EMR

eventNameDescriptionSampleRule
anyCatch-all entry for EMR rules that match the service but not a specific eventName.NN
AddInstanceFleetAdds an instance fleet to a running cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AddInstanceGroupsAdds one or more instance groups to a running cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AddJobFlowStepsAddJobFlowSteps adds new steps to a running cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
AddTagsAdds tags to an Amazon EMR resource, such as a cluster or an Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CancelStepsCancels a pending step or steps in a running cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreatePersistentAppUICreates a persistent application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateSecurityConfigurationCreates a security configuration, which is stored in the service and can be specified when a cluster is created. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateStudioCreates a new Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateStudioSessionMappingMaps a user or group to the Amazon EMR Studio specified by StudioId, and applies a session policy to refine Studio permissions for that user or group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSecurityConfigurationDeletes a security configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteStudioRemoves an Amazon EMR Studio from the Studio metadata store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteStudioSessionMappingRemoves a user or group from an Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeClusterProvides cluster-level details including status, hardware and software configuration, VPC settings, and so on. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeJobFlowsThis API is no longer supported and will eventually be removed. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeNotebookExecutionProvides details of a notebook execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribePersistentAppUIDescribes a persistent application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeReleaseLabelProvides Amazon EMR release label details, such as the releases available the Region where the API request is run, and the available applications for a specific Amazon EMR release label. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeSecurityConfigurationProvides the details of a security configuration by returning the configuration JSON. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeStepProvides more detail about the cluster step. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeStudioReturns details for the specified Amazon EMR Studio including ID, Name, VPC, Studio access URL, and so on. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetAutoTerminationPolicyReturns the auto-termination policy for an Amazon EMR cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetBlockPublicAccessConfigurationReturns the Amazon EMR block public access configuration for your Amazon Web Services account in the current Region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetClusterSessionCredentialsProvides temporary, HTTP basic credentials that are associated with a given runtime IAM role and used by a cluster with fine-grained access control activated. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetManagedScalingPolicyFetches the attached managed scaling policy for an Amazon EMR cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetOnClusterAppUIPresignedURLThe presigned URL properties for the cluster's application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetPersistentAppUIPresignedURLThe presigned URL properties for the cluster's application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSessionReturns detailed information about a session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSessionEndpointReturns the Spark Connect endpoint URL and a time-limited authentication token for the specified session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetStudioSessionMappingFetches mapping details for the specified Amazon EMR Studio and identity (user or group). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListBootstrapActionsProvides information about the bootstrap actions associated with a cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListClustersProvides the status of all clusters visible to this Amazon Web Services account.YN
ListInstanceFleetsLists all available details about the instance fleets in a cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListInstanceGroupsProvides all available details about the instance groups in a cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListInstancesProvides information for all active Amazon EC2 instances and Amazon EC2 instances terminated in the last 30 days, up to a maximum of 2,000. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListNotebookExecutionsProvides summaries of all notebook executions. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListReleaseLabelsRetrieves release labels of Amazon EMR services in the Region where the API is called. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListSecurityConfigurationsLists all the security configurations visible to this account, providing their creation dates and times, and their names. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListSessionsLists the sessions on a cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListStepsProvides a list of steps for the cluster in reverse order unless you specify stepIds with the request or filter by StepStates. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListStudiosReturns a list of all Amazon EMR Studios associated with the Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListStudioSessionMappingsReturns a list of all user or group session mappings for the Amazon EMR Studio specified by StudioId. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListSupportedInstanceTypesA list of the instance types that Amazon EMR supports. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ModifyClusterModifies the number of steps that can be executed concurrently for the cluster specified using ClusterID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ModifyInstanceFleetModifies the target On-Demand and target Spot capacities for the instance fleet with the specified InstanceFleetID within the cluster specified using ClusterID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ModifyInstanceGroupsModifyInstanceGroups modifies the number of nodes and configuration settings of an instance group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutAutoScalingPolicyCreates or updates an automatic scaling policy for a core instance group or task instance group in an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutAutoTerminationPolicyAuto-termination is supported in Amazon EMR releases 5.30.0 and 6.1.0 and later. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutBlockPublicAccessConfigurationCreates or updates an Amazon EMR block public access configuration for your Amazon Web Services account in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutManagedScalingPolicyCreates or updates a managed scaling policy for an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveAutoScalingPolicyRemoves an automatic scaling policy from a specified instance group within an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveAutoTerminationPolicyRemoves an auto-termination policy from an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveManagedScalingPolicyRemoves a managed scaling policy from a specified Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveTagsRemoves tags from an Amazon EMR resource, such as a cluster or Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RunJobFlowRunJobFlow creates and starts running a new cluster (job flow). Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SetKeepJobFlowAliveWhenNoStepsYou can use the SetKeepJobFlowAliveWhenNoSteps to configure a cluster (job flow) to terminate after the step execution, i.e., all your steps are executed. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
SetTerminationProtectionSetTerminationProtection locks a cluster (job flow) so the Amazon EC2 instances in the cluster cannot be terminated by user intervention, an API call, or in the event of a job-flow error. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
SetUnhealthyNodeReplacementSpecify whether to enable unhealthy node replacement, which lets Amazon EMR gracefully replace core nodes on a cluster if any nodes become unhealthy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
SetVisibleToAllUsersThe SetVisibleToAllUsers parameter is no longer supported. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartNotebookExecutionStarts a notebook execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartSessionCreates and starts a new Spark Connect session on the specified cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StopNotebookExecutionStops a notebook execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TerminateJobFlowsTerminateJobFlows shuts a list of clusters (job flows) down. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
TerminateSessionTerminates an active session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateStudioUpdates an Amazon EMR Studio configuration, including attributes such as name, description, and subnets. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateStudioSessionMappingUpdates the session policy attached to the user or group for the specified Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: EMR (catch-all)

#
Service
elasticmapreduce

Description

Catch-all entry for EMR rules that match the service but not a specific eventName.

AddInstanceFleet

#
Service
elasticmapreduce

Description

Adds an instance fleet to a running cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AddInstanceGroups

#
Service
elasticmapreduce

Description

Adds one or more instance groups to a running cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AddJobFlowSteps

#
Service
elasticmapreduce

Description

AddJobFlowSteps adds new steps to a running cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7d3e10dc-48d7-4b31-be6b-491ad8822789",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "AddJobFlowSteps",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "89b9c98e-a8e9-4bdd-ad50-36c92e397871",
  "userAgent": "aws-sdk-java/2.48.1 md/io#sync md/http#Apache5 ua/2.1 api/EMR#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

AddTags

#
Service
elasticmapreduce

Description

Adds tags to an Amazon EMR resource, such as a cluster or an Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CancelSteps

#
Service
elasticmapreduce

Description

Cancels a pending step or steps in a running cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d3966a3c-af91-43a9-92dd-d4c5ccbaf2fd",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "CancelSteps",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "b3268016-8ac9-4445-90a7-f65039c56d67",
  "userAgent": "aws-sdk-java/2.48.1 md/io#sync md/http#Apache5 ua/2.1 api/EMR#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

CreatePersistentAppUI

#
Service
elasticmapreduce

Description

Creates a persistent application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateSecurityConfiguration

#
Service
elasticmapreduce

Description

Creates a security configuration, which is stored in the service and can be specified when a cluster is created. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateStudio

#
Service
elasticmapreduce

Description

Creates a new Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateStudioSessionMapping

#
Service
elasticmapreduce

Description

Maps a user or group to the Amazon EMR Studio specified by StudioId, and applies a session policy to refine Studio permissions for that user or group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteSecurityConfiguration

#
Service
elasticmapreduce

Description

Deletes a security configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteStudio

#
Service
elasticmapreduce

Description

Removes an Amazon EMR Studio from the Studio metadata store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteStudioSessionMapping

#
Service
elasticmapreduce

Description

Removes a user or group from an Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeCluster

#
Service
elasticmapreduce

Description

Provides cluster-level details including status, hardware and software configuration, VPC settings, and so on. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeJobFlows

#
Service
elasticmapreduce

Description

This API is no longer supported and will eventually be removed. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeNotebookExecution

#
Service
elasticmapreduce

Description

Provides details of a notebook execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribePersistentAppUI

#
Service
elasticmapreduce

Description

Describes a persistent application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeReleaseLabel

#
Service
elasticmapreduce

Description

Provides Amazon EMR release label details, such as the releases available the Region where the API request is run, and the available applications for a specific Amazon EMR release label. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeSecurityConfiguration

#
Service
elasticmapreduce

Description

Provides the details of a security configuration by returning the configuration JSON. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7e86dff4-e63a-497f-a0c4-a3610c0e9902",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "DescribeSecurityConfiguration",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4b1ceec0-74f4-43c3-8182-d207020505c5",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#adaptive",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

DescribeStep

#
Service
elasticmapreduce

Description

Provides more detail about the cluster step. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d578bb15-d92e-45d9-a0d9-ad150febb767",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "DescribeStep",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1740cf1a-aabf-4515-810b-bad49824e863",
  "userAgent": "aws-sdk-java/2.48.1 md/io#sync md/http#Apache5 ua/2.1 api/EMR#2.48.x os/Linux#6.1.176-223.369.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

DescribeStudio

#
Service
elasticmapreduce

Description

Returns details for the specified Amazon EMR Studio including ID, Name, VPC, Studio access URL, and so on. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e3cf8fa1-9d0c-4469-97b2-21c3428e4378",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "DescribeStudio",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "fdf10349-e4b1-4d9b-9c0f-6cc00e717c8e",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/emr#1.58.0 m/E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetAutoTerminationPolicy

#
Service
elasticmapreduce

Description

Returns the auto-termination policy for an Amazon EMR cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d63816fb-3aaf-4c0e-88ce-d7db825ba120",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "GetAutoTerminationPolicy",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bf7bd89c-0bc7-45ef-83aa-42c2cc6a690b",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/emr#1.58.0 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetBlockPublicAccessConfiguration

#
Service
elasticmapreduce

Description

Returns the Amazon EMR block public access configuration for your Amazon Web Services account in the current Region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "27ee7067-6618-4945-87ef-0f96fa016939",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "GetBlockPublicAccessConfiguration",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ca6d3122-fc0e-4171-94a2-c1a401e680f1",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/emr#1.58.0 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
  }
}

GetClusterSessionCredentials

#
Service
elasticmapreduce

Description

Provides temporary, HTTP basic credentials that are associated with a given runtime IAM role and used by a cluster with fine-grained access control activated. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetManagedScalingPolicy

#
Service
elasticmapreduce

Description

Fetches the attached managed scaling policy for an Amazon EMR cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "05bc5ac7-481c-493c-b739-8fcb5953c3ce",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "GetManagedScalingPolicy",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f06096a5-fed8-442c-af13-4f6da45a6278",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/emr#1.58.0 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetOnClusterAppUIPresignedURL

#
Service
elasticmapreduce

Description

The presigned URL properties for the cluster's application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetPersistentAppUIPresignedURL

#
Service
elasticmapreduce

Description

The presigned URL properties for the cluster's application user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSession

#
Service
elasticmapreduce

Description

Returns detailed information about a session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSessionEndpoint

#
Service
elasticmapreduce

Description

Returns the Spark Connect endpoint URL and a time-limited authentication token for the specified session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetStudioSessionMapping

#
Service
elasticmapreduce

Description

Fetches mapping details for the specified Amazon EMR Studio and identity (user or group). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListBootstrapActions

#
Service
elasticmapreduce

Description

Provides information about the bootstrap actions associated with a cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListClusters

#
Service
elasticmapreduce

Description

Provides the status of all clusters visible to this Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "ap-southeast-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: elasticmapreduce:ListClusters on resource: *",
  "eventCategory": "Management",
  "eventID": "34d998e2-aaba-401c-bc22-3c48c3529a3c",
  "eventName": "ListClusters",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventTime": "2021-04-13T11:35:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "1030f834-e70d-4ed1-952a-33ed8ed80cab",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListInstanceFleets

#
Service
elasticmapreduce

Description

Lists all available details about the instance fleets in a cluster. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "babe2907-972a-4844-af65-d77da9763d1c",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "ListInstanceFleets",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1b83ff75-14c6-4428-bc47-8da2958ece71",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#adaptive",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListInstanceGroups

#
Service
elasticmapreduce

Description

Provides all available details about the instance groups in a cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListInstances

#
Service
elasticmapreduce

Description

Provides information for all active Amazon EC2 instances and Amazon EC2 instances terminated in the last 30 days, up to a maximum of 2,000. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5c67a2c4-4240-4991-b02c-20522d4aa244",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "ListInstances",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ef52268d-1190-4361-88f0-c9c46d93db78",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#adaptive",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListNotebookExecutions

#
Service
elasticmapreduce

Description

Provides summaries of all notebook executions. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c5d86716-b2a9-46fd-8b25-4c22dc50d67b",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "ListNotebookExecutions",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bcac9aa0-5aa6-46c1-9568-ca054007c40d",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/emr#1.58.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-west-1.amazonaws.com"
  }
}

ListReleaseLabels

#
Service
elasticmapreduce

Description

Retrieves release labels of Amazon EMR services in the Region where the API is called. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListSecurityConfigurations

#
Service
elasticmapreduce

Description

Lists all the security configurations visible to this account, providing their creation dates and times, and their names. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5648cd84-77f2-4b8f-9b30-80fc7406e4e9",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "ListSecurityConfigurations",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "73cf99dc-3646-4dfc-8f76-c1fd1ccf1d25",
  "userAgent": "config.amazonaws.com"
}

ListSessions

#
Service
elasticmapreduce

Description

Lists the sessions on a cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListSteps

#
Service
elasticmapreduce

Description

Provides a list of steps for the cluster in reverse order unless you specify stepIds with the request or filter by StepStates. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1d1fe50c-ba91-4b4b-87d1-5a64b4c77bf7",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "ListSteps",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4fcb9746-3f70-42c1-b06a-014d655696f7",
  "userAgent": "aws-sdk-java/2.48.1 md/io#sync md/http#Apache5 ua/2.1 api/EMR#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/F,AJ,C,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListStudios

#
Service
elasticmapreduce

Description

Returns a list of all Amazon EMR Studios associated with the Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "269a28bc-d299-4aa9-9a04-d40d8e2be8ae",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "ListStudios",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3fc7bfef-0b88-486d-8695-6e71d783f478",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/emr#1.58.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
  }
}

ListStudioSessionMappings

#
Service
elasticmapreduce

Description

Returns a list of all user or group session mappings for the Amazon EMR Studio specified by StudioId. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListSupportedInstanceTypes

#
Service
elasticmapreduce

Description

A list of the instance types that Amazon EMR supports. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ModifyCluster

#
Service
elasticmapreduce

Description

Modifies the number of steps that can be executed concurrently for the cluster specified using ClusterID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ModifyInstanceFleet

#
Service
elasticmapreduce

Description

Modifies the target On-Demand and target Spot capacities for the instance fleet with the specified InstanceFleetID within the cluster specified using ClusterID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ModifyInstanceGroups

#
Service
elasticmapreduce

Description

ModifyInstanceGroups modifies the number of nodes and configuration settings of an instance group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutAutoScalingPolicy

#
Service
elasticmapreduce

Description

Creates or updates an automatic scaling policy for a core instance group or task instance group in an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutAutoTerminationPolicy

#
Service
elasticmapreduce

Description

Auto-termination is supported in Amazon EMR releases 5.30.0 and 6.1.0 and later. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutBlockPublicAccessConfiguration

#
Service
elasticmapreduce

Description

Creates or updates an Amazon EMR block public access configuration for your Amazon Web Services account in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutManagedScalingPolicy

#
Service
elasticmapreduce

Description

Creates or updates a managed scaling policy for an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveAutoScalingPolicy

#
Service
elasticmapreduce

Description

Removes an automatic scaling policy from a specified instance group within an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveAutoTerminationPolicy

#
Service
elasticmapreduce

Description

Removes an auto-termination policy from an Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveManagedScalingPolicy

#
Service
elasticmapreduce

Description

Removes a managed scaling policy from a specified Amazon EMR cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveTags

#
Service
elasticmapreduce

Description

Removes tags from an Amazon EMR resource, such as a cluster or Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RunJobFlow

#
Service
elasticmapreduce

Description

RunJobFlow creates and starts running a new cluster (job flow). Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "db8284c7-54a2-4fda-b991-5143734d3009",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "RunJobFlow",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "15dba8f8-8a87-417d-8bed-e4ac5e3b0bee",
  "userAgent": "aws-sdk-java/2.48.1 md/io#sync md/http#Apache5 ua/2.1 api/EMR#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

SetKeepJobFlowAliveWhenNoSteps

#
Service
elasticmapreduce

Description

You can use the SetKeepJobFlowAliveWhenNoSteps to configure a cluster (job flow) to terminate after the step execution, i.e., all your steps are executed. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

SetTerminationProtection

#
Service
elasticmapreduce

Description

SetTerminationProtection locks a cluster (job flow) so the Amazon EC2 instances in the cluster cannot be terminated by user intervention, an API call, or in the event of a job-flow error. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

SetUnhealthyNodeReplacement

#
Service
elasticmapreduce

Description

Specify whether to enable unhealthy node replacement, which lets Amazon EMR gracefully replace core nodes on a cluster if any nodes become unhealthy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

SetVisibleToAllUsers

#
Service
elasticmapreduce

Description

The SetVisibleToAllUsers parameter is no longer supported. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartNotebookExecution

#
Service
elasticmapreduce

Description

Starts a notebook execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartSession

#
Service
elasticmapreduce

Description

Creates and starts a new Spark Connect session on the specified cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StopNotebookExecution

#
Service
elasticmapreduce

Description

Stops a notebook execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TerminateJobFlows

#
Service
elasticmapreduce

Description

TerminateJobFlows shuts a list of clusters (job flows) down. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "54f15883-7068-4b53-aedc-d242c75343e6",
  "eventSource": "elasticmapreduce.amazonaws.com",
  "eventName": "TerminateJobFlows",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "1421841d-f398-4195-8b73-0d843661b410",
  "userAgent": "aws-sdk-java/2.48.1 md/io#sync md/http#Apache5 ua/2.1 api/EMR#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

TerminateSession

#
Service
elasticmapreduce

Description

Terminates an active session. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateStudio

#
Service
elasticmapreduce

Description

Updates an Amazon EMR Studio configuration, including attributes such as name, description, and subnets. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateStudioSessionMapping

#
Service
elasticmapreduce

Description

Updates the session policy attached to the user or group for the specified Amazon EMR Studio. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.