Elastic Load Balancing

eventNameDescriptionSampleRule
anyCatch-all entry for Elastic Load Balancing rules that match the service but not a specific eventName.NN
ApplySecurityGroupsToLoadBalancerAssociates one or more security groups with a Classic Load Balancer, controlling which traffic is allowed to reach the load balancer.YY
CreateListenerCreates a listener for an Application or Network Load Balancer, defining the protocol, port, and default routing actions.YN
ModifyListenerModifies the attributes of a listener, including certificates, default actions, protocol, or port.YY
SetSecurityGroupsReplaces the security groups associated with an Application or Network Load Balancer with a new set of security groups.YY
AddListenerCertificatesAdds the specified SSL server certificate to the certificate list for the specified HTTPS or TLS listener.NN
AddTagsAdds the specified tags to the specified load balancer.YN
AddTrustStoreRevocationsAdds the specified revocation file to the specified trust store.NN
AttachLoadBalancerToSubnetsAdds one or more subnets to the set of configured subnets for the specified load balancer.NN
ConfigureHealthCheckSpecifies the health check settings to use when evaluating the health state of your EC2 instances.NN
CreateAppCookieStickinessPolicyGenerates a stickiness policy with sticky session lifetimes that follow that of an application-generated cookie.NN
CreateLBCookieStickinessPolicyGenerates a stickiness policy with sticky session lifetimes controlled by the lifetime of the browser (user-agent) or a specified expiration period.NN
CreateLoadBalancerCreates a Classic Load Balancer.YN
CreateLoadBalancerListenersCreates one or more listeners for the specified load balancer.NN
CreateLoadBalancerPolicyCreates a policy with the specified attributes for the specified load balancer.NN
CreateRuleCreates a rule for the specified listener.YN
CreateTargetGroupCreates a target group.YN
CreateTrustStoreCreates a trust store.NN
DeleteListenerDeletes the specified listener.YN
DeleteLoadBalancerDeletes the specified load balancer.YN
DeleteLoadBalancerListenersDeletes the specified listeners from the specified load balancer.YN
DeleteLoadBalancerPolicyDeletes the specified policy from the specified load balancer.YN
DeleteRuleDeletes the specified rule.YN
DeleteSharedTrustStoreAssociationDeletes a shared trust store association.YN
DeleteTargetGroupDeletes the specified target group.YN
DeleteTrustStoreDeletes a trust store.YN
DeregisterInstancesFromLoadBalancerDeregisters the specified instances from the specified load balancer.YN
DeregisterTargetsDeregisters the specified targets from the specified target group.YN
DescribeAccountLimitsDescribes the current Elastic Load Balancing resource limits for your AWS account.YN
DescribeCapacityReservationDescribes the capacity reservation status for the specified load balancer.YN
DescribeInstanceHealthDescribes the state of the specified instances with respect to the specified load balancer.YN
DescribeListenerAttributesDescribes the attributes for the specified listener.YN
DescribeListenerCertificatesDescribes the default certificate and the certificate list for the specified HTTPS or TLS listener.YN
DescribeListenersDescribes the specified listeners or the listeners for the specified Application Load Balancer, Network Load Balancer, or Gateway Load Balancer.YN
DescribeLoadBalancerAttributesDescribes the attributes for the specified load balancer.YN
DescribeLoadBalancerPoliciesDescribes the specified policies.YN
DescribeLoadBalancerPolicyTypesDescribes the specified load balancer policy types or all load balancer policy types.YN
DescribeLoadBalancersDescribes the specified the load balancers.YN
DescribeRulesDescribes the specified rules or the rules for the specified listener.YN
DescribeSSLPoliciesDescribes the specified policies or all policies used for SSL negotiation.YN
DescribeTagsDescribes the tags associated with the specified load balancers.YN
DescribeTargetGroupAttributesDescribes the attributes for the specified target group.YN
DescribeTargetGroupsDescribes the specified target groups or all of your target groups.YN
DescribeTargetHealthDescribes the health of the specified targets or all of your targets.NN
DescribeTrustStoreAssociationsDescribes all resources associated with the specified trust store.YN
DescribeTrustStoreRevocationsDescribes the revocation files in use by the specified trust store or revocation files.YN
DescribeTrustStoresDescribes all trust stores for the specified account.YN
DetachLoadBalancerFromSubnetsRemoves the specified subnets from the set of configured subnets for the load balancer.YN
DisableAvailabilityZonesForLoadBalancerRemoves the specified Availability Zones from the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC.YN
EnableAvailabilityZonesForLoadBalancerAdds the specified Availability Zones to the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC.NN
GetResourcePolicyRetrieves the resource policy for a specified resource.YN
GetTrustStoreCaCertificatesBundleRetrieves the ca certificate bundle.YN
GetTrustStoreRevocationContentRetrieves the specified revocation file.YN
ModifyCapacityReservationModifies the capacity reservation of the specified load balancer.YN
ModifyIpPools[Application Load Balancers] Modify the IP pool associated to a load balancer.YN
ModifyListenerAttributesModifies the specified attributes of the specified listener.YN
ModifyLoadBalancerAttributesModifies the attributes of the specified load balancer.YN
ModifyRuleReplaces the specified properties of the specified rule.YN
ModifyTargetGroupModifies the health checks used when evaluating the health state of the targets in the specified target group.YN
ModifyTargetGroupAttributesModifies the specified attributes of the specified target group.YN
ModifyTrustStoreUpdate the ca certificate bundle for the specified trust store.YN
RegisterInstancesWithLoadBalancerAdds the specified instances to the specified load balancer.NN
RegisterTargetsRegisters the specified targets with the specified target group.YN
RemoveListenerCertificatesRemoves the specified certificate from the certificate list for the specified HTTPS or TLS listener.YN
RemoveTagsRemoves one or more tags from the specified load balancer.YN
RemoveTrustStoreRevocationsRemoves the specified revocation file from the specified trust store.YN
SetIpAddressTypeSets the type of IP addresses used by the subnets of the specified load balancer.YN
SetLoadBalancerListenerSSLCertificateSets the certificate that terminates the specified listener's SSL connections.NN
SetLoadBalancerPoliciesForBackendServerReplaces the set of policies associated with the specified port on which the EC2 instance is listening with a new set of policies.NN
SetLoadBalancerPoliciesOfListenerReplaces the current set of policies for the specified load balancer port with the specified set of policies.NN
SetRulePrioritiesSets the priorities of the specified rules.YN
SetSubnetsEnables the Availability Zones for the specified public subnets for the specified Application Load Balancer, Network Load Balancer or Gateway Load Balancer.YN
DescribeWebACLAssociationDescribeWebACLAssociation recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetLoadBalancerWebACLGetLoadBalancerWebACL recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN

any: Elastic Load Balancing (catch-all)

#
Service
elasticloadbalancing

Description

Catch-all entry for Elastic Load Balancing rules that match the service but not a specific eventName.

ApplySecurityGroupsToLoadBalancer

#
Service
elasticloadbalancing

Description

Associates one or more security groups with a Classic Load Balancer, controlling which traffic is allowed to reach the load balancer.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:16Z",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventName": "ApplySecurityGroupsToLoadBalancer",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#elb.apply-security-groups-to-load-balancer",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-harn-elb-eb7866'",
  "requestParameters": {
    "loadBalancerName": "dw-harn-elb-eb7866",
    "securityGroups": [
      "sg-00000000000000000"
    ]
  },
  "responseElements": null,
  "requestID": "cd7c77a1-99b4-4dcb-8331-de3192bc11a7",
  "eventID": "19c400be-5d67-4d3b-937f-a0fd8ea8d43f",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "apiVersion": "2012-06-01",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • LoadBalancer Security Group Modification source medium: Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.T1190↳ also matches SetSecurityGroups

Kusto #

CreateListener

#
Service
elasticloadbalancing

Description

Creates a listener for an Application or Network Load Balancer, defining the protocol, port, and default routing actions.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d5947dd5-efb1-4c40-9bbf-7f2d31774abf",
  "eventName": "CreateListener",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a9742afd-937e-405a-aa8d-0cf67cbe7b0a",
  "requestParameters": {
    "defaultActions": [
      {
        "fixedResponseConfig": {
          "contentType": "text/plain",
          "messageBody": "dwfix-ok",
          "statusCode": "200"
        },
        "type": "fixed-response"
      }
    ],
    "loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
    "port": 80,
    "protocol": "HTTP",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "listeners": [
      {
        "defaultActions": [
          {
            "fixedResponseConfig": {
              "contentType": "text/plain",
              "messageBody": "dwfix-ok",
              "statusCode": "200"
            },
            "type": "fixed-response"
          }
        ],
        "listenerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e",
        "loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
        "port": 80,
        "protocol": "HTTP"
      }
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyListener

#
Service
elasticloadbalancing

Description

Modifies the attributes of a listener, including certificates, default actions, protocol, or port.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "51d5ecff-3d7e-4369-87a1-af1ca6580c3d",
  "eventName": "ModifyListener",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "68182055-dfb3-413d-a36c-62bd614c97f8",
  "requestParameters": {
    "listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

SetSecurityGroups

#
Service
elasticloadbalancing

Description

Replaces the security groups associated with an Application or Network Load Balancer with a new set of security groups.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4726a0cf-e3c1-4060-a8d1-f20c21aad2c6",
  "eventName": "SetSecurityGroups",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "64e9e572-c6a0-46bf-af57-609de730b137",
  "requestParameters": {
    "loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
    "securityGroups": [
      "sg-063fc1a8302bc48a4"
    ]
  },
  "responseElements": {
    "securityGroupIds": [
      "sg-063fc1a8302bc48a4"
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • LoadBalancer Security Group Modification source medium: Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.T1190↳ also matches ApplySecurityGroupsToLoadBalancer

Kusto #

AddListenerCertificates

#
Service
elasticloadbalancing

Description

Adds the specified SSL server certificate to the certificate list for the specified HTTPS or TLS listener.

AddTags

#
Service
elasticloadbalancing

Description

Adds the specified tags to the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ddccc2d0-d148-4a61-aa8f-52af44ee1caf",
  "eventName": "AddTags",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3d492cd0-6ca3-4253-b7e9-401c8c9fa53f",
  "requestParameters": {
    "resourceArns": [
      "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49"
    ],
    "tags": [
      {
        "key": "Stage",
        "value": "test"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AddTrustStoreRevocations

#
Service
elasticloadbalancing

Description

Adds the specified revocation file to the specified trust store.

AttachLoadBalancerToSubnets

#
Service
elasticloadbalancing

Description

Adds one or more subnets to the set of configured subnets for the specified load balancer.

ConfigureHealthCheck

#
Service
elasticloadbalancing

Description

Specifies the health check settings to use when evaluating the health state of your EC2 instances.

CreateAppCookieStickinessPolicy

#
Service
elasticloadbalancing

Description

Generates a stickiness policy with sticky session lifetimes that follow that of an application-generated cookie.

CreateLBCookieStickinessPolicy

#
Service
elasticloadbalancing

Description

Generates a stickiness policy with sticky session lifetimes controlled by the lifetime of the browser (user-agent) or a specified expiration period.

CreateLoadBalancer

#
Service
elasticloadbalancing

Description

Creates a Classic Load Balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4234414a-d796-4a09-b832-4d8069466b57",
  "eventName": "CreateLoadBalancer",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:10:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "299c081d-f518-47a8-a257-ee0a947ae7f1",
  "requestParameters": {
    "ipAddressType": "ipv4",
    "name": "dwfix-elb-ct",
    "scheme": "internet-facing",
    "securityGroups": [
      "sg-063fc1a8302bc48a4"
    ],
    "subnets": [
      "subnet-0c9f719882f5c95ae",
      "subnet-04caa2ba1250f8fb6"
    ],
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      },
      {
        "key": "Purpose",
        "value": "sample-collection"
      }
    ],
    "type": "application"
  },
  "responseElements": {
    "loadBalancers": [
      {
        "availabilityZones": [
          {
            "loadBalancerAddresses": [],
            "subnetId": "subnet-0c9f719882f5c95ae",
            "zoneName": "us-west-1a"
          },
          {
            "loadBalancerAddresses": [],
            "subnetId": "subnet-04caa2ba1250f8fb6",
            "zoneName": "us-west-1c"
          }
        ],
        "canonicalHostedZoneId": "Z368ELLRRE2KJ0",
        "createdTime": "Jun 29, 2026, 9:10:12 PM",
        "dNSName": "dwfix-elb-ct-1819491149.us-west-1.elb.amazonaws.com",
        "ipAddressType": "ipv4",
        "loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
        "loadBalancerName": "dwfix-elb-ct",
        "scheme": "internet-facing",
        "securityGroups": [
          "sg-063fc1a8302bc48a4"
        ],
        "state": {
          "code": "provisioning"
        },
        "type": "application",
        "vpcId": "vpc-0cf63cfb072f7d61f"
      }
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateLoadBalancerListeners

#
Service
elasticloadbalancing

Description

Creates one or more listeners for the specified load balancer.

CreateLoadBalancerPolicy

#
Service
elasticloadbalancing

Description

Creates a policy with the specified attributes for the specified load balancer.

CreateRule

#
Service
elasticloadbalancing

Description

Creates a rule for the specified listener.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "63719f30-5a8e-4762-9475-83ab9d06c089",
  "eventName": "CreateRule",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2421d1db-aa27-40cc-81d3-4a3afa2ccf4e",
  "requestParameters": {
    "actions": [
      {
        "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
        "type": "forward"
      }
    ],
    "conditions": [
      {
        "field": "path-pattern",
        "pathPatternConfig": {
          "values": [
            "/dwfix/*"
          ]
        }
      }
    ],
    "listenerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e",
    "priority": 10,
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "responseElements": {
    "rules": [
      {
        "actions": [
          {
            "forwardConfig": {
              "targetGroupStickinessConfig": {
                "enabled": false
              },
              "targetGroups": [
                {
                  "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
                  "weight": 1
                }
              ]
            },
            "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
            "type": "forward"
          }
        ],
        "conditions": [
          {
            "field": "path-pattern",
            "pathPatternConfig": {
              "values": [
                "/dwfix/*"
              ]
            },
            "values": [
              "/dwfix/*"
            ]
          }
        ],
        "isDefault": false,
        "priority": "10",
        "ruleArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener-rule/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e/bf31981153a4c38e",
        "transforms": []
      }
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTargetGroup

#
Service
elasticloadbalancing

Description

Creates a target group.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d4cbca58-3cba-45ca-b826-e119f4e23511",
  "eventName": "CreateTargetGroup",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:10:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5f92324b-9d42-4ba8-9bc1-ec276028cf7e",
  "requestParameters": {
    "healthCheckEnabled": true,
    "healthCheckIntervalSeconds": 30,
    "healthCheckPath": "/health",
    "healthCheckProtocol": "HTTP",
    "healthCheckTimeoutSeconds": 5,
    "healthyThresholdCount": 2,
    "name": "dwfix-tg-ct",
    "port": 80,
    "protocol": "HTTP",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "targetType": "ip",
    "unhealthyThresholdCount": 3,
    "vpcId": "vpc-0cf63cfb072f7d61f"
  },
  "responseElements": {
    "targetGroups": [
      {
        "healthCheckEnabled": true,
        "healthCheckIntervalSeconds": 30,
        "healthCheckPath": "/health",
        "healthCheckPort": "traffic-port",
        "healthCheckProtocol": "HTTP",
        "healthCheckTimeoutSeconds": 5,
        "healthyThresholdCount": 2,
        "ipAddressType": "ipv4",
        "matcher": {
          "httpCode": "200"
        },
        "port": 80,
        "protocol": "HTTP",
        "protocolVersion": "HTTP1",
        "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
        "targetGroupName": "dwfix-tg-ct",
        "targetType": "ip",
        "unhealthyThresholdCount": 3,
        "vpcId": "vpc-0cf63cfb072f7d61f"
      }
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTrustStore

#
Service
elasticloadbalancing

Description

Creates a trust store.

DeleteListener

#
Service
elasticloadbalancing

Description

Deletes the specified listener.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "18e0e4bc-5250-4543-b79e-b7c7d26c47d7",
  "eventName": "DeleteListener",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f4932e45-36e8-4bee-b546-7f67df1d5b75",
  "requestParameters": {
    "listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLoadBalancer

#
Service
elasticloadbalancing

Description

Deletes the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f74f165c-7097-4521-9d11-7418b6e86b02",
  "eventName": "DeleteLoadBalancer",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "09cb0a1a-c6fb-493a-88fa-e218e5ac7b3c",
  "requestParameters": {
    "loadBalancerName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLoadBalancerListeners

#
Service
elasticloadbalancing

Description

Deletes the specified listeners from the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "ce60cc87-a9af-4852-b523-d1dcf98745cd",
  "eventName": "DeleteLoadBalancerListeners",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "83313971-07a7-4073-a017-0d92c99668ee",
  "requestParameters": {
    "loadBalancerName": "dw-probe",
    "loadBalancerPorts": [
      1
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLoadBalancerPolicy

#
Service
elasticloadbalancing

Description

Deletes the specified policy from the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "8d1e64d1-794b-4550-9222-b492a7ef67e7",
  "eventName": "DeleteLoadBalancerPolicy",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "10935fd3-0127-4186-92a4-8d2e2160d45a",
  "requestParameters": {
    "loadBalancerName": "dw-probe",
    "policyName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRule

#
Service
elasticloadbalancing

Description

Deletes the specified rule.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' is not a valid listener rule ARN",
  "eventCategory": "Management",
  "eventID": "7a518cbb-048b-4f22-85cf-6d1e6809cd42",
  "eventName": "DeleteRule",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "00e6a46f-95bc-4f95-aa9c-30d5a10b471f",
  "requestParameters": {
    "ruleArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSharedTrustStoreAssociation

#
Service
elasticloadbalancing

Description

Deletes a shared trust store association.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "19239926-b9fe-4c49-851a-055c79c04918",
  "eventName": "DeleteSharedTrustStoreAssociation",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "52e969bd-c6a2-4d9b-9084-244af75ee32c",
  "requestParameters": {
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe",
    "trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTargetGroup

#
Service
elasticloadbalancing

Description

Deletes the specified target group.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "e13de03d-5f84-46d1-9ce3-148f5c97ba91",
  "eventName": "DeleteTargetGroup",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d24064ba-9587-429a-b9d2-272f310de1b5",
  "requestParameters": {
    "targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTrustStore

#
Service
elasticloadbalancing

Description

Deletes a trust store.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "7598db67-dc96-42dc-8460-57b5b0d0b27d",
  "eventName": "DeleteTrustStore",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ebf83d8f-da01-4d8e-9b55-a856446dd16c",
  "requestParameters": {
    "trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterInstancesFromLoadBalancer

#
Service
elasticloadbalancing

Description

Deregisters the specified instances from the specified load balancer.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
  "eventCategory": "Management",
  "eventID": "4e70e0af-8136-4ef3-b63c-8aee4ef9a1e0",
  "eventName": "DeregisterInstancesFromLoadBalancer",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "db3e155c-2ad8-4b9a-88b6-d43dbdb591dd",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterTargets

#
Service
elasticloadbalancing

Description

Deregisters the specified targets from the specified target group.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "ed5094dd-99bd-4b7d-b3a7-a3a63db9fe00",
  "eventName": "DeregisterTargets",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5da57148-4e66-4ca0-9d6e-680ca6131569",
  "requestParameters": {
    "targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe",
    "targets": [
      {
        "id": "dw-probe"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAccountLimits

#
Service
elasticloadbalancing

Description

Describes the current Elastic Load Balancing resource limits for your AWS account.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-east-1",
  "eventID": "5ed179b2-36a9-4717-9d43-239539b311ce1",
  "eventName": "DescribeAccountLimits",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2018-10-17T20:03:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "c24b0edd-d247-11e8-81b0-73efac09c3e4",
  "requestParameters": null,
  "responseElements": {
    "limits": [
      {
        "max": "20",
        "name": "classic-load-balancers"
      },
      {
        "max": "100",
        "name": "classic-listeners"
      },
      {
        "max": "1000",
        "name": "classic-registered-instances"
      }
    ]
  },
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCapacityReservation

#
Service
elasticloadbalancing

Description

Describes the capacity reservation status for the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "1be9962e-441f-472d-b6b6-295e00ba6c64",
  "eventName": "DescribeCapacityReservation",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ba3348f6-c78b-4bfd-9be5-c46e2c932377",
  "requestParameters": {
    "loadBalancerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceHealth

#
Service
elasticloadbalancing

Description

Describes the state of the specified instances with respect to the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "ea1fbc52-fd54-4a3e-94f3-60eac43ed985",
  "eventName": "DescribeInstanceHealth",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "077442ad-3d95-4b02-afdb-a72e770f02a2",
  "requestParameters": {
    "loadBalancerName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeListenerAttributes

#
Service
elasticloadbalancing

Description

Describes the attributes for the specified listener.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "efbe8afa-f185-4ac8-b8d2-1eb4e417789b",
  "eventName": "DescribeListenerAttributes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "64fa9b06-f30f-4ef8-922d-ed611ba0bd22",
  "requestParameters": {
    "listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeListenerCertificates

#
Service
elasticloadbalancing

Description

Describes the default certificate and the certificate list for the specified HTTPS or TLS listener.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' is not a valid listener ARN",
  "eventCategory": "Management",
  "eventID": "a988b33e-47e6-4ec0-a8c5-4abd9512ed5c",
  "eventName": "DescribeListenerCertificates",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "329068ce-b1a2-44c3-809f-668d2ba5adcb",
  "requestParameters": {
    "listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeListeners

#
Service
elasticloadbalancing

Description

Describes the specified listeners or the listeners for the specified Application Load Balancer, Network Load Balancer, or Gateway Load Balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "You must specify either either listener ARNs or a load balancer ARN",
  "eventID": "51441b9-901b-4b86-9caa-74bee6ad44f5",
  "eventName": "DescribeListeners",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2018-10-21T16:26:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "153567c-d54e-11e8-8672-a75fe701a20e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Boto3/1.7.4 Python/3.6.6 Linux/4.16.0-kali2-amd64 Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeLoadBalancerAttributes

#
Service
elasticloadbalancing

Description

Describes the attributes for the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "02c4149a-117e-459b-9ae4-97d58a1913fa",
  "eventName": "DescribeLoadBalancerAttributes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "993e9321-6e6d-4cb0-939b-d44bc9b7090b",
  "requestParameters": {
    "loadBalancerName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeLoadBalancerPolicies

#
Service
elasticloadbalancing

Description

Describes the specified policies.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "ap-south-1",
  "eventID": "55808b8-5fa8-4a26-bb6c-7db19382dcf8",
  "eventName": "DescribeLoadBalancerPolicies",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2018-08-05T17:02:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "5e1018d8-98d1-11e8-b4ed-543058db633b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "250.251.253.3",
  "userAgent": "Boto3/1.5.32 Python/3.6.4 Darwin/17.6.0 Botocore/1.8.50",
  "userIdentity": {
    "accessKeyId": "ASIAPYBUDZE3ZQU169GB",
    "accountId": "811596193553",
    "arn": "arn:aws:sts::811596193553:assumed-role/SummitRouteAudit/4032461535040776536",
    "principalId": "AROAMY611GPC0EPB1P0F9:4032461535040776536",
    "sessionContext": {
      "attributes": {
        "creationDate": "2018-08-05T17:00:49Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {
        "accountId": "811596193553",
        "arn": "arn:aws:iam::811596193553:role/SummitRouteAudit",
        "principalId": "AROAMY611GPC0EPB1P0F9",
        "type": "Role",
        "userName": "SummitRouteAudit"
      }
    },
    "type": "AssumedRole"
  }
}

References #

DescribeLoadBalancerPolicyTypes

#
Service
elasticloadbalancing

Description

Describes the specified load balancer policy types or all load balancer policy types.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-east-1",
  "eventID": "55f64e05-3ea1-435d-8e9d-ba1c382b6e6c",
  "eventName": "DescribeLoadBalancerPolicyTypes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2018-10-17T20:03:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "c263c721-d247-11e8-81b0-73efac09c3e4",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeLoadBalancers

#
Service
elasticloadbalancing

Description

Describes the specified the load balancers.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "e3bb4364-d0ca-4c0f-a194-b3af5d5280b3",
  "eventName": "DescribeLoadBalancers",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "bec55cd2-46d8-4e98-adf6-c8fe209ec48a",
  "requestParameters": {
    "pageSize": 200
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeRules

#
Service
elasticloadbalancing

Description

Describes the specified rules or the rules for the specified listener.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "You must specify either listener rule ARNs or a listener ARN",
  "eventID": "fb7164ba-3cab-4b57-878b-b791c88628d9",
  "eventName": "DescribeRules",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2018-10-17T20:23:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "8b8cbfd8-d24a-11e8-ad05-8f41c543bc94",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeSSLPolicies

#
Service
elasticloadbalancing

Description

Describes the specified policies or all policies used for SSL negotiation.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "ap-northeast-1",
  "eventID": "33db55cc-c408-4207-93bf-efbb48dcf7cc",
  "eventName": "DescribeSSLPolicies",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2018-01-18T20:33:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "d1299bd5-fc8e-11e7-b3e8-13d2f20a35ba",
  "requestParameters": {
    "names": []
  },
  "responseElements": {
    "sslPolicies": [
      {
        "ciphers": [
          {
            "name": "ECDHE-ECDSA-AES128-GCM-SHA256",
            "priority": 1
          },
          {
            "name": "ECDHE-RSA-AES128-GCM-SHA256",
            "priority": 2
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA256",
            "priority": 3
          },
          {
            "name": "ECDHE-RSA-AES128-SHA256",
            "priority": 4
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA",
            "priority": 5
          },
          {
            "name": "ECDHE-RSA-AES128-SHA",
            "priority": 6
          },
          {
            "name": "ECDHE-ECDSA-AES256-GCM-SHA384",
            "priority": 7
          },
          {
            "name": "ECDHE-RSA-AES256-GCM-SHA384",
            "priority": 8
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA384",
            "priority": 9
          },
          {
            "name": "ECDHE-RSA-AES256-SHA384",
            "priority": 10
          },
          {
            "name": "ECDHE-RSA-AES256-SHA",
            "priority": 11
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA",
            "priority": 12
          },
          {
            "name": "AES128-GCM-SHA256",
            "priority": 13
          },
          {
            "name": "AES128-SHA256",
            "priority": 14
          },
          {
            "name": "AES128-SHA",
            "priority": 15
          },
          {
            "name": "AES256-GCM-SHA384",
            "priority": 16
          },
          {
            "name": "AES256-SHA256",
            "priority": 17
          },
          {
            "name": "AES256-SHA",
            "priority": 18
          }
        ],
        "name": "ELBSecurityPolicy-2016-08",
        "sslProtocols": [
          "TLSv1",
          "TLSv1.1",
          "TLSv1.2"
        ]
      },
      {
        "ciphers": [
          {
            "name": "ECDHE-ECDSA-AES128-GCM-SHA256",
            "priority": 1
          },
          {
            "name": "ECDHE-RSA-AES128-GCM-SHA256",
            "priority": 2
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA256",
            "priority": 3
          },
          {
            "name": "ECDHE-RSA-AES128-SHA256",
            "priority": 4
          },
          {
            "name": "ECDHE-ECDSA-AES256-GCM-SHA384",
            "priority": 5
          },
          {
            "name": "ECDHE-RSA-AES256-GCM-SHA384",
            "priority": 6
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA384",
            "priority": 7
          },
          {
            "name": "ECDHE-RSA-AES256-SHA384",
            "priority": 8
          },
          {
            "name": "AES128-GCM-SHA256",
            "priority": 9
          },
          {
            "name": "AES128-SHA256",
            "priority": 10
          },
          {
            "name": "AES256-GCM-SHA384",
            "priority": 11
          },
          {
            "name": "AES256-SHA256",
            "priority": 12
          }
        ],
        "name": "ELBSecurityPolicy-TLS-1-2-2017-01",
        "sslProtocols": [
          "TLSv1.2"
        ]
      },
      {
        "ciphers": [
          {
            "name": "ECDHE-ECDSA-AES128-GCM-SHA256",
            "priority": 1
          },
          {
            "name": "ECDHE-RSA-AES128-GCM-SHA256",
            "priority": 2
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA256",
            "priority": 3
          },
          {
            "name": "ECDHE-RSA-AES128-SHA256",
            "priority": 4
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA",
            "priority": 5
          },
          {
            "name": "ECDHE-RSA-AES128-SHA",
            "priority": 6
          },
          {
            "name": "ECDHE-ECDSA-AES256-GCM-SHA384",
            "priority": 7
          },
          {
            "name": "ECDHE-RSA-AES256-GCM-SHA384",
            "priority": 8
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA384",
            "priority": 9
          },
          {
            "name": "ECDHE-RSA-AES256-SHA384",
            "priority": 10
          },
          {
            "name": "ECDHE-RSA-AES256-SHA",
            "priority": 11
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA",
            "priority": 12
          },
          {
            "name": "AES128-GCM-SHA256",
            "priority": 13
          },
          {
            "name": "AES128-SHA256",
            "priority": 14
          },
          {
            "name": "AES128-SHA",
            "priority": 15
          },
          {
            "name": "AES256-GCM-SHA384",
            "priority": 16
          },
          {
            "name": "AES256-SHA256",
            "priority": 17
          },
          {
            "name": "AES256-SHA",
            "priority": 18
          }
        ],
        "name": "ELBSecurityPolicy-TLS-1-1-2017-01",
        "sslProtocols": [
          "TLSv1.1",
          "TLSv1.2"
        ]
      },
      {
        "ciphers": [
          {
            "name": "ECDHE-ECDSA-AES128-GCM-SHA256",
            "priority": 1
          },
          {
            "name": "ECDHE-RSA-AES128-GCM-SHA256",
            "priority": 2
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA256",
            "priority": 3
          },
          {
            "name": "ECDHE-RSA-AES128-SHA256",
            "priority": 4
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA",
            "priority": 5
          },
          {
            "name": "ECDHE-RSA-AES128-SHA",
            "priority": 6
          },
          {
            "name": "ECDHE-ECDSA-AES256-GCM-SHA384",
            "priority": 7
          },
          {
            "name": "ECDHE-RSA-AES256-GCM-SHA384",
            "priority": 8
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA384",
            "priority": 9
          },
          {
            "name": "ECDHE-RSA-AES256-SHA384",
            "priority": 10
          },
          {
            "name": "ECDHE-RSA-AES256-SHA",
            "priority": 11
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA",
            "priority": 12
          },
          {
            "name": "AES128-GCM-SHA256",
            "priority": 13
          },
          {
            "name": "AES128-SHA256",
            "priority": 14
          },
          {
            "name": "AES128-SHA",
            "priority": 15
          },
          {
            "name": "AES256-GCM-SHA384",
            "priority": 16
          },
          {
            "name": "AES256-SHA256",
            "priority": 17
          },
          {
            "name": "AES256-SHA",
            "priority": 18
          }
        ],
        "name": "ELBSecurityPolicy-2015-05",
        "sslProtocols": [
          "TLSv1",
          "TLSv1.1",
          "TLSv1.2"
        ]
      },
      {
        "ciphers": [
          {
            "name": "ECDHE-ECDSA-AES128-GCM-SHA256",
            "priority": 1
          },
          {
            "name": "ECDHE-RSA-AES128-GCM-SHA256",
            "priority": 2
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA256",
            "priority": 3
          },
          {
            "name": "ECDHE-RSA-AES128-SHA256",
            "priority": 4
          },
          {
            "name": "ECDHE-ECDSA-AES128-SHA",
            "priority": 5
          },
          {
            "name": "ECDHE-RSA-AES128-SHA",
            "priority": 6
          },
          {
            "name": "ECDHE-ECDSA-AES256-GCM-SHA384",
            "priority": 7
          },
          {
            "name": "ECDHE-RSA-AES256-GCM-SHA384",
            "priority": 8
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA384",
            "priority": 9
          },
          {
            "name": "ECDHE-RSA-AES256-SHA384",
            "priority": 10
          },
          {
            "name": "ECDHE-RSA-AES256-SHA",
            "priority": 11
          },
          {
            "name": "ECDHE-ECDSA-AES256-SHA",
            "priority": 12
          },
          {
            "name": "AES128-GCM-SHA256",
            "priority": 13
          },
          {
            "name": "AES128-SHA256",
            "priority": 14
          },
          {
            "name": "AES128-SHA",
            "priority": 15
          },
          {
            "name": "AES256-GCM-SHA384",
            "priority": 16
          },
          {
            "name": "AES256-SHA256",
            "priority": 17
          },
          {
            "name": "AES256-SHA",
            "priority": 18
          },
          {
            "name": "DES-CBC3-SHA",
            "priority": 19
          }
        ],
        "name": "ELBSecurityPolicy-TLS-1-0-2015-04",
        "sslProtocols": [
          "TLSv1",
          "TLSv1.1",
          "TLSv1.2"
        ]
      }
    ]
  },
  "sourceIPAddress": "250.253.254.5",
  "userAgent": "Boto3/1.5.18 Python/3.6.1 Darwin/16.7.0 Botocore/1.8.32",
  "userIdentity": {
    "accessKeyId": "ASIAHP2ACUZ6KIJYE7JR",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "sessionContext": {
      "attributes": {
        "creationDate": "2018-01-18T20:29:52Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeTags

#
Service
elasticloadbalancing

Description

Describes the tags associated with the specified load balancers.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "Cannot find Load Balancer dw-probe",
  "eventCategory": "Management",
  "eventID": "9cdc8d54-9675-4cc3-8fa7-468b3afb97b9",
  "eventName": "DescribeTags",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f6bc7a5d-44ec-4aab-a5bf-33d63c3602c7",
  "requestParameters": {
    "loadBalancerNames": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTargetGroupAttributes

#
Service
elasticloadbalancing

Description

Describes the attributes for the specified target group.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "b9d1103f-7481-48e1-a97a-e8b054e1916b",
  "eventName": "DescribeTargetGroupAttributes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "88ea1a0f-43f9-4c86-a304-c3d156fb4e28",
  "requestParameters": {
    "targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTargetGroups

#
Service
elasticloadbalancing

Description

Describes the specified target groups or all of your target groups.

Example CloudTrail Event #

{
  "awsRegion": "ap-south-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::111111111111:user/cloudsploit is not authorized to perform: elasticloadbalancing:DescribeTargetGroups",
  "eventCategory": "Management",
  "eventID": "f58a0152-f2da-42f6-807b-4de082274a36",
  "eventName": "DescribeTargetGroups",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2021-04-13T11:35:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "b971a811-614e-428d-9273-553de6464f65",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "95.90.195.80",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

DescribeTargetHealth

#
Service
elasticloadbalancing

Description

Describes the health of the specified targets or all of your targets.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "287c9207-28bc-4e8e-ac69-ffbbf8bfa333",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventName": "DescribeTargetHealth",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "2015-12-01",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "74f13232-10e8-45d0-be2f-dd1b58e021f5",
  "userAgent": "ecs.amazonaws.com"
}

DescribeTrustStoreAssociations

#
Service
elasticloadbalancing

Description

Describes all resources associated with the specified trust store.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "1925c8b9-9b87-49a4-bc8e-a2e2e7391a55",
  "eventName": "DescribeTrustStoreAssociations",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "97fb5b74-7a2f-4cbb-bf09-ce7954105a46",
  "requestParameters": {
    "trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTrustStoreRevocations

#
Service
elasticloadbalancing

Description

Describes the revocation files in use by the specified trust store or revocation files.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "8b6f0416-b90d-4eed-ba65-6d21b698ee0f",
  "eventName": "DescribeTrustStoreRevocations",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "50d523c9-ac81-4234-946b-2d381fb2b61b",
  "requestParameters": {
    "trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTrustStores

#
Service
elasticloadbalancing

Description

Describes all trust stores for the specified account.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dc486195-11a7-4733-a786-965b0dd8861a",
  "eventName": "DescribeTrustStores",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:31:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "699e96d8-8342-4989-b12c-9c6f6a9746c6",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DetachLoadBalancerFromSubnets

#
Service
elasticloadbalancing

Description

Removes the specified subnets from the set of configured subnets for the load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "958ce188-741e-456f-a21c-bbcc40a3c09d",
  "eventName": "DetachLoadBalancerFromSubnets",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "804d6bc1-cc26-4588-9ec8-69052ef5be8b",
  "requestParameters": {
    "loadBalancerName": "dw-probe",
    "subnets": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableAvailabilityZonesForLoadBalancer

#
Service
elasticloadbalancing

Description

Removes the specified Availability Zones from the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC.

Example CloudTrail Event #

{
  "apiVersion": "2012-06-01",
  "awsRegion": "us-west-1",
  "errorCode": "AccessPointNotFoundException",
  "errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "99cfc952-0936-4c38-aa16-67a020bb6a91",
  "eventName": "DisableAvailabilityZonesForLoadBalancer",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8dc809c1-f260-4bb9-8c43-56acb62e7ce2",
  "requestParameters": {
    "availabilityZones": [
      "dw-probe"
    ],
    "loadBalancerName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableAvailabilityZonesForLoadBalancer

#
Service
elasticloadbalancing

Description

Adds the specified Availability Zones to the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC.

GetResourcePolicy

#
Service
elasticloadbalancing

Description

Retrieves the resource policy for a specified resource.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "7d7e1124-cc47-4de5-8067-d8c0018fd942",
  "eventName": "GetResourcePolicy",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "10235ef3-b818-4616-8c24-8462894f2ba3",
  "requestParameters": {
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTrustStoreCaCertificatesBundle

#
Service
elasticloadbalancing

Description

Retrieves the ca certificate bundle.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "7412b889-fb08-3843-9946-1aadb76788e5",
  "eventName": "GetTrustStoreCaCertificatesBundle",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "114f86bd-b579-45d3-9dba-4cfab42dbc65",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:iam::123456789012:role/dw-probe",
      "accountId": "HIDDEN_DUE_TO_SECURITY_REASONS",
      "type": "AWS::ElasticLoadBalancingV2::TrustStore"
    }
  ],
  "responseElements": null,
  "sharedEventID": "9eb40541-e9e2-4e86-a607-2f367999b1fb",
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTrustStoreRevocationContent

#
Service
elasticloadbalancing

Description

Retrieves the specified revocation file.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "c154504d-cedb-3521-bf4a-a23340f849da",
  "eventName": "GetTrustStoreRevocationContent",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T18:43:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "dac8e53c-fc6a-4a12-a216-2c627fd71ce1",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:iam::123456789012:role/dw-probe",
      "accountId": "HIDDEN_DUE_TO_SECURITY_REASONS",
      "type": "AWS::ElasticLoadBalancingV2::TrustStore"
    }
  ],
  "responseElements": null,
  "sharedEventID": "8c7693a5-12cb-4c69-9a9e-ed82717264a2",
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCapacityReservation

#
Service
elasticloadbalancing

Description

Modifies the capacity reservation of the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "91677d0f-c0bc-4a84-8b37-bf7b1cdf30d0",
  "eventName": "ModifyCapacityReservation",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6f39cbde-af1c-4d42-89b2-52fbb314fa88",
  "requestParameters": {
    "loadBalancerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpPools

#
Service
elasticloadbalancing

Description

[Application Load Balancers] Modify the IP pool associated to a load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "b40755de-e8a5-4170-816f-ed30a83b287d",
  "eventName": "ModifyIpPools",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5fae1f9a-a16a-438f-b3cf-001ccf246e4a",
  "requestParameters": {
    "loadBalancerArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyListenerAttributes

#
Service
elasticloadbalancing

Description

Modifies the specified attributes of the specified listener.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
  "eventCategory": "Management",
  "eventID": "9c1ac239-575a-4a92-bac1-d5f85e3aff11",
  "eventName": "ModifyListenerAttributes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d5fb2d21-8dbf-4634-8825-46b8612da1ff",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyLoadBalancerAttributes

#
Service
elasticloadbalancing

Description

Modifies the attributes of the specified load balancer.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
  "eventCategory": "Management",
  "eventID": "36e2edbc-4032-4d22-a140-1768d18f161a",
  "eventName": "ModifyLoadBalancerAttributes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e68954f1-89cf-42ae-88f5-85137d27639b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyRule

#
Service
elasticloadbalancing

Description

Replaces the specified properties of the specified rule.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' is not a valid listener rule ARN",
  "eventCategory": "Management",
  "eventID": "1d7452f8-1630-461c-b2c0-2df13bd4b7af",
  "eventName": "ModifyRule",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1f1e22b9-9c16-496a-b9e7-9ee5b88486ee",
  "requestParameters": {
    "ruleArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTargetGroup

#
Service
elasticloadbalancing

Description

Modifies the health checks used when evaluating the health state of the targets in the specified target group.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "bca3fe5d-c52a-4c37-be2b-1f012f26859f",
  "eventName": "ModifyTargetGroup",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dcbcfe2d-85e9-4be7-9737-7e8ba7cab092",
  "requestParameters": {
    "targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTargetGroupAttributes

#
Service
elasticloadbalancing

Description

Modifies the specified attributes of the specified target group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
  "eventCategory": "Management",
  "eventID": "f2403b28-1b09-4187-a28a-e050e0695ad3",
  "eventName": "ModifyTargetGroupAttributes",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2ed10d33-7fce-4032-bf08-692066a60d85",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTrustStore

#
Service
elasticloadbalancing

Description

Update the ca certificate bundle for the specified trust store.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "cbc28fdb-1c16-44ae-8057-d17745cadcb9",
  "eventName": "ModifyTrustStore",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7eeeca8c-e930-48e2-9dc0-1a6f674d0f66",
  "requestParameters": {
    "caCertificatesBundleS3Bucket": "dw-probe",
    "caCertificatesBundleS3Key": "dw-probe",
    "trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RegisterInstancesWithLoadBalancer

#
Service
elasticloadbalancing

Description

Adds the specified instances to the specified load balancer.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bd78bbf1-d444-4b34-9f8d-d5f28248d1df",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventName": "RegisterInstancesWithLoadBalancer",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "2012-06-01",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "d3581b5f-63e1-484a-857a-38e160b43a69",
  "userAgent": "eks.amazonaws.com"
}

RegisterTargets

#
Service
elasticloadbalancing

Description

Registers the specified targets with the specified target group.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b29da1b7-ddfa-41e1-9dcb-4bf3c1a5b0bc",
  "eventName": "RegisterTargets",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "251e6a29-e2a8-4c8f-aade-fbbf2065ed45",
  "requestParameters": {
    "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
    "targets": [
      {
        "id": "172.31.0.10",
        "port": 80
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveListenerCertificates

#
Service
elasticloadbalancing

Description

Removes the specified certificate from the certificate list for the specified HTTPS or TLS listener.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
  "eventCategory": "Management",
  "eventID": "bdc6405d-89d2-43f3-9d69-140d97f7e322",
  "eventName": "RemoveListenerCertificates",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "66318278-8c2b-48a2-88e8-6c8b351c65e3",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveTags

#
Service
elasticloadbalancing

Description

Removes one or more tags from the specified load balancer.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
  "eventCategory": "Management",
  "eventID": "02d79bf9-2a6a-43fd-aceb-a7b428e0f0cc",
  "eventName": "RemoveTags",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "430ee59b-87d6-4b17-b5bb-036224207e96",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveTrustStoreRevocations

#
Service
elasticloadbalancing

Description

Removes the specified revocation file from the specified trust store.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
  "eventCategory": "Management",
  "eventID": "7ccf25c6-735b-4265-aa94-c03f566fc7c7",
  "eventName": "RemoveTrustStoreRevocations",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T19:23:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e069c86b-9a7d-44fa-8d42-4d3c9f20efc6",
  "requestParameters": {
    "revocationIds": [
      1
    ],
    "trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SetIpAddressType

#
Service
elasticloadbalancing

Description

Sets the type of IP addresses used by the subnets of the specified load balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "You must specify subnets with an associated IPv6 CIDR block.",
  "eventCategory": "Management",
  "eventID": "c5aaf152-779d-425b-85fc-36d5515ec4f3",
  "eventName": "SetIpAddressType",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b9345147-5282-4031-b806-87b8e5e86ae8",
  "requestParameters": {
    "ipAddressType": "dualstack",
    "loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SetLoadBalancerListenerSSLCertificate

#
Service
elasticloadbalancing

Description

Sets the certificate that terminates the specified listener's SSL connections.

SetLoadBalancerPoliciesForBackendServer

#
Service
elasticloadbalancing

Description

Replaces the set of policies associated with the specified port on which the EC2 instance is listening with a new set of policies.

SetLoadBalancerPoliciesOfListener

#
Service
elasticloadbalancing

Description

Replaces the current set of policies for the specified load balancer port with the specified set of policies.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4fe2271b-44a0-4a30-be44-4b0d97fdf565",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventName": "SetLoadBalancerPoliciesOfListener",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "apiVersion": "2012-06-01",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "972365f5-bfb2-4487-9fb9-752c4794bfd9",
  "userAgent": "eks.amazonaws.com"
}

SetRulePriorities

#
Service
elasticloadbalancing

Description

Sets the priorities of the specified rules.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e1c81136-f9a2-4b70-82a8-967f416ccccb",
  "eventName": "SetRulePriorities",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ce3c1409-cee0-4830-8694-ed4e996c4ac3",
  "requestParameters": {
    "rulePriorities": [
      {
        "priority": 20,
        "ruleArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener-rule/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e/bf31981153a4c38e"
      }
    ]
  },
  "responseElements": {
    "rules": [
      {
        "actions": [
          {
            "forwardConfig": {
              "targetGroupStickinessConfig": {
                "enabled": false
              },
              "targetGroups": [
                {
                  "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
                  "weight": 1
                }
              ]
            },
            "targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
            "type": "forward"
          }
        ],
        "conditions": [
          {
            "field": "path-pattern",
            "pathPatternConfig": {
              "values": [
                "/dwfix/*"
              ]
            },
            "values": [
              "/dwfix/*"
            ]
          }
        ],
        "isDefault": false,
        "priority": "20",
        "ruleArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener-rule/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e/bf31981153a4c38e"
      }
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SetSubnets

#
Service
elasticloadbalancing

Description

Enables the Availability Zones for the specified public subnets for the specified Application Load Balancer, Network Load Balancer or Gateway Load Balancer.

Example CloudTrail Event #

{
  "apiVersion": "2015-12-01",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ebe18556-27a0-48a5-83dd-c1b7f2ddc9bd",
  "eventName": "SetSubnets",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventTime": "2026-06-29T21:12:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4d4408d1-7502-46d4-956b-563d0dafe598",
  "requestParameters": {
    "loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
    "subnets": [
      "subnet-0c9f719882f5c95ae",
      "subnet-04caa2ba1250f8fb6"
    ]
  },
  "responseElements": {
    "availabilityZones": [
      {
        "loadBalancerAddresses": [],
        "subnetId": "subnet-0c9f719882f5c95ae",
        "zoneName": "us-west-1a"
      },
      {
        "loadBalancerAddresses": [],
        "subnetId": "subnet-04caa2ba1250f8fb6",
        "zoneName": "us-west-1c"
      }
    ],
    "ipAddressType": "ipv4"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeWebACLAssociation

#
Service
elasticloadbalancing

Description

DescribeWebACLAssociation recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e53b97b3-74a9-445d-af5b-c11ee61b4901",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventName": "DescribeWebACLAssociation",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "2015-12-01",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bf2cb23b-6c36-4aef-99f4-5757eb5b4733",
  "userAgent": "wafv2.amazonaws.com"
}

GetLoadBalancerWebACL

#
Service
elasticloadbalancing

Description

GetLoadBalancerWebACL recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "157e32b9-0af7-469c-b6b9-0a5fb2843671",
  "eventSource": "elasticloadbalancing.amazonaws.com",
  "eventName": "GetLoadBalancerWebACL",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "2015-12-01",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "9dd815b3-cca6-449c-acee-5654191cb954",
  "userAgent": "wafv2.amazonaws.com"
}