DescribeUserGroupsReturns a list of user groups.YN
DescribeUsersReturns a list of users.YN
DisassociateGlobalReplicationGroupRemove a secondary cluster from the Global datastore using the Global datastore name.YN
ExportServerlessCacheSnapshotProvides the functionality to export the serverless cache snapshot data to Amazon S3.NN
FailoverGlobalReplicationGroupUsed to failover the primary region to a secondary region.NN
IncreaseNodeGroupsInGlobalReplicationGroupIncrease the number of node groups in the Global datastoreNN
IncreaseReplicaCountDynamically increases the number of replicas in a Valkey or Redis OSS (cluster mode disabled) replication group or the number of replica nodes in one or more node groups (shards) of a Valkey or Redis OSS (cluster mode enabled) replication g.NN
ListAllowedNodeTypeModificationsLists all available node types that you can scale with your cluster's replication group's current node type.YN
ListTagsForResourceLists all tags currently on a named resource.YN
ModifyCacheClusterThe ModifyCacheCluster operation modifies the settings for a cache cluster.YN
ModifyCacheParameterGroupThe ModifyCacheParameterGroup operation modifies the parameters of a cache parameter group.YN
ModifyCacheSubnetGroupThe ModifyCacheSubnetGroup operation modifies an existing cache subnet group.YN
ModifyGlobalReplicationGroupModifies the settings for a Global datastore.YN
ModifyReplicationGroupThe ModifyReplicationGroup operation modifies the settings for a replication group.YN
ModifyReplicationGroupShardConfigurationModifies a replication group's shards (node groups) by allowing you to add shards, remove shards, or rebalance the keyspaces among existing shards.YN
ModifyServerlessCacheThis API modifies the attributes of a serverless cache.YN
ModifyUserChanges user password(s) and/or access string.YN
ModifyUserGroupChanges the list of users that belong to the user group.YN
PurchaseReservedCacheNodesOfferingThe PurchaseReservedCacheNodesOffering operation allows you to purchase a reserved cache node offering.NN
RebalanceSlotsInGlobalReplicationGroupRedistribute slots to ensure uniform distribution across existing shards in the cluster.NN
RebootCacheClusterThe RebootCacheCluster operation reboots some, or all, of the cache nodes within a provisioned cache cluster.YN
RemoveTagsFromResourceRemoves the tags identified by the TagKeys list from the named resource.YN
ResetCacheParameterGroupThe ResetCacheParameterGroup operation modifies the parameters of a cache parameter group to the engine or system default value.YN
StartMigrationStart the migration of data.NN
TestFailoverRepresents the input of a TestFailover operation which tests automatic failover on a specified node group (called shard in the console) in a replication group (called cluster in the console).NN
TestMigrationAsync API to test connection between source and target replication group.NN

any: ElastiCache (catch-all)

#
Service
elasticache

Description

Catch-all entry for ElastiCache rules that match the service but not a specific eventName.

AuthorizeCacheSecurityGroupIngress

#
Service
elasticache

Description

Grants ingress network access to a cache security group for the specified EC2 security group.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

CreateCacheSecurityGroup

#
Service
elasticache

Description

Creates a new cache security group to control network access for EC2-Classic ElastiCache clusters.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

DeleteCacheSecurityGroup

#
Service
elasticache

Description

Deletes an existing cache security group, provided no clusters are currently associated with it.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Use of cache security groups is not permitted in this API version for your account.",
  "eventCategory": "Management",
  "eventID": "3606dfff-3048-4089-bb93-079751cbd2a3",
  "eventName": "DeleteCacheSecurityGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2ac33b20-b3e2-4e5c-ba83-7461c839550e",
  "requestParameters": {
    "cacheSecurityGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

RevokeCacheSecurityGroupIngress

#
Service
elasticache

Description

Removes a previously authorized ingress rule from a cache security group for the specified EC2 security group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Use of cache security groups is not permitted in this API version for your account.",
  "eventCategory": "Management",
  "eventID": "8f36f04d-1fbb-4f20-b695-0c3bf3560208",
  "eventName": "RevokeCacheSecurityGroupIngress",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8bf40580-ad52-4678-9d1a-dd47f0dfcedb",
  "requestParameters": {
    "cacheSecurityGroupName": "dw-probe",
    "eC2SecurityGroupName": "dw-probe",
    "eC2SecurityGroupOwnerId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

AddTagsToResource

#
Service
elasticache

Description

A tag is a key-value pair where the key and value are case-sensitive.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d20b6920-be8d-41cc-b55f-f70db8cfa80b",
  "eventName": "AddTagsToResource",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T21:49:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0f7253a5-96d9-4cbe-abe5-088991e9734a",
  "requestParameters": {
    "resourceName": "arn:aws:elasticache:us-west-1:123456789012:parametergroup:dwfix-pg-redis7",
    "tags": [
      {
        "key": "env",
        "value": "dw-test"
      }
    ]
  },
  "responseElements": {
    "tagList": [
      {
        "key": "env",
        "value": "dw-test"
      },
      {
        "key": "dw-sample",
        "value": "true"
      }
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

BatchApplyUpdateAction

#
Service
elasticache

Description

Apply the service update.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "92e6ea18-37dd-44c0-a7a4-8f630901fc9e",
  "eventSource": "elasticache.amazonaws.com",
  "eventName": "BatchApplyUpdateAction",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "66fc618c-b3b1-428e-9c8d-bb8f067d1dce",
  "userAgent": "Boto3/1.43.54 md/Botocore#1.43.54 ua/2.1 os/linux#6.8.0-1060-aws md/arch#aarch64 lang/python#3.11.15 md/pyimpl#CPython m/Z,0,b,D cfg/retry-mode#legacy Botocore/1.43.54",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-east-2.amazonaws.com"
  }
}

BatchStopUpdateAction

#
Service
elasticache

Description

Stop the service update.

CompleteMigration

#
Service
elasticache

Description

Complete the migration of data.

CopyServerlessCacheSnapshot

#
Service
elasticache

Description

Creates a copy of an existing serverless cache’s snapshot.

CopySnapshot

#
Service
elasticache

Description

The CopySnapshot operation makes a copy of an existing snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: elasticache:CopySnapshot",
  "eventID": "a31c0ad0-538c-4092-a9bb-8fbfe488186e",
  "eventName": "CopySnapshot",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2017-03-03T15:56:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "fc1da687-0029-11e7-b720-11a54f9f192c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "217.243.208.176",
  "userAgent": "aws-cli/1.11.56 Python/2.7.12 Linux/4.4.0-59-generic botocore/1.5.19",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

CreateCacheCluster

#
Service
elasticache

Description

The CreateCacheCluster operation creates a cache cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ced567d4-4f48-4bde-8076-ea27ce47b6ab",
  "eventName": "CreateCacheCluster",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T22:40:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6c7e170e-f49e-40ab-a1cb-1f88020aaa8d",
  "requestParameters": {
    "cacheClusterId": "dwfix-heavy-ec",
    "cacheNodeType": "cache.t3.micro",
    "cacheParameterGroupName": "dwfix-heavy-ec-pg",
    "cacheSubnetGroupName": "dwfix-heavy-ec-sng",
    "engine": "redis",
    "engineVersion": "7.1",
    "numCacheNodes": 1,
    "tags": [
      {
        "key": "dw-sample",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "aRN": "arn:aws:elasticache:us-west-1:123456789012:cluster:dwfix-heavy-ec",
    "atRestEncryptionEnabled": false,
    "autoMinorVersionUpgrade": true,
    "cacheClusterId": "dwfix-heavy-ec",
    "cacheClusterStatus": "creating",
    "cacheNodeType": "cache.t3.micro",
    "cacheParameterGroup": {
      "cacheNodeIdsToReboot": [],
      "cacheParameterGroupName": "dwfix-heavy-ec-pg",
      "parameterApplyStatus": "in-sync"
    },
    "cacheSecurityGroups": [],
    "cacheSubnetGroupName": "dwfix-heavy-ec-sng",
    "clientDownloadLandingPage": "https://console.aws.amazon.com/elasticache/home#client-download:",
    "deleteProtection": false,
    "engine": "redis",
    "engineVersion": "7.1.0",
    "ipDiscovery": "ipv4",
    "logDeliveryConfigurations": [],
    "networkType": "ipv4",
    "numCacheNodes": 1,
    "pendingModifiedValues": {},
    "preferredMaintenanceWindow": "mon:11:30-mon:12:30",
    "replicationGroupLogDeliveryEnabled": false,
    "snapshotRetentionLimit": 0,
    "snapshotWindow": "12:30-13:30",
    "transitEncryptionEnabled": false
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateCacheParameterGroup

#
Service
elasticache

Description

The CreateCacheParameterGroup operation creates a new cache parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d79ebb6b-a7b2-4224-a215-3efb0ef1a237",
  "eventName": "CreateCacheParameterGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T21:49:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "97cf0358-c0d7-40a0-902f-30d341a2e01f",
  "requestParameters": {
    "cacheParameterGroupFamily": "redis7",
    "cacheParameterGroupName": "dwfix-pg-redis7",
    "description": "dwfix sample elasticache parameter group",
    "tags": [
      {
        "key": "dw-sample",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "aRN": "arn:aws:elasticache:us-west-1:123456789012:parametergroup:dwfix-pg-redis7",
    "cacheParameterGroupFamily": "redis7",
    "cacheParameterGroupName": "dwfix-pg-redis7",
    "description": "dwfix sample elasticache parameter group",
    "isGlobal": false
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateCacheSubnetGroup

#
Service
elasticache

Description

The CreateCacheSubnetGroup operation creates a new cache subnet group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f8ad59db-7710-4540-bb0d-6477e0af860f",
  "eventName": "CreateCacheSubnetGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T21:49:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f33f55a0-dad6-4f2f-955b-2162714dc6dc",
  "requestParameters": {
    "cacheSubnetGroupDescription": "dwfix sample subnet group",
    "cacheSubnetGroupName": "dwfix-sg-elasticache",
    "subnetIds": [
      "subnet-0c9f719882f5c95ae",
      "subnet-04caa2ba1250f8fb6"
    ],
    "tags": [
      {
        "key": "dw-sample",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "aRN": "arn:aws:elasticache:us-west-1:123456789012:subnetgroup:dwfix-sg-elasticache",
    "cacheSubnetGroupDescription": "dwfix sample subnet group",
    "cacheSubnetGroupName": "dwfix-sg-elasticache",
    "subnets": [
      {
        "subnetAvailabilityZone": {
          "name": "us-west-1a"
        },
        "subnetIdentifier": "subnet-0c9f719882f5c95ae",
        "supportedNetworkTypes": [
          "ipv4"
        ]
      },
      {
        "subnetAvailabilityZone": {
          "name": "us-west-1c"
        },
        "subnetIdentifier": "subnet-04caa2ba1250f8fb6",
        "supportedNetworkTypes": [
          "ipv4"
        ]
      }
    ],
    "supportedNetworkTypes": [
      "ipv4"
    ],
    "vpcId": "vpc-0cf63cfb072f7d61f"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateGlobalReplicationGroup

#
Service
elasticache

Description

Global Datastore offers fully managed, fast, reliable and secure cross-region replication.

CreateReplicationGroup

#
Service
elasticache

Description

The CreateReplicationGroup operation creates a replication group.

CreateServerlessCache

#
Service
elasticache

Description

Creates a serverless cache.

CreateServerlessCacheSnapshot

#
Service
elasticache

Description

This API creates a copy of an entire ServerlessCache at a specific moment in time.

CreateSnapshot

#
Service
elasticache

Description

The CreateSnapshot operation creates a copy of an entire cache cluster at a specific moment in time.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "41e13827-c1c2-44f7-8bc4-65b06849c5db",
  "eventName": "CreateSnapshot",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T22:48:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "069591c2-40a7-47c4-bde8-262ddb800332",
  "requestParameters": {
    "cacheClusterId": "dwfix-heavy-ec",
    "snapshotName": "dwfix-heavy-ec-snap"
  },
  "responseElements": {
    "aRN": "arn:aws:elasticache:us-west-1:123456789012:snapshot:dwfix-heavy-ec-snap",
    "autoMinorVersionUpgrade": true,
    "cacheClusterCreateTime": "Jun 29, 2026, 10:45:36 PM",
    "cacheClusterId": "dwfix-heavy-ec",
    "cacheNodeType": "cache.t3.micro",
    "cacheParameterGroupName": "dwfix-heavy-ec-pg",
    "cacheSubnetGroupName": "dwfix-heavy-ec-sng",
    "dataTiering": "disabled",
    "engine": "redis",
    "engineVersion": "7.1.0",
    "nodeSnapshots": [
      {
        "cacheNodeCreateTime": "Jun 29, 2026, 10:45:36 PM",
        "cacheNodeId": "0001",
        "cacheSize": ""
      }
    ],
    "numCacheNodes": 1,
    "port": 6379,
    "preferredAvailabilityZone": "us-west-1c",
    "preferredMaintenanceWindow": "sun:05:00-sun:06:00",
    "snapshotName": "dwfix-heavy-ec-snap",
    "snapshotRetentionLimit": 0,
    "snapshotSource": "manual",
    "snapshotStatus": "creating",
    "snapshotWindow": "12:30-13:30",
    "vpcId": "vpc-0cf63cfb072f7d61f"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateUser

#
Service
elasticache

Description

For Valkey engine version 7.2 onwards and Redis OSS 6.0 to 7.1: Creates a user.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cefdef2f-ff22-4879-9fac-529a30ab8f95",
  "eventName": "CreateUser",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T21:49:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a8b7ff1b-bcd6-46ab-b3de-9e5388c18433",
  "requestParameters": {
    "accessString": "on ~* +@all",
    "authenticationMode": {
      "type": "iam"
    },
    "engine": "redis",
    "tags": [
      {
        "key": "dw-sample",
        "value": "true"
      }
    ],
    "userId": "dwfix-user-ec",
    "userName": "dwfix-user-ec"
  },
  "responseElements": {
    "aRN": "arn:aws:elasticache:us-west-1:123456789012:user:dwfix-user-ec",
    "accessString": "on ~* +@all",
    "authentication": {
      "type": "iam"
    },
    "engine": "redis",
    "minimumEngineVersion": "7.0",
    "status": "active",
    "userGroupIds": [],
    "userId": "dwfix-user-ec",
    "userName": "dwfix-user-ec"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateUserGroup

#
Service
elasticache

Description

For Valkey engine version 7.2 onwards and Redis OSS 6.0 to 7.1: Creates a user group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "DefaultUserRequired",
  "errorMessage": "Redis user group needs to contain a user with the user name default.",
  "eventCategory": "Management",
  "eventID": "dc108c31-3a72-4b9c-983a-2b83e001c2a6",
  "eventName": "CreateUserGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T21:49:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7a8fbe78-874c-4b70-97cf-84e3059f9179",
  "requestParameters": {
    "engine": "redis",
    "tags": [
      {
        "key": "dw-sample",
        "value": "true"
      }
    ],
    "userGroupId": "dwfix-ug-ec",
    "userIds": [
      "dwfix-user-ec"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DecreaseNodeGroupsInGlobalReplicationGroup

#
Service
elasticache

Description

Decreases the number of node groups in a Global datastore

DecreaseReplicaCount

#
Service
elasticache

Description

Dynamically decreases the number of replicas in a Valkey or Redis OSS (cluster mode disabled) replication group or the number of replica nodes in one or more node groups (shards) of a Valkey or Redis OSS (cluster mode enabled) replication g.

DeleteCacheCluster

#
Service
elasticache

Description

The DeleteCacheCluster operation deletes a previously provisioned cache cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheClusterNotFoundFault",
  "errorMessage": "CacheCluster not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "1236b10f-bcb6-4d4d-a645-aca600b50450",
  "eventName": "DeleteCacheCluster",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b38cee5b-975f-441f-ac94-258caea32d84",
  "requestParameters": {
    "cacheClusterId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCacheParameterGroup

#
Service
elasticache

Description

The DeleteCacheParameterGroup operation deletes the specified cache parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheParameterGroupNotFoundFault",
  "errorMessage": "CacheParameterGroupnot found: dw-probe",
  "eventCategory": "Management",
  "eventID": "2ac37348-b968-464a-a0a7-1dd628ef1c2d",
  "eventName": "DeleteCacheParameterGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "da77bef8-d046-4aac-9f4e-5f08f08e4006",
  "requestParameters": {
    "cacheParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCacheSubnetGroup

#
Service
elasticache

Description

The DeleteCacheSubnetGroup operation deletes a cache subnet group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheSubnetGroupNotFoundFault",
  "errorMessage": "Cache Subnet Group dw-probe does not exist.",
  "eventCategory": "Management",
  "eventID": "6c8817e2-80e4-4519-8da2-e0ed0fd1a85e",
  "eventName": "DeleteCacheSubnetGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a8542fd2-71ad-444c-a787-462758f60d72",
  "requestParameters": {
    "cacheSubnetGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteGlobalReplicationGroup

#
Service
elasticache

Description

Deleting a Global datastore is a two-step process: First, you must DisassociateGlobalReplicationGroup to remove the secondary clusters in the Global datastore.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Deletion of primary replication group is not supported. You can manually delete primary Replication Group after the Global Replication Group is deleted.",
  "eventCategory": "Management",
  "eventID": "e2522a0d-db84-43d6-90ef-82e26a020b76",
  "eventName": "DeleteGlobalReplicationGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ef850cc8-496a-45c2-8bcc-be93d32905ab",
  "requestParameters": {
    "globalReplicationGroupId": "dw-probe",
    "retainPrimaryReplicationGroup": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteReplicationGroup

#
Service
elasticache

Description

The DeleteReplicationGroup operation deletes an existing cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ReplicationGroupNotFoundFault",
  "errorMessage": "Specified replication group does not exist",
  "eventCategory": "Management",
  "eventID": "ccf8c62f-5408-4111-8ae6-b9229408d365",
  "eventName": "DeleteReplicationGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1ac88c01-d89d-4218-bcc2-47c6d05bebda",
  "requestParameters": {
    "replicationGroupId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteServerlessCache

#
Service
elasticache

Description

Deletes a specified existing serverless cache.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ServerlessCacheNotFoundFault",
  "errorMessage": "Serverless cache with name dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "0b22a84f-b9f4-4ffe-8bf0-1357f91e4575",
  "eventName": "DeleteServerlessCache",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "521e3cbf-82ee-4543-a0b7-20477aa5d840",
  "requestParameters": {
    "serverlessCacheName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteServerlessCacheSnapshot

#
Service
elasticache

Description

Deletes an existing serverless cache snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ServerlessCacheSnapshotNotFoundFault",
  "errorMessage": "Serverless cache snapshot with specified name does not exists.",
  "eventCategory": "Management",
  "eventID": "11c8793c-9a83-4c1c-9740-7111e294e888",
  "eventName": "DeleteServerlessCacheSnapshot",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cd4261ef-6dce-40d4-8a75-07adb4fc196b",
  "requestParameters": {
    "serverlessCacheSnapshotName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSnapshot

#
Service
elasticache

Description

The DeleteSnapshot operation deletes an existing snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "SnapshotNotFoundFault",
  "errorMessage": "Snapshot with name dw-probe not found",
  "eventCategory": "Management",
  "eventID": "3eda2980-0de0-4980-ab6d-512ee533cf1d",
  "eventName": "DeleteSnapshot",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ed2a88c7-a49c-4ba9-933a-22086a2e2b27",
  "requestParameters": {
    "snapshotName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteUser

#
Service
elasticache

Description

For Valkey engine version 7.2 onwards and Redis OSS 6.0 onwards: Deletes a user.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UserNotFoundFault",
  "errorMessage": "User ddddd not found.",
  "eventCategory": "Management",
  "eventID": "f451e6d5-df22-4b18-970b-669e83fea9cd",
  "eventName": "DeleteUser",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cdc851fd-082e-4234-80be-8348be808b62",
  "requestParameters": {
    "userId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteUserGroup

#
Service
elasticache

Description

For Valkey engine version 7.2 onwards and Redis OSS 6.0 onwards: Deletes a user group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UserGroupNotFoundFault",
  "errorMessage": "User group dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "2ec6970a-1791-4412-a77d-6dcdce538047",
  "eventName": "DeleteUserGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0558dd15-7068-483b-ae7d-efd54e30edea",
  "requestParameters": {
    "userGroupId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCacheClusters

#
Service
elasticache

Description

The DescribeCacheClusters operation returns information about all provisioned cache clusters if no cache cluster identifier is specified, or about a specific cache cluster if a cache cluster identifier is supplied.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "967432c34-07a1-49b2-8123-2a3b83195",
  "eventName": "DescribeCacheClusters",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2017-03-16T18:48:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "57672d5-0a79-11e7-8057-93a5f666f043",
  "requestParameters": {
    "maxRecords": 100,
    "showCacheNodeInfo": true
  },
  "responseElements": null,
  "sourceIPAddress": "5.3.205.235",
  "userAgent": "aws-sdk-ruby2/2.7.16 ruby/2.3.1 x86_64-linux-gnu",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCacheEngineVersions

#
Service
elasticache

Description

The DescribeCacheEngineVersions operation returns a list of the available cache engines and their versions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "089429a42-03e9-48a9-a6de-16baf5132465",
  "eventName": "DescribeCacheEngineVersions",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-21T16:26:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "024f3203-d54e-11e8-bdf7-9fd98708fad",
  "requestParameters": {
    "defaultOnly": false,
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Boto3/1.7.4 Python/3.6.6 Linux/4.16.0-kali2-amd64 Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCacheParameterGroups

#
Service
elasticache

Description

The DescribeCacheParameterGroups operation returns a list of cache parameter group descriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "33a6a0fc-5590-4896-a01d-2a38a303f9ed",
  "eventName": "DescribeCacheParameterGroups",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-17T20:19:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "426302cd4-d24a-11e8-a1d2-67d93416f094",
  "requestParameters": {
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCacheParameters

#
Service
elasticache

Description

The DescribeCacheParameters operation returns the detailed parameter list for a particular cache parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheParameterGroupNotFoundFault",
  "errorMessage": "CacheParameterGroupnot found: dw-probe",
  "eventCategory": "Management",
  "eventID": "34345911-774c-420d-84db-d25d350cfe8c",
  "eventName": "DescribeCacheParameters",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:43:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cc8f18a1-c392-4b5d-ae9e-2ad91276e923",
  "requestParameters": {
    "cacheParameterGroupName": "dw-probe",
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCacheSecurityGroups

#
Service
elasticache

Description

The DescribeCacheSecurityGroups operation returns a list of cache security group descriptions.

Example CloudTrail Event #

{
  "awsRegion": "ca-central-1",
  "eventID": "76b7dcb6-ef7b-4c3c-b162-4a05526da418",
  "eventName": "DescribeCacheSecurityGroups",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2017-05-26T02:24:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "6c150a7a-41ba-11e7-9ffd-c94ae1019899",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "Boto3/1.4.4 Python/2.7.12 Linux/4.4.0-31-generic Botocore/1.5.56",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCacheSubnetGroups

#
Service
elasticache

Description

The DescribeCacheSubnetGroups operation returns a list of cache subnet group descriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "50ca74ee-34bd-415f-955b-5b4921950b38",
  "eventName": "DescribeCacheSubnetGroups",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2017-03-16T18:48:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "2266eab8-0a79-11e7-8057-93a5f666f043",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "5.3.205.235",
  "userAgent": "aws-sdk-ruby2/2.7.16 ruby/2.3.1 x86_64-linux-gnu",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeEngineDefaultParameters

#
Service
elasticache

Description

The DescribeEngineDefaultParameters operation returns the default engine and system parameter information for the specified cache engine.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "CacheParameterGroupFamily dw-probe is not a valid parameter group family.",
  "eventCategory": "Management",
  "eventID": "3dff5979-1530-48dc-b90e-604cff6a236b",
  "eventName": "DescribeEngineDefaultParameters",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:43:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "11541b49-fed3-475d-a47a-4913ee1a8602",
  "requestParameters": {
    "cacheParameterGroupFamily": "dw-probe",
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeEvents

#
Service
elasticache

Description

The DescribeEvents operation returns events related to cache clusters, cache security groups, and cache parameter groups.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "0b6764b6-6162-4f9d-998f-6725a75e009c",
  "eventName": "DescribeEvents",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-17T20:19:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "700695a4e-d24a-11e8-a226-f9384a808bfe",
  "requestParameters": {
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeGlobalReplicationGroups

#
Service
elasticache

Description

Returns information about a particular global replication group.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: elasticache:DescribeGlobalReplicationGroups",
  "eventID": "d3b7f557-4375-4483-bbb9-189c6fc9a9cd",
  "eventName": "DescribeGlobalReplicationGroups",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2020-06-10T05:33:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "631f45ed-81a9-4a07-89da-fda1d0dd5d27",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeReplicationGroups

#
Service
elasticache

Description

The DescribeReplicationGroups operation returns information about a particular replication group.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "ee922c7d-41db-4c88-90bd-fd17996b60ab",
  "eventName": "DescribeReplicationGroups",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2017-06-10T04:05:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "0b43227d-4d92-11e7-a6c3-83ce282517",
  "requestParameters": {
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "57.253.150.203",
  "userAgent": "aws-cli/1.11.72 Python/2.7.13 Darwin/16.6.0 botocore/1.5.35",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeReservedCacheNodes

#
Service
elasticache

Description

The DescribeReservedCacheNodes operation returns information about reserved cache nodes for this account, or about a specified reserved cache node.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "509c99c5-eb75-4ce6-9efa-96f6e0b66e52",
  "eventName": "DescribeReservedCacheNodes",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-17T20:19:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "02b9bd74-d24a-11e8-a226-f9384a808bfe",
  "requestParameters": {
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeReservedCacheNodesOfferings

#
Service
elasticache

Description

The DescribeReservedCacheNodesOfferings operation lists available reserved cache node offerings.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "d603d9f0-2113-46fb-ae75-d8aaba70b73d",
  "eventName": "DescribeReservedCacheNodesOfferings",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-21T16:26:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "0310fb6f-d54e-11e8-bdf7-9fd98708fad",
  "requestParameters": {
    "maxRecords": 100
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Boto3/1.7.4 Python/3.6.6 Linux/4.16.0-kali2-amd64 Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeServerlessCaches

#
Service
elasticache

Description

Returns information about a specific serverless cache.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6a48d09d-37c6-437e-a0d0-7b381519ec7d",
  "eventName": "DescribeServerlessCaches",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:31:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "82b8644c-0c2d-4b9c-aa4d-38dd98dc8af2",
  "requestParameters": {
    "maxResults": 100
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeServerlessCacheSnapshots

#
Service
elasticache

Description

Returns information about serverless cache snapshots.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ec82181a-2831-448a-a711-5fa3cdacf5bb",
  "eventName": "DescribeServerlessCacheSnapshots",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:31:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9a5c1480-965d-4416-86e9-1c73c9d0e149",
  "requestParameters": {
    "maxResults": 50
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeServiceUpdates

#
Service
elasticache

Description

Returns details of the service updates

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: elasticache:DescribeServiceUpdates",
  "eventID": "c8e44f8d-6483-46bc-aa04-d8a0944bac50",
  "eventName": "DescribeServiceUpdates",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2020-06-10T05:33:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "affff8ad-64dd-4b1b-9e65-2978afe46431",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeSnapshots

#
Service
elasticache

Description

The DescribeSnapshots operation returns information about cache cluster snapshots.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "228a1cdd-9b09-42c9-b7cf-986a0d620a4c",
  "eventName": "DescribeSnapshots",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-17T20:19:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "02ce08c6-d24a-11e8-a226-f9384a808bfe",
  "requestParameters": {
    "maxRecords": 50
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeUpdateActions

#
Service
elasticache

Description

Returns details of the update actions

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: elasticache:DescribeUpdateActions",
  "eventID": "35ece015-b392-4fed-95fc-f9fdc7863de8",
  "eventName": "DescribeUpdateActions",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2020-06-10T05:33:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "bb4ed318-c821-455b-8fb9-a988837c760",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeUserGroups

#
Service
elasticache

Description

Returns a list of user groups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3e2ac35d-15f3-44b6-aedf-706dfb206ab3",
  "eventName": "DescribeUserGroups",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:31:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f6a5f335-a4d0-4a78-aa7c-9f0ec5792e31",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeUsers

#
Service
elasticache

Description

Returns a list of users.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "99ddeb77-17dd-4ad9-b78a-7cae9f717747",
  "eventName": "DescribeUsers",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:31:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a302d1c4-1baa-409e-baad-6e66f090873e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateGlobalReplicationGroup

#
Service
elasticache

Description

Remove a secondary cluster from the Global datastore using the Global datastore name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterValueException",
  "errorMessage": "Region name: dw-probe is not valid.",
  "eventCategory": "Management",
  "eventID": "da30818d-380f-4e38-9245-af38945cb44f",
  "eventName": "DisassociateGlobalReplicationGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ceaee1c5-a6e5-4c6f-bbdb-b30a4d624cea",
  "requestParameters": {
    "globalReplicationGroupId": "dw-probe",
    "replicationGroupId": "dw-probe",
    "replicationGroupRegion": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ExportServerlessCacheSnapshot

#
Service
elasticache

Description

Provides the functionality to export the serverless cache snapshot data to Amazon S3.

FailoverGlobalReplicationGroup

#
Service
elasticache

Description

Used to failover the primary region to a secondary region.

IncreaseNodeGroupsInGlobalReplicationGroup

#
Service
elasticache

Description

Increase the number of node groups in the Global datastore

IncreaseReplicaCount

#
Service
elasticache

Description

Dynamically increases the number of replicas in a Valkey or Redis OSS (cluster mode disabled) replication group or the number of replica nodes in one or more node groups (shards) of a Valkey or Redis OSS (cluster mode enabled) replication g.

ListAllowedNodeTypeModifications

#
Service
elasticache

Description

Lists all available node types that you can scale with your cluster's replication group's current node type.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: elasticache:ListAllowedNodeTypeModifications",
  "eventID": "231745c-6cc8-40bc-85e1-24ac026d5f40",
  "eventName": "ListAllowedNodeTypeModifications",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2018-10-17T20:19:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "02e205f7-d24a-11e8-a226-f9384a808bfe",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListTagsForResource

#
Service
elasticache

Description

Lists all tags currently on a named resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidARNFault",
  "errorMessage": "Input ARN string does not have 7 components.",
  "eventCategory": "Management",
  "eventID": "c105555a-32d2-4d63-a8a1-9dbe8483cca0",
  "eventName": "ListTagsForResource",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T18:43:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d97e6359-810e-44e2-a622-2fed90c08a0b",
  "requestParameters": {
    "resourceName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCacheCluster

#
Service
elasticache

Description

The ModifyCacheCluster operation modifies the settings for a cache cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheClusterNotFoundFault",
  "errorMessage": "CacheCluster not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "7f70834c-2c35-4f90-a9b1-b71e278626fc",
  "eventName": "ModifyCacheCluster",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d667936a-b1c4-4ff9-ac8e-4c17dd7094f1",
  "requestParameters": {
    "applyImmediately": false,
    "cacheClusterId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCacheParameterGroup

#
Service
elasticache

Description

The ModifyCacheParameterGroup operation modifies the parameters of a cache parameter group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheParameterGroupNotFoundFault",
  "errorMessage": "CacheParameterGroup not found: dw-probe",
  "eventCategory": "Management",
  "eventID": "6ec19256-1745-4e3d-990f-1e7bf9453930",
  "eventName": "ModifyCacheParameterGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "92079427-eb1c-4e98-ae96-536e1b566a5c",
  "requestParameters": {
    "cacheParameterGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCacheSubnetGroup

#
Service
elasticache

Description

The ModifyCacheSubnetGroup operation modifies an existing cache subnet group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "CacheSubnetGroupNotFoundFault",
  "errorMessage": "Cache Subnet Group dw-probe does not exist.",
  "eventCategory": "Management",
  "eventID": "71bb7599-e974-4e61-afa0-3909a44230a5",
  "eventName": "ModifyCacheSubnetGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8f77b177-ae5c-4751-9be4-0c17ebc9ab3b",
  "requestParameters": {
    "cacheSubnetGroupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyGlobalReplicationGroup

#
Service
elasticache

Description

Modifies the settings for a Global datastore.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "GlobalReplicationGroupNotFoundFault",
  "errorMessage": "Global Replication Group not found",
  "eventCategory": "Management",
  "eventID": "1c402265-7d33-4931-82bd-8db5eed6f932",
  "eventName": "ModifyGlobalReplicationGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7a240e78-ee83-4b8c-993f-bf2179c501a0",
  "requestParameters": {
    "applyImmediately": false,
    "globalReplicationGroupId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyReplicationGroup

#
Service
elasticache

Description

The ModifyReplicationGroup operation modifies the settings for a replication group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ReplicationGroupNotFoundFault",
  "errorMessage": "Replication group 'dw-probe' not found",
  "eventCategory": "Management",
  "eventID": "e607add6-25bd-4242-8025-781f3321d247",
  "eventName": "ModifyReplicationGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5bb078d1-a9bf-4511-a0ab-f347b6cebf0c",
  "requestParameters": {
    "applyImmediately": false,
    "replicationGroupId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyReplicationGroupShardConfiguration

#
Service
elasticache

Description

Modifies a replication group's shards (node groups) by allowing you to add shards, remove shards, or rebalance the keyspaces among existing shards.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ReplicationGroupNotFoundFault",
  "errorMessage": "Replication group 'dw-probe' not found",
  "eventCategory": "Management",
  "eventID": "00848cba-4244-4369-914d-b5f85e02a1db",
  "eventName": "ModifyReplicationGroupShardConfiguration",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b5ec61be-c776-4256-9e37-e8eda32a49e5",
  "requestParameters": {
    "applyImmediately": false,
    "nodeGroupCount": 1,
    "replicationGroupId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyServerlessCache

#
Service
elasticache

Description

This API modifies the attributes of a serverless cache.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ServerlessCacheNotFoundFault",
  "errorMessage": "Serverless cache with name dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "397a4ab1-1a03-44ad-ae7b-705b11094356",
  "eventName": "ModifyServerlessCache",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "70a7c3c7-f142-4d27-9d15-6eeff6095bbd",
  "requestParameters": {
    "serverlessCacheName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyUser

#
Service
elasticache

Description

Changes user password(s) and/or access string.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UserNotFoundFault",
  "errorMessage": "User ddddd not found.",
  "eventCategory": "Management",
  "eventID": "558a0051-7edc-4581-b568-b0d1cdfbff7e",
  "eventName": "ModifyUser",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "72eb780d-0e43-4743-9320-b83e33be6419",
  "requestParameters": {
    "userId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyUserGroup

#
Service
elasticache

Description

Changes the list of users that belong to the user group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UserGroupNotFoundFault",
  "errorMessage": "User group dw-probe not found.",
  "eventCategory": "Management",
  "eventID": "b256f6e8-2955-4649-87f4-a5adb0f6beb5",
  "eventName": "ModifyUserGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a2700b27-611e-423b-ba1e-e047ca0fdb06",
  "requestParameters": {
    "userGroupId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PurchaseReservedCacheNodesOffering

#
Service
elasticache

Description

The PurchaseReservedCacheNodesOffering operation allows you to purchase a reserved cache node offering.

RebalanceSlotsInGlobalReplicationGroup

#
Service
elasticache

Description

Redistribute slots to ensure uniform distribution across existing shards in the cluster.

RebootCacheCluster

#
Service
elasticache

Description

The RebootCacheCluster operation reboots some, or all, of the cache nodes within a provisioned cache cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "22dbbdac-ff5f-4cdf-9192-c46c4ee21aa3",
  "eventName": "RebootCacheCluster",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T22:45:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b69e2725-3f62-4791-be65-a9ef84636529",
  "requestParameters": {
    "cacheClusterId": "dwfix-heavy-ec",
    "cacheNodeIdsToReboot": [
      "0001"
    ]
  },
  "responseElements": {
    "aRN": "arn:aws:elasticache:us-west-1:123456789012:cluster:dwfix-heavy-ec",
    "atRestEncryptionEnabled": false,
    "autoMinorVersionUpgrade": true,
    "cacheClusterCreateTime": "Jun 29, 2026, 10:45:36 PM",
    "cacheClusterId": "dwfix-heavy-ec",
    "cacheClusterStatus": "rebooting cache cluster nodes",
    "cacheNodeType": "cache.t3.micro",
    "cacheParameterGroup": {
      "cacheNodeIdsToReboot": [],
      "cacheParameterGroupName": "dwfix-heavy-ec-pg",
      "parameterApplyStatus": "in-sync"
    },
    "cacheSecurityGroups": [],
    "cacheSubnetGroupName": "dwfix-heavy-ec-sng",
    "clientDownloadLandingPage": "https://console.aws.amazon.com/elasticache/home#client-download:",
    "deleteProtection": false,
    "engine": "redis",
    "engineVersion": "7.1.0",
    "ipDiscovery": "ipv4",
    "logDeliveryConfigurations": [],
    "networkType": "ipv4",
    "numCacheNodes": 1,
    "pendingModifiedValues": {},
    "preferredAvailabilityZone": "us-west-1c",
    "preferredMaintenanceWindow": "sun:05:00-sun:06:00",
    "replicationGroupLogDeliveryEnabled": false,
    "snapshotRetentionLimit": 0,
    "snapshotWindow": "12:30-13:30",
    "transitEncryptionEnabled": false
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveTagsFromResource

#
Service
elasticache

Description

Removes the tags identified by the TagKeys list from the named resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidARNFault",
  "errorMessage": "Input ARN string does not have 7 components.",
  "eventCategory": "Management",
  "eventID": "e2fc9f28-f704-4d17-9df5-d02626cad159",
  "eventName": "RemoveTagsFromResource",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1995c90e-9e6b-4666-84e5-b62e2c2e8c20",
  "requestParameters": {
    "resourceName": "dw-probe",
    "tagKeys": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetCacheParameterGroup

#
Service
elasticache

Description

The ResetCacheParameterGroup operation modifies the parameters of a cache parameter group to the engine or system default value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterCombinationException",
  "errorMessage": "Must specify either ResetAllParameters or a list of parameters to reset.",
  "eventCategory": "Management",
  "eventID": "965aed20-9cb7-4f4e-af43-6a689947893c",
  "eventName": "ResetCacheParameterGroup",
  "eventSource": "elasticache.amazonaws.com",
  "eventTime": "2026-06-29T19:23:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c9b1810c-b36b-485b-8604-38aa1a1276a2",
  "requestParameters": {
    "cacheParameterGroupName": "dw-probe",
    "resetAllParameters": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticache.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartMigration

#
Service
elasticache

Description

Start the migration of data.

TestFailover

#
Service
elasticache

Description

Represents the input of a TestFailover operation which tests automatic failover on a specified node group (called shard in the console) in a replication group (called cluster in the console).

TestMigration

#
Service
elasticache

Description

Async API to test connection between source and target replication group.