Elastic Load Balancing
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Elastic Load Balancing rules that match the service but not a specific eventName. | N | N |
| Apply | Associates one or more security groups with a Classic Load Balancer, controlling which traffic is allowed to reach the load balancer. | Y | Y |
| Create | Creates a listener for an Application or Network Load Balancer, defining the protocol, port, and default routing actions. | Y | N |
| Modify | Modifies the attributes of a listener, including certificates, default actions, protocol, or port. | Y | Y |
| Set | Replaces the security groups associated with an Application or Network Load Balancer with a new set of security groups. | Y | Y |
| Add | Adds the specified SSL server certificate to the certificate list for the specified HTTPS or TLS listener. | N | N |
| Add | Adds the specified tags to the specified load balancer. | Y | N |
| Add | Adds the specified revocation file to the specified trust store. | N | N |
| Attach | Adds one or more subnets to the set of configured subnets for the specified load balancer. | N | N |
| Configure | Specifies the health check settings to use when evaluating the health state of your EC2 instances. | N | N |
| Create | Generates a stickiness policy with sticky session lifetimes that follow that of an application-generated cookie. | N | N |
| Create | Generates a stickiness policy with sticky session lifetimes controlled by the lifetime of the browser (user-agent) or a specified expiration period. | N | N |
| Create | Creates a Classic Load Balancer. | Y | N |
| Create | Creates one or more listeners for the specified load balancer. | N | N |
| Create | Creates a policy with the specified attributes for the specified load balancer. | N | N |
| Create | Creates a rule for the specified listener. | Y | N |
| Create | Creates a target group. | Y | N |
| Create | Creates a trust store. | N | N |
| Delete | Deletes the specified listener. | Y | N |
| Delete | Deletes the specified load balancer. | Y | N |
| Delete | Deletes the specified listeners from the specified load balancer. | Y | N |
| Delete | Deletes the specified policy from the specified load balancer. | Y | N |
| Delete | Deletes the specified rule. | Y | N |
| Delete | Deletes a shared trust store association. | Y | N |
| Delete | Deletes the specified target group. | Y | N |
| Delete | Deletes a trust store. | Y | N |
| Deregister | Deregisters the specified instances from the specified load balancer. | Y | N |
| Deregister | Deregisters the specified targets from the specified target group. | Y | N |
| Describe | Describes the current Elastic Load Balancing resource limits for your AWS account. | Y | N |
| Describe | Describes the capacity reservation status for the specified load balancer. | Y | N |
| Describe | Describes the state of the specified instances with respect to the specified load balancer. | Y | N |
| Describe | Describes the attributes for the specified listener. | Y | N |
| Describe | Describes the default certificate and the certificate list for the specified HTTPS or TLS listener. | Y | N |
| Describe | Describes the specified listeners or the listeners for the specified Application Load Balancer, Network Load Balancer, or Gateway Load Balancer. | Y | N |
| Describe | Describes the attributes for the specified load balancer. | Y | N |
| Describe | Describes the specified policies. | Y | N |
| Describe | Describes the specified load balancer policy types or all load balancer policy types. | Y | N |
| Describe | Describes the specified the load balancers. | Y | N |
| Describe | Describes the specified rules or the rules for the specified listener. | Y | N |
| Describe | Describes the specified policies or all policies used for SSL negotiation. | Y | N |
| Describe | Describes the tags associated with the specified load balancers. | Y | N |
| Describe | Describes the attributes for the specified target group. | Y | N |
| Describe | Describes the specified target groups or all of your target groups. | Y | N |
| Describe | Describes the health of the specified targets or all of your targets. | N | N |
| Describe | Describes all resources associated with the specified trust store. | Y | N |
| Describe | Describes the revocation files in use by the specified trust store or revocation files. | Y | N |
| Describe | Describes all trust stores for the specified account. | Y | N |
| Detach | Removes the specified subnets from the set of configured subnets for the load balancer. | Y | N |
| Disable | Removes the specified Availability Zones from the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC. | Y | N |
| Enable | Adds the specified Availability Zones to the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC. | N | N |
| Get | Retrieves the resource policy for a specified resource. | Y | N |
| Get | Retrieves the ca certificate bundle. | Y | N |
| Get | Retrieves the specified revocation file. | Y | N |
| Modify | Modifies the capacity reservation of the specified load balancer. | Y | N |
| Modify | [Application Load Balancers] Modify the IP pool associated to a load balancer. | Y | N |
| Modify | Modifies the specified attributes of the specified listener. | Y | N |
| Modify | Modifies the attributes of the specified load balancer. | Y | N |
| Modify | Replaces the specified properties of the specified rule. | Y | N |
| Modify | Modifies the health checks used when evaluating the health state of the targets in the specified target group. | Y | N |
| Modify | Modifies the specified attributes of the specified target group. | Y | N |
| Modify | Update the ca certificate bundle for the specified trust store. | Y | N |
| Register | Adds the specified instances to the specified load balancer. | N | N |
| Register | Registers the specified targets with the specified target group. | Y | N |
| Remove | Removes the specified certificate from the certificate list for the specified HTTPS or TLS listener. | Y | N |
| Remove | Removes one or more tags from the specified load balancer. | Y | N |
| Remove | Removes the specified revocation file from the specified trust store. | Y | N |
| Set | Sets the type of IP addresses used by the subnets of the specified load balancer. | Y | N |
| Set | Sets the certificate that terminates the specified listener's SSL connections. | N | N |
| Set | Replaces the set of policies associated with the specified port on which the EC2 instance is listening with a new set of policies. | N | N |
| Set | Replaces the current set of policies for the specified load balancer port with the specified set of policies. | N | N |
| Set | Sets the priorities of the specified rules. | Y | N |
| Set | Enables the Availability Zones for the specified public subnets for the specified Application Load Balancer, Network Load Balancer or Gateway Load Balancer. | Y | N |
| Describe | DescribeWebACLAssociation recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetLoadBalancerWebACL recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
any: Elastic Load Balancing (catch-all)
#Description
Catch-all entry for Elastic Load Balancing rules that match the service but not a specific eventName.
ApplySecurityGroupsToLoadBalancer
#Description
Associates one or more security groups with a Classic Load Balancer, controlling which traffic is allowed to reach the load balancer.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:16Z",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventName": "ApplySecurityGroupsToLoadBalancer",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#elb.apply-security-groups-to-load-balancer",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-harn-elb-eb7866'",
"requestParameters": {
"loadBalancerName": "dw-harn-elb-eb7866",
"securityGroups": [
"sg-00000000000000000"
]
},
"responseElements": null,
"requestID": "cd7c77a1-99b4-4dcb-8331-de3192bc11a7",
"eventID": "19c400be-5d67-4d3b-937f-a0fd8ea8d43f",
"readOnly": false,
"eventType": "AwsApiCall",
"apiVersion": "2012-06-01",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1190↳ also matches SetSecurityGroups Kusto #
T1562, T1562.007↳ also matches SetSecurityGroups
CreateListener
#Description
Creates a listener for an Application or Network Load Balancer, defining the protocol, port, and default routing actions.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d5947dd5-efb1-4c40-9bbf-7f2d31774abf",
"eventName": "CreateListener",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a9742afd-937e-405a-aa8d-0cf67cbe7b0a",
"requestParameters": {
"defaultActions": [
{
"fixedResponseConfig": {
"contentType": "text/plain",
"messageBody": "dwfix-ok",
"statusCode": "200"
},
"type": "fixed-response"
}
],
"loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
"port": 80,
"protocol": "HTTP",
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"responseElements": {
"listeners": [
{
"defaultActions": [
{
"fixedResponseConfig": {
"contentType": "text/plain",
"messageBody": "dwfix-ok",
"statusCode": "200"
},
"type": "fixed-response"
}
],
"listenerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e",
"loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
"port": 80,
"protocol": "HTTP"
}
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyListener
#Description
Modifies the attributes of a listener, including certificates, default actions, protocol, or port.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "51d5ecff-3d7e-4369-87a1-af1ca6580c3d",
"eventName": "ModifyListener",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "68182055-dfb3-413d-a36c-62bd614c97f8",
"requestParameters": {
"listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1600
SetSecurityGroups
#Description
Replaces the security groups associated with an Application or Network Load Balancer with a new set of security groups.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4726a0cf-e3c1-4060-a8d1-f20c21aad2c6",
"eventName": "SetSecurityGroups",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "64e9e572-c6a0-46bf-af57-609de730b137",
"requestParameters": {
"loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
"securityGroups": [
"sg-063fc1a8302bc48a4"
]
},
"responseElements": {
"securityGroupIds": [
"sg-063fc1a8302bc48a4"
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1190↳ also matches ApplySecurityGroupsToLoadBalancer Kusto #
T1562, T1562.007↳ also matches ApplySecurityGroupsToLoadBalancer
AddListenerCertificates
#Description
Adds the specified SSL server certificate to the certificate list for the specified HTTPS or TLS listener.
AddTrustStoreRevocations
#Description
Adds the specified revocation file to the specified trust store.
AttachLoadBalancerToSubnets
#Description
Adds one or more subnets to the set of configured subnets for the specified load balancer.
ConfigureHealthCheck
#Description
Specifies the health check settings to use when evaluating the health state of your EC2 instances.
CreateLoadBalancer
#Description
Creates a Classic Load Balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4234414a-d796-4a09-b832-4d8069466b57",
"eventName": "CreateLoadBalancer",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:10:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "299c081d-f518-47a8-a257-ee0a947ae7f1",
"requestParameters": {
"ipAddressType": "ipv4",
"name": "dwfix-elb-ct",
"scheme": "internet-facing",
"securityGroups": [
"sg-063fc1a8302bc48a4"
],
"subnets": [
"subnet-0c9f719882f5c95ae",
"subnet-04caa2ba1250f8fb6"
],
"tags": [
{
"key": "dwfix",
"value": "true"
},
{
"key": "Purpose",
"value": "sample-collection"
}
],
"type": "application"
},
"responseElements": {
"loadBalancers": [
{
"availabilityZones": [
{
"loadBalancerAddresses": [],
"subnetId": "subnet-0c9f719882f5c95ae",
"zoneName": "us-west-1a"
},
{
"loadBalancerAddresses": [],
"subnetId": "subnet-04caa2ba1250f8fb6",
"zoneName": "us-west-1c"
}
],
"canonicalHostedZoneId": "Z368ELLRRE2KJ0",
"createdTime": "Jun 29, 2026, 9:10:12 PM",
"dNSName": "dwfix-elb-ct-1819491149.us-west-1.elb.amazonaws.com",
"ipAddressType": "ipv4",
"loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
"loadBalancerName": "dwfix-elb-ct",
"scheme": "internet-facing",
"securityGroups": [
"sg-063fc1a8302bc48a4"
],
"state": {
"code": "provisioning"
},
"type": "application",
"vpcId": "vpc-0cf63cfb072f7d61f"
}
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateLoadBalancerListeners
#Description
Creates one or more listeners for the specified load balancer.
CreateLoadBalancerPolicy
#Description
Creates a policy with the specified attributes for the specified load balancer.
CreateRule
#Description
Creates a rule for the specified listener.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "63719f30-5a8e-4762-9475-83ab9d06c089",
"eventName": "CreateRule",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2421d1db-aa27-40cc-81d3-4a3afa2ccf4e",
"requestParameters": {
"actions": [
{
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"type": "forward"
}
],
"conditions": [
{
"field": "path-pattern",
"pathPatternConfig": {
"values": [
"/dwfix/*"
]
}
}
],
"listenerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e",
"priority": 10,
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"responseElements": {
"rules": [
{
"actions": [
{
"forwardConfig": {
"targetGroupStickinessConfig": {
"enabled": false
},
"targetGroups": [
{
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"weight": 1
}
]
},
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"type": "forward"
}
],
"conditions": [
{
"field": "path-pattern",
"pathPatternConfig": {
"values": [
"/dwfix/*"
]
},
"values": [
"/dwfix/*"
]
}
],
"isDefault": false,
"priority": "10",
"ruleArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener-rule/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e/bf31981153a4c38e",
"transforms": []
}
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTargetGroup
#Description
Creates a target group.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d4cbca58-3cba-45ca-b826-e119f4e23511",
"eventName": "CreateTargetGroup",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:10:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5f92324b-9d42-4ba8-9bc1-ec276028cf7e",
"requestParameters": {
"healthCheckEnabled": true,
"healthCheckIntervalSeconds": 30,
"healthCheckPath": "/health",
"healthCheckProtocol": "HTTP",
"healthCheckTimeoutSeconds": 5,
"healthyThresholdCount": 2,
"name": "dwfix-tg-ct",
"port": 80,
"protocol": "HTTP",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"targetType": "ip",
"unhealthyThresholdCount": 3,
"vpcId": "vpc-0cf63cfb072f7d61f"
},
"responseElements": {
"targetGroups": [
{
"healthCheckEnabled": true,
"healthCheckIntervalSeconds": 30,
"healthCheckPath": "/health",
"healthCheckPort": "traffic-port",
"healthCheckProtocol": "HTTP",
"healthCheckTimeoutSeconds": 5,
"healthyThresholdCount": 2,
"ipAddressType": "ipv4",
"matcher": {
"httpCode": "200"
},
"port": 80,
"protocol": "HTTP",
"protocolVersion": "HTTP1",
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"targetGroupName": "dwfix-tg-ct",
"targetType": "ip",
"unhealthyThresholdCount": 3,
"vpcId": "vpc-0cf63cfb072f7d61f"
}
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTrustStore
#Description
Creates a trust store.
DeleteListener
#Description
Deletes the specified listener.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "18e0e4bc-5250-4543-b79e-b7c7d26c47d7",
"eventName": "DeleteListener",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f4932e45-36e8-4bee-b546-7f67df1d5b75",
"requestParameters": {
"listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLoadBalancer
#Description
Deletes the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f74f165c-7097-4521-9d11-7418b6e86b02",
"eventName": "DeleteLoadBalancer",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "09cb0a1a-c6fb-493a-88fa-e218e5ac7b3c",
"requestParameters": {
"loadBalancerName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLoadBalancerListeners
#Description
Deletes the specified listeners from the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
"eventCategory": "Management",
"eventID": "ce60cc87-a9af-4852-b523-d1dcf98745cd",
"eventName": "DeleteLoadBalancerListeners",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "83313971-07a7-4073-a017-0d92c99668ee",
"requestParameters": {
"loadBalancerName": "dw-probe",
"loadBalancerPorts": [
1
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLoadBalancerPolicy
#Description
Deletes the specified policy from the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
"eventCategory": "Management",
"eventID": "8d1e64d1-794b-4550-9222-b492a7ef67e7",
"eventName": "DeleteLoadBalancerPolicy",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "10935fd3-0127-4186-92a4-8d2e2160d45a",
"requestParameters": {
"loadBalancerName": "dw-probe",
"policyName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRule
#Description
Deletes the specified rule.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' is not a valid listener rule ARN",
"eventCategory": "Management",
"eventID": "7a518cbb-048b-4f22-85cf-6d1e6809cd42",
"eventName": "DeleteRule",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "00e6a46f-95bc-4f95-aa9c-30d5a10b471f",
"requestParameters": {
"ruleArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTargetGroup
#Description
Deletes the specified target group.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "e13de03d-5f84-46d1-9ce3-148f5c97ba91",
"eventName": "DeleteTargetGroup",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d24064ba-9587-429a-b9d2-272f310de1b5",
"requestParameters": {
"targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTrustStore
#Description
Deletes a trust store.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "7598db67-dc96-42dc-8460-57b5b0d0b27d",
"eventName": "DeleteTrustStore",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ebf83d8f-da01-4d8e-9b55-a856446dd16c",
"requestParameters": {
"trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterInstancesFromLoadBalancer
#Description
Deregisters the specified instances from the specified load balancer.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
"eventCategory": "Management",
"eventID": "4e70e0af-8136-4ef3-b63c-8aee4ef9a1e0",
"eventName": "DeregisterInstancesFromLoadBalancer",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "db3e155c-2ad8-4b9a-88b6-d43dbdb591dd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterTargets
#Description
Deregisters the specified targets from the specified target group.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "ed5094dd-99bd-4b7d-b3a7-a3a63db9fe00",
"eventName": "DeregisterTargets",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5da57148-4e66-4ca0-9d6e-680ca6131569",
"requestParameters": {
"targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe",
"targets": [
{
"id": "dw-probe"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAccountLimits
#Description
Describes the current Elastic Load Balancing resource limits for your AWS account.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-east-1",
"eventID": "5ed179b2-36a9-4717-9d43-239539b311ce1",
"eventName": "DescribeAccountLimits",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2018-10-17T20:03:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "c24b0edd-d247-11e8-81b0-73efac09c3e4",
"requestParameters": null,
"responseElements": {
"limits": [
{
"max": "20",
"name": "classic-load-balancers"
},
{
"max": "100",
"name": "classic-listeners"
},
{
"max": "1000",
"name": "classic-registered-instances"
}
]
},
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeCapacityReservation
#Description
Describes the capacity reservation status for the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "1be9962e-441f-472d-b6b6-295e00ba6c64",
"eventName": "DescribeCapacityReservation",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ba3348f6-c78b-4bfd-9be5-c46e2c932377",
"requestParameters": {
"loadBalancerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceHealth
#Description
Describes the state of the specified instances with respect to the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
"eventCategory": "Management",
"eventID": "ea1fbc52-fd54-4a3e-94f3-60eac43ed985",
"eventName": "DescribeInstanceHealth",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "077442ad-3d95-4b02-afdb-a72e770f02a2",
"requestParameters": {
"loadBalancerName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeListenerAttributes
#Description
Describes the attributes for the specified listener.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "efbe8afa-f185-4ac8-b8d2-1eb4e417789b",
"eventName": "DescribeListenerAttributes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "64fa9b06-f30f-4ef8-922d-ed611ba0bd22",
"requestParameters": {
"listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeListenerCertificates
#Description
Describes the default certificate and the certificate list for the specified HTTPS or TLS listener.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' is not a valid listener ARN",
"eventCategory": "Management",
"eventID": "a988b33e-47e6-4ec0-a8c5-4abd9512ed5c",
"eventName": "DescribeListenerCertificates",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "329068ce-b1a2-44c3-809f-668d2ba5adcb",
"requestParameters": {
"listenerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeListeners
#Description
Describes the specified listeners or the listeners for the specified Application Load Balancer, Network Load Balancer, or Gateway Load Balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "You must specify either either listener ARNs or a load balancer ARN",
"eventID": "51441b9-901b-4b86-9caa-74bee6ad44f5",
"eventName": "DescribeListeners",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2018-10-21T16:26:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "153567c-d54e-11e8-8672-a75fe701a20e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Boto3/1.7.4 Python/3.6.6 Linux/4.16.0-kali2-amd64 Botocore/1.10.4",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeLoadBalancerAttributes
#Description
Describes the attributes for the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
"eventCategory": "Management",
"eventID": "02c4149a-117e-459b-9ae4-97d58a1913fa",
"eventName": "DescribeLoadBalancerAttributes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "993e9321-6e6d-4cb0-939b-d44bc9b7090b",
"requestParameters": {
"loadBalancerName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeLoadBalancerPolicies
#Description
Describes the specified policies.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "ap-south-1",
"eventID": "55808b8-5fa8-4a26-bb6c-7db19382dcf8",
"eventName": "DescribeLoadBalancerPolicies",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2018-08-05T17:02:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "5e1018d8-98d1-11e8-b4ed-543058db633b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "250.251.253.3",
"userAgent": "Boto3/1.5.32 Python/3.6.4 Darwin/17.6.0 Botocore/1.8.50",
"userIdentity": {
"accessKeyId": "ASIAPYBUDZE3ZQU169GB",
"accountId": "811596193553",
"arn": "arn:aws:sts::811596193553:assumed-role/SummitRouteAudit/4032461535040776536",
"principalId": "AROAMY611GPC0EPB1P0F9:4032461535040776536",
"sessionContext": {
"attributes": {
"creationDate": "2018-08-05T17:00:49Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:role/SummitRouteAudit",
"principalId": "AROAMY611GPC0EPB1P0F9",
"type": "Role",
"userName": "SummitRouteAudit"
}
},
"type": "AssumedRole"
}
}
References #
DescribeLoadBalancerPolicyTypes
#Description
Describes the specified load balancer policy types or all load balancer policy types.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-east-1",
"eventID": "55f64e05-3ea1-435d-8e9d-ba1c382b6e6c",
"eventName": "DescribeLoadBalancerPolicyTypes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2018-10-17T20:03:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "c263c721-d247-11e8-81b0-73efac09c3e4",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeLoadBalancers
#Description
Describes the specified the load balancers.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "e3bb4364-d0ca-4c0f-a194-b3af5d5280b3",
"eventName": "DescribeLoadBalancers",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "bec55cd2-46d8-4e98-adf6-c8fe209ec48a",
"requestParameters": {
"pageSize": 200
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeRules
#Description
Describes the specified rules or the rules for the specified listener.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "You must specify either listener rule ARNs or a listener ARN",
"eventID": "fb7164ba-3cab-4b57-878b-b791c88628d9",
"eventName": "DescribeRules",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2018-10-17T20:23:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "8b8cbfd8-d24a-11e8-ad05-8f41c543bc94",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeSSLPolicies
#Description
Describes the specified policies or all policies used for SSL negotiation.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "ap-northeast-1",
"eventID": "33db55cc-c408-4207-93bf-efbb48dcf7cc",
"eventName": "DescribeSSLPolicies",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2018-01-18T20:33:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "d1299bd5-fc8e-11e7-b3e8-13d2f20a35ba",
"requestParameters": {
"names": []
},
"responseElements": {
"sslPolicies": [
{
"ciphers": [
{
"name": "ECDHE-ECDSA-AES128-GCM-SHA256",
"priority": 1
},
{
"name": "ECDHE-RSA-AES128-GCM-SHA256",
"priority": 2
},
{
"name": "ECDHE-ECDSA-AES128-SHA256",
"priority": 3
},
{
"name": "ECDHE-RSA-AES128-SHA256",
"priority": 4
},
{
"name": "ECDHE-ECDSA-AES128-SHA",
"priority": 5
},
{
"name": "ECDHE-RSA-AES128-SHA",
"priority": 6
},
{
"name": "ECDHE-ECDSA-AES256-GCM-SHA384",
"priority": 7
},
{
"name": "ECDHE-RSA-AES256-GCM-SHA384",
"priority": 8
},
{
"name": "ECDHE-ECDSA-AES256-SHA384",
"priority": 9
},
{
"name": "ECDHE-RSA-AES256-SHA384",
"priority": 10
},
{
"name": "ECDHE-RSA-AES256-SHA",
"priority": 11
},
{
"name": "ECDHE-ECDSA-AES256-SHA",
"priority": 12
},
{
"name": "AES128-GCM-SHA256",
"priority": 13
},
{
"name": "AES128-SHA256",
"priority": 14
},
{
"name": "AES128-SHA",
"priority": 15
},
{
"name": "AES256-GCM-SHA384",
"priority": 16
},
{
"name": "AES256-SHA256",
"priority": 17
},
{
"name": "AES256-SHA",
"priority": 18
}
],
"name": "ELBSecurityPolicy-2016-08",
"sslProtocols": [
"TLSv1",
"TLSv1.1",
"TLSv1.2"
]
},
{
"ciphers": [
{
"name": "ECDHE-ECDSA-AES128-GCM-SHA256",
"priority": 1
},
{
"name": "ECDHE-RSA-AES128-GCM-SHA256",
"priority": 2
},
{
"name": "ECDHE-ECDSA-AES128-SHA256",
"priority": 3
},
{
"name": "ECDHE-RSA-AES128-SHA256",
"priority": 4
},
{
"name": "ECDHE-ECDSA-AES256-GCM-SHA384",
"priority": 5
},
{
"name": "ECDHE-RSA-AES256-GCM-SHA384",
"priority": 6
},
{
"name": "ECDHE-ECDSA-AES256-SHA384",
"priority": 7
},
{
"name": "ECDHE-RSA-AES256-SHA384",
"priority": 8
},
{
"name": "AES128-GCM-SHA256",
"priority": 9
},
{
"name": "AES128-SHA256",
"priority": 10
},
{
"name": "AES256-GCM-SHA384",
"priority": 11
},
{
"name": "AES256-SHA256",
"priority": 12
}
],
"name": "ELBSecurityPolicy-TLS-1-2-2017-01",
"sslProtocols": [
"TLSv1.2"
]
},
{
"ciphers": [
{
"name": "ECDHE-ECDSA-AES128-GCM-SHA256",
"priority": 1
},
{
"name": "ECDHE-RSA-AES128-GCM-SHA256",
"priority": 2
},
{
"name": "ECDHE-ECDSA-AES128-SHA256",
"priority": 3
},
{
"name": "ECDHE-RSA-AES128-SHA256",
"priority": 4
},
{
"name": "ECDHE-ECDSA-AES128-SHA",
"priority": 5
},
{
"name": "ECDHE-RSA-AES128-SHA",
"priority": 6
},
{
"name": "ECDHE-ECDSA-AES256-GCM-SHA384",
"priority": 7
},
{
"name": "ECDHE-RSA-AES256-GCM-SHA384",
"priority": 8
},
{
"name": "ECDHE-ECDSA-AES256-SHA384",
"priority": 9
},
{
"name": "ECDHE-RSA-AES256-SHA384",
"priority": 10
},
{
"name": "ECDHE-RSA-AES256-SHA",
"priority": 11
},
{
"name": "ECDHE-ECDSA-AES256-SHA",
"priority": 12
},
{
"name": "AES128-GCM-SHA256",
"priority": 13
},
{
"name": "AES128-SHA256",
"priority": 14
},
{
"name": "AES128-SHA",
"priority": 15
},
{
"name": "AES256-GCM-SHA384",
"priority": 16
},
{
"name": "AES256-SHA256",
"priority": 17
},
{
"name": "AES256-SHA",
"priority": 18
}
],
"name": "ELBSecurityPolicy-TLS-1-1-2017-01",
"sslProtocols": [
"TLSv1.1",
"TLSv1.2"
]
},
{
"ciphers": [
{
"name": "ECDHE-ECDSA-AES128-GCM-SHA256",
"priority": 1
},
{
"name": "ECDHE-RSA-AES128-GCM-SHA256",
"priority": 2
},
{
"name": "ECDHE-ECDSA-AES128-SHA256",
"priority": 3
},
{
"name": "ECDHE-RSA-AES128-SHA256",
"priority": 4
},
{
"name": "ECDHE-ECDSA-AES128-SHA",
"priority": 5
},
{
"name": "ECDHE-RSA-AES128-SHA",
"priority": 6
},
{
"name": "ECDHE-ECDSA-AES256-GCM-SHA384",
"priority": 7
},
{
"name": "ECDHE-RSA-AES256-GCM-SHA384",
"priority": 8
},
{
"name": "ECDHE-ECDSA-AES256-SHA384",
"priority": 9
},
{
"name": "ECDHE-RSA-AES256-SHA384",
"priority": 10
},
{
"name": "ECDHE-RSA-AES256-SHA",
"priority": 11
},
{
"name": "ECDHE-ECDSA-AES256-SHA",
"priority": 12
},
{
"name": "AES128-GCM-SHA256",
"priority": 13
},
{
"name": "AES128-SHA256",
"priority": 14
},
{
"name": "AES128-SHA",
"priority": 15
},
{
"name": "AES256-GCM-SHA384",
"priority": 16
},
{
"name": "AES256-SHA256",
"priority": 17
},
{
"name": "AES256-SHA",
"priority": 18
}
],
"name": "ELBSecurityPolicy-2015-05",
"sslProtocols": [
"TLSv1",
"TLSv1.1",
"TLSv1.2"
]
},
{
"ciphers": [
{
"name": "ECDHE-ECDSA-AES128-GCM-SHA256",
"priority": 1
},
{
"name": "ECDHE-RSA-AES128-GCM-SHA256",
"priority": 2
},
{
"name": "ECDHE-ECDSA-AES128-SHA256",
"priority": 3
},
{
"name": "ECDHE-RSA-AES128-SHA256",
"priority": 4
},
{
"name": "ECDHE-ECDSA-AES128-SHA",
"priority": 5
},
{
"name": "ECDHE-RSA-AES128-SHA",
"priority": 6
},
{
"name": "ECDHE-ECDSA-AES256-GCM-SHA384",
"priority": 7
},
{
"name": "ECDHE-RSA-AES256-GCM-SHA384",
"priority": 8
},
{
"name": "ECDHE-ECDSA-AES256-SHA384",
"priority": 9
},
{
"name": "ECDHE-RSA-AES256-SHA384",
"priority": 10
},
{
"name": "ECDHE-RSA-AES256-SHA",
"priority": 11
},
{
"name": "ECDHE-ECDSA-AES256-SHA",
"priority": 12
},
{
"name": "AES128-GCM-SHA256",
"priority": 13
},
{
"name": "AES128-SHA256",
"priority": 14
},
{
"name": "AES128-SHA",
"priority": 15
},
{
"name": "AES256-GCM-SHA384",
"priority": 16
},
{
"name": "AES256-SHA256",
"priority": 17
},
{
"name": "AES256-SHA",
"priority": 18
},
{
"name": "DES-CBC3-SHA",
"priority": 19
}
],
"name": "ELBSecurityPolicy-TLS-1-0-2015-04",
"sslProtocols": [
"TLSv1",
"TLSv1.1",
"TLSv1.2"
]
}
]
},
"sourceIPAddress": "250.253.254.5",
"userAgent": "Boto3/1.5.18 Python/3.6.1 Darwin/16.7.0 Botocore/1.8.32",
"userIdentity": {
"accessKeyId": "ASIAHP2ACUZ6KIJYE7JR",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"sessionContext": {
"attributes": {
"creationDate": "2018-01-18T20:29:52Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeTargetGroupAttributes
#Description
Describes the attributes for the specified target group.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "b9d1103f-7481-48e1-a97a-e8b054e1916b",
"eventName": "DescribeTargetGroupAttributes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "88ea1a0f-43f9-4c86-a304-c3d156fb4e28",
"requestParameters": {
"targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTargetGroups
#Description
Describes the specified target groups or all of your target groups.
Example CloudTrail Event #
{
"awsRegion": "ap-south-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::111111111111:user/cloudsploit is not authorized to perform: elasticloadbalancing:DescribeTargetGroups",
"eventCategory": "Management",
"eventID": "f58a0152-f2da-42f6-807b-4de082274a36",
"eventName": "DescribeTargetGroups",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2021-04-13T11:35:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "111111111111",
"requestID": "b971a811-614e-428d-9273-553de6464f65",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "95.90.195.80",
"userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
DescribeTargetHealth
#Description
Describes the health of the specified targets or all of your targets.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "287c9207-28bc-4e8e-ac69-ffbbf8bfa333",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventName": "DescribeTargetHealth",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2015-12-01",
"readOnly": true,
"managementEvent": true,
"requestID": "74f13232-10e8-45d0-be2f-dd1b58e021f5",
"userAgent": "ecs.amazonaws.com"
}
DescribeTrustStoreAssociations
#Description
Describes all resources associated with the specified trust store.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "1925c8b9-9b87-49a4-bc8e-a2e2e7391a55",
"eventName": "DescribeTrustStoreAssociations",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "97fb5b74-7a2f-4cbb-bf09-ce7954105a46",
"requestParameters": {
"trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTrustStoreRevocations
#Description
Describes the revocation files in use by the specified trust store or revocation files.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "8b6f0416-b90d-4eed-ba65-6d21b698ee0f",
"eventName": "DescribeTrustStoreRevocations",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "50d523c9-ac81-4234-946b-2d381fb2b61b",
"requestParameters": {
"trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTrustStores
#Description
Describes all trust stores for the specified account.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dc486195-11a7-4733-a786-965b0dd8861a",
"eventName": "DescribeTrustStores",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:31:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "699e96d8-8342-4989-b12c-9c6f6a9746c6",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DetachLoadBalancerFromSubnets
#Description
Removes the specified subnets from the set of configured subnets for the load balancer.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
"eventCategory": "Management",
"eventID": "958ce188-741e-456f-a21c-bbcc40a3c09d",
"eventName": "DetachLoadBalancerFromSubnets",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "804d6bc1-cc26-4588-9ec8-69052ef5be8b",
"requestParameters": {
"loadBalancerName": "dw-probe",
"subnets": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableAvailabilityZonesForLoadBalancer
#Description
Removes the specified Availability Zones from the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC.
Example CloudTrail Event #
{
"apiVersion": "2012-06-01",
"awsRegion": "us-west-1",
"errorCode": "AccessPointNotFoundException",
"errorMessage": "There is no ACTIVE Load Balancer named 'dw-probe'",
"eventCategory": "Management",
"eventID": "99cfc952-0936-4c38-aa16-67a020bb6a91",
"eventName": "DisableAvailabilityZonesForLoadBalancer",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8dc809c1-f260-4bb9-8c43-56acb62e7ce2",
"requestParameters": {
"availabilityZones": [
"dw-probe"
],
"loadBalancerName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableAvailabilityZonesForLoadBalancer
#Description
Adds the specified Availability Zones to the set of Availability Zones for the specified load balancer in EC2-Classic or a default VPC.
GetResourcePolicy
#Description
Retrieves the resource policy for a specified resource.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "7d7e1124-cc47-4de5-8067-d8c0018fd942",
"eventName": "GetResourcePolicy",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "10235ef3-b818-4616-8c24-8462894f2ba3",
"requestParameters": {
"resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTrustStoreCaCertificatesBundle
#Description
Retrieves the ca certificate bundle.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "7412b889-fb08-3843-9946-1aadb76788e5",
"eventName": "GetTrustStoreCaCertificatesBundle",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "114f86bd-b579-45d3-9dba-4cfab42dbc65",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:iam::123456789012:role/dw-probe",
"accountId": "HIDDEN_DUE_TO_SECURITY_REASONS",
"type": "AWS::ElasticLoadBalancingV2::TrustStore"
}
],
"responseElements": null,
"sharedEventID": "9eb40541-e9e2-4e86-a607-2f367999b1fb",
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTrustStoreRevocationContent
#Description
Retrieves the specified revocation file.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "c154504d-cedb-3521-bf4a-a23340f849da",
"eventName": "GetTrustStoreRevocationContent",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T18:43:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "dac8e53c-fc6a-4a12-a216-2c627fd71ce1",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:iam::123456789012:role/dw-probe",
"accountId": "HIDDEN_DUE_TO_SECURITY_REASONS",
"type": "AWS::ElasticLoadBalancingV2::TrustStore"
}
],
"responseElements": null,
"sharedEventID": "8c7693a5-12cb-4c69-9a9e-ed82717264a2",
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyCapacityReservation
#Description
Modifies the capacity reservation of the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "91677d0f-c0bc-4a84-8b37-bf7b1cdf30d0",
"eventName": "ModifyCapacityReservation",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6f39cbde-af1c-4d42-89b2-52fbb314fa88",
"requestParameters": {
"loadBalancerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpPools
#Description
[Application Load Balancers] Modify the IP pool associated to a load balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "b40755de-e8a5-4170-816f-ed30a83b287d",
"eventName": "ModifyIpPools",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5fae1f9a-a16a-438f-b3cf-001ccf246e4a",
"requestParameters": {
"loadBalancerArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyListenerAttributes
#Description
Modifies the specified attributes of the specified listener.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
"eventCategory": "Management",
"eventID": "9c1ac239-575a-4a92-bac1-d5f85e3aff11",
"eventName": "ModifyListenerAttributes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d5fb2d21-8dbf-4634-8825-46b8612da1ff",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyLoadBalancerAttributes
#Description
Modifies the attributes of the specified load balancer.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
"eventCategory": "Management",
"eventID": "36e2edbc-4032-4d22-a140-1768d18f161a",
"eventName": "ModifyLoadBalancerAttributes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e68954f1-89cf-42ae-88f5-85137d27639b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyRule
#Description
Replaces the specified properties of the specified rule.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' is not a valid listener rule ARN",
"eventCategory": "Management",
"eventID": "1d7452f8-1630-461c-b2c0-2df13bd4b7af",
"eventName": "ModifyRule",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1f1e22b9-9c16-496a-b9e7-9ee5b88486ee",
"requestParameters": {
"ruleArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTargetGroup
#Description
Modifies the health checks used when evaluating the health state of the targets in the specified target group.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "bca3fe5d-c52a-4c37-be2b-1f012f26859f",
"eventName": "ModifyTargetGroup",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dcbcfe2d-85e9-4be7-9737-7e8ba7cab092",
"requestParameters": {
"targetGroupArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTargetGroupAttributes
#Description
Modifies the specified attributes of the specified target group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
"eventCategory": "Management",
"eventID": "f2403b28-1b09-4187-a28a-e050e0695ad3",
"eventName": "ModifyTargetGroupAttributes",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2ed10d33-7fce-4032-bf08-692066a60d85",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTrustStore
#Description
Update the ca certificate bundle for the specified trust store.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "cbc28fdb-1c16-44ae-8057-d17745cadcb9",
"eventName": "ModifyTrustStore",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7eeeca8c-e930-48e2-9dc0-1a6f674d0f66",
"requestParameters": {
"caCertificatesBundleS3Bucket": "dw-probe",
"caCertificatesBundleS3Key": "dw-probe",
"trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RegisterInstancesWithLoadBalancer
#Description
Adds the specified instances to the specified load balancer.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "bd78bbf1-d444-4b34-9f8d-d5f28248d1df",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventName": "RegisterInstancesWithLoadBalancer",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2012-06-01",
"readOnly": false,
"managementEvent": true,
"requestID": "d3581b5f-63e1-484a-857a-38e160b43a69",
"userAgent": "eks.amazonaws.com"
}
RegisterTargets
#Description
Registers the specified targets with the specified target group.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b29da1b7-ddfa-41e1-9dcb-4bf3c1a5b0bc",
"eventName": "RegisterTargets",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "251e6a29-e2a8-4c8f-aade-fbbf2065ed45",
"requestParameters": {
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"targets": [
{
"id": "172.31.0.10",
"port": 80
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RemoveListenerCertificates
#Description
Removes the specified certificate from the certificate list for the specified HTTPS or TLS listener.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "HIDDEN_DUE_TO_SECURITY_REASONS",
"eventCategory": "Management",
"eventID": "bdc6405d-89d2-43f3-9d69-140d97f7e322",
"eventName": "RemoveListenerCertificates",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "66318278-8c2b-48a2-88e8-6c8b351c65e3",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RemoveTrustStoreRevocations
#Description
Removes the specified revocation file from the specified trust store.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "'arn:aws:iam::123456789012:role/dw-probe' must be in ARN format",
"eventCategory": "Management",
"eventID": "7ccf25c6-735b-4265-aa94-c03f566fc7c7",
"eventName": "RemoveTrustStoreRevocations",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T19:23:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e069c86b-9a7d-44fa-8d42-4d3c9f20efc6",
"requestParameters": {
"revocationIds": [
1
],
"trustStoreArn": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SetIpAddressType
#Description
Sets the type of IP addresses used by the subnets of the specified load balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "You must specify subnets with an associated IPv6 CIDR block.",
"eventCategory": "Management",
"eventID": "c5aaf152-779d-425b-85fc-36d5515ec4f3",
"eventName": "SetIpAddressType",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b9345147-5282-4031-b806-87b8e5e86ae8",
"requestParameters": {
"ipAddressType": "dualstack",
"loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SetLoadBalancerListenerSSLCertificate
#Description
Sets the certificate that terminates the specified listener's SSL connections.
SetLoadBalancerPoliciesForBackendServer
#Description
Replaces the set of policies associated with the specified port on which the EC2 instance is listening with a new set of policies.
SetLoadBalancerPoliciesOfListener
#Description
Replaces the current set of policies for the specified load balancer port with the specified set of policies.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4fe2271b-44a0-4a30-be44-4b0d97fdf565",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventName": "SetLoadBalancerPoliciesOfListener",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"apiVersion": "2012-06-01",
"readOnly": false,
"managementEvent": true,
"requestID": "972365f5-bfb2-4487-9fb9-752c4794bfd9",
"userAgent": "eks.amazonaws.com"
}
SetRulePriorities
#Description
Sets the priorities of the specified rules.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e1c81136-f9a2-4b70-82a8-967f416ccccb",
"eventName": "SetRulePriorities",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ce3c1409-cee0-4830-8694-ed4e996c4ac3",
"requestParameters": {
"rulePriorities": [
{
"priority": 20,
"ruleArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener-rule/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e/bf31981153a4c38e"
}
]
},
"responseElements": {
"rules": [
{
"actions": [
{
"forwardConfig": {
"targetGroupStickinessConfig": {
"enabled": false
},
"targetGroups": [
{
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"weight": 1
}
]
},
"targetGroupArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:targetgroup/dwfix-tg-ct/7665bbaa6ad76109",
"type": "forward"
}
],
"conditions": [
{
"field": "path-pattern",
"pathPatternConfig": {
"values": [
"/dwfix/*"
]
},
"values": [
"/dwfix/*"
]
}
],
"isDefault": false,
"priority": "20",
"ruleArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:listener-rule/app/dwfix-elb-ct/8d3411ad46e19e49/4c025edaea94aa3e/bf31981153a4c38e"
}
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SetSubnets
#Description
Enables the Availability Zones for the specified public subnets for the specified Application Load Balancer, Network Load Balancer or Gateway Load Balancer.
Example CloudTrail Event #
{
"apiVersion": "2015-12-01",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ebe18556-27a0-48a5-83dd-c1b7f2ddc9bd",
"eventName": "SetSubnets",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventTime": "2026-06-29T21:12:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4d4408d1-7502-46d4-956b-563d0dafe598",
"requestParameters": {
"loadBalancerArn": "arn:aws:elasticloadbalancing:us-west-1:123456789012:loadbalancer/app/dwfix-elb-ct/8d3411ad46e19e49",
"subnets": [
"subnet-0c9f719882f5c95ae",
"subnet-04caa2ba1250f8fb6"
]
},
"responseElements": {
"availabilityZones": [
{
"loadBalancerAddresses": [],
"subnetId": "subnet-0c9f719882f5c95ae",
"zoneName": "us-west-1a"
},
{
"loadBalancerAddresses": [],
"subnetId": "subnet-04caa2ba1250f8fb6",
"zoneName": "us-west-1c"
}
],
"ipAddressType": "ipv4"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticloadbalancing.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeWebACLAssociation
#Description
DescribeWebACLAssociation recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e53b97b3-74a9-445d-af5b-c11ee61b4901",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventName": "DescribeWebACLAssociation",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2015-12-01",
"readOnly": true,
"managementEvent": true,
"requestID": "bf2cb23b-6c36-4aef-99f4-5757eb5b4733",
"userAgent": "wafv2.amazonaws.com"
}
GetLoadBalancerWebACL
#Description
GetLoadBalancerWebACL recorded by CloudTrail for Elastic Load Balancing. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "157e32b9-0af7-469c-b6b9-0a5fb2843671",
"eventSource": "elasticloadbalancing.amazonaws.com",
"eventName": "GetLoadBalancerWebACL",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2015-12-01",
"readOnly": true,
"managementEvent": true,
"requestID": "9dd815b3-cca6-449c-acee-5654191cb954",
"userAgent": "wafv2.amazonaws.com"
}