Elasticsearch Service

eventNameDescriptionSampleRule
anyCatch-all entry for Elasticsearch Service rules that match the service but not a specific eventName.NN
AcceptInboundConnectionAllows the destination Amazon OpenSearch Service domain owner to accept an inbound cross-cluster search connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AcceptInboundCrossClusterSearchConnectionAllows the destination domain owner to accept an inbound cross-cluster search connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AddDataSourceCreates a new direct-query data source to the specified domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AddDirectQueryDataSourceAdds a new data source in Amazon OpenSearch Service so that you can perform direct queries on external data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AddTagsAttaches tags to an existing Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociatePackageAssociates a package with an Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociatePackagesOperation in the Amazon OpenSearch Service API for associating multiple packages with a domain simultaneously. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AttachDataSourceAttaches a data source to an OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AuthorizeVpcEndpointAccessProvides access to an Amazon OpenSearch Service domain through the use of an interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CancelDomainConfigChangeCancels a pending configuration change on an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CancelElasticsearchServiceSoftwareUpdateCancels a scheduled service software update for an Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CancelServiceSoftwareUpdateCancels a scheduled service software update for an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateApplicationCreates an OpenSearch UI application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateDomainCreates an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateElasticsearchDomainCreates a new Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateIndexCreates an OpenSearch index with optional automatic semantic enrichment for specified text fields. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateOutboundConnectionCreates a new cross-cluster search connection from a source Amazon OpenSearch Service domain to a destination domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateOutboundCrossClusterSearchConnectionCreates a new cross-cluster search connection from a source domain to a destination domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreatePackageCreate a package for use with Amazon ES domains. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateVpcEndpointCreates an Amazon OpenSearch Service-managed VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteApplicationDeletes a specified OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteDataSourceDeletes a direct-query data source. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteDirectQueryDataSourceDeletes a previously configured direct query data source from Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteDomainDeletes an Amazon OpenSearch Service domain and all of its data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteElasticsearchDomainPermanently deletes the specified Elasticsearch domain and all of its data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteElasticsearchServiceRoleDeletes the service-linked role that Elasticsearch Service uses to manage and maintain VPC domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteInboundConnectionAllows the destination Amazon OpenSearch Service domain owner to delete an existing inbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteInboundCrossClusterSearchConnectionAllows the destination domain owner to delete an existing inbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteIndexDeletes an OpenSearch index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteOutboundConnectionAllows the source Amazon OpenSearch Service domain owner to delete an existing outbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteOutboundCrossClusterSearchConnectionAllows the source domain owner to delete an existing outbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeletePackageDelete the package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteVpcEndpointDeletes an Amazon OpenSearch Service-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeregisterCapabilityDeregisters a capability from an OpenSearch UI application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDataSourceAttachmentReturns the current status and details of a specific data source attachment for an OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDomainDescribes the domain configuration for the specified Amazon OpenSearch Service domain, including the domain ID, domain service endpoint, and domain ARN. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeDomainAutoTunesProvides scheduled Auto-Tune action details for the Elasticsearch domain, such as Auto-Tune action type, description, severity, and scheduled date. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDomainChangeProgressReturns information about the current blue/green deployment happening on a domain, including a change ID, status, and progress stages. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeDomainConfigReturns the configuration of an Amazon OpenSearch Service domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeDomainHealthReturns information about domain and node health, the standby Availability Zone, number of nodes per Availability Zone, and shard count per node. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDomainNodesReturns information about domain and nodes, including data nodes, master nodes, ultrawarm nodes, Availability Zone(s), standby nodes, node configurations, and node states. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeDomainsReturns domain configuration information about the specified Amazon OpenSearch Service domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDryRunProgressDescribes the progress of a pre-update dry run analysis on an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeElasticsearchDomainReturns domain configuration information about the specified Elasticsearch domain, including the domain ID, domain endpoint, and domain ARN. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeElasticsearchDomainConfigProvides cluster configuration information about the specified Elasticsearch domain, such as the state, creation date, update version, and update date for cluster options. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeElasticsearchDomainsReturns domain configuration information about the specified Elasticsearch domains, including the domain ID, domain endpoint, and domain ARN. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeElasticsearchInstanceTypeLimitsDescribe Elasticsearch Limits for a given InstanceType and ElasticsearchVersion. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeInboundConnectionsLists all the inbound cross-cluster search connections for a destination (remote) Amazon OpenSearch Service domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeInboundCrossClusterSearchConnectionsLists all the inbound cross-cluster search connections for a destination domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeInsightDetailsDescribes the details of an existing insight for an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeInstanceTypeLimitsDescribes the instance count, storage, and master node limits for a given OpenSearch or Elasticsearch version and instance type. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeOutboundConnectionsLists all the outbound cross-cluster connections for a local (source) Amazon OpenSearch Service domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeOutboundCrossClusterSearchConnectionsLists all the outbound cross-cluster search connections for a source domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribePackagesDescribes all packages available to Amazon ES. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeReservedElasticsearchInstanceOfferingsLists available reserved Elasticsearch instance offerings. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeReservedElasticsearchInstancesReturns information about reserved Elasticsearch instances for this account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeReservedInstanceOfferingsDescribes the available Amazon OpenSearch Service Reserved Instance offerings for a given Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeReservedInstancesDescribes the Amazon OpenSearch Service instances that you have reserved in a given Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeVpcEndpointsDescribes one or more Amazon OpenSearch Service-managed VPC endpoints. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DetachDataSourceRemoves a data source from an OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DissociatePackageDissociates a package from the Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DissociatePackagesDissociates multiple packages from a domain simultaneously. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetApplicationRetrieves the configuration and status of an existing OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetCapabilityRetrieves information about a registered capability for an OpenSearch UI application, including its configuration and current status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetCompatibleElasticsearchVersionsReturns a list of upgrade compatible Elastisearch versions. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetCompatibleVersionsReturns a map of OpenSearch or Elasticsearch versions and the versions you can upgrade them to. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetDataSourceRetrieves information about a direct query data source. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetDefaultApplicationSettingGets the ARN of the current default application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetDirectQueryDataSourceReturns detailed configuration information for a specific direct query data source in Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetDomainMaintenanceStatusThe status of the maintenance action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetIndexRetrieves information about an OpenSearch index including its schema and semantic enrichment configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetPackageVersionHistoryReturns a list of versions of the package, along with their creation time and commit message. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetUpgradeHistoryRetrieves the complete history of the last 10 upgrades that were performed on the domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetUpgradeStatusRetrieves the latest status of the last upgrade or upgrade eligibility check that was performed on the domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListApplicationsLists all OpenSearch applications under your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDataSourceAttachmentsReturns a paginated list of all data source attachments for an OpenSearch application, including attachments in all states (PENDING, ATTACHED, and FAILED). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDataSourcesLists direct-query data sources for a specific domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDirectQueryDataSourcesLists an inventory of all the direct query data sources that you have configured within Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDomainMaintenancesA list of maintenance actions for the domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDomainNamesReturns the name of all Elasticsearch domains owned by the current user's account.YN
ListDomainsForPackageLists all Amazon ES domains associated with the package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListElasticsearchInstanceTypesList all Elasticsearch instance types that are supported for given ElasticsearchVersion Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListElasticsearchVersionsList all supported Elasticsearch versions Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListInsightsLists insights for an Amazon OpenSearch Service domain or Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListInstanceTypeDetailsLists all instance types and available features for a given OpenSearch or Elasticsearch version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListPackagesForDomainLists all packages associated with the Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListScheduledActionsRetrieves a list of configuration changes that are scheduled for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsReturns all tags for the given Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListVersionsLists all versions of OpenSearch and Elasticsearch that Amazon OpenSearch Service supports. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListVpcEndpointAccessRetrieves information about each principal that is allowed to access a given Amazon OpenSearch Service domain through the use of an interface VPC endpoint. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListVpcEndpointsRetrieves all Amazon OpenSearch Service-managed VPC endpoints in the current account and Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListVpcEndpointsForDomainRetrieves all Amazon OpenSearch Service-managed VPC endpoints associated with a particular domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
PurchaseReservedElasticsearchInstanceOfferingAllows you to purchase reserved Elasticsearch instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PurchaseReservedInstanceOfferingAllows you to purchase Amazon OpenSearch Service Reserved Instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutDefaultApplicationSettingSets the default application to the application with the specified ARN. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RegisterCapabilityRegisters a capability for an OpenSearch UI application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RejectInboundConnectionAllows the remote Amazon OpenSearch Service domain owner to reject an inbound cross-cluster connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RejectInboundCrossClusterSearchConnectionAllows the destination domain owner to reject an inbound cross-cluster search connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveTagsRemoves the specified set of tags from the specified Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RevokeVpcEndpointAccessRevokes access to an Amazon OpenSearch Service domain that was provided through an interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RollbackServiceSoftwareUpdateRolls back a service software update for a domain to the previous version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartDomainMaintenanceStarts the node maintenance process on the data node. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartElasticsearchServiceSoftwareUpdateSchedules a service software update for an Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartServiceSoftwareUpdateSchedules a service software update for an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateApplicationUpdates the configuration and settings of an existing OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDataSourceUpdates a direct-query data source. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDirectQueryDataSourceUpdates the configuration or properties of an existing direct query data source in Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDomainConfigModifies the cluster configuration of the specified Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateElasticsearchDomainConfigModifies the cluster configuration of the specified Elasticsearch domain, setting as setting the instance type and the number of instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateIndexUpdates an existing OpenSearch index schema and semantic enrichment configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdatePackageUpdates a package for use with Amazon ES domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdatePackageScopeUpdates the scope of a package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateScheduledActionReschedules a planned domain configuration change for a later time. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateVpcEndpointModifies an Amazon OpenSearch Service-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpgradeDomainAllows you to either upgrade your Amazon OpenSearch Service domain or perform an upgrade eligibility check to a compatible version of OpenSearch or Elasticsearch. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpgradeElasticsearchDomainAllows you to either upgrade your domain or perform an Upgrade eligibility check to a compatible Elasticsearch version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetMigrationRetrieves the current status and progress of a migration job, including the number of exported and imported objects and error details if the migration failed. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
InsightFeedbackSubmits feedback for an existing insight in an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListMigrationsLists migration jobs for an Amazon OpenSearch Service application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartMigrationInitiates a migration job to migrate saved objects from a data source to an Amazon OpenSearch Service application workspace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: Elasticsearch Service (catch-all)

#
Service
es

Description

Catch-all entry for Elasticsearch Service rules that match the service but not a specific eventName.

AcceptInboundConnection

#
Service
es

Description

Allows the destination Amazon OpenSearch Service domain owner to accept an inbound cross-cluster search connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AcceptInboundCrossClusterSearchConnection

#
Service
es

Description

Allows the destination domain owner to accept an inbound cross-cluster search connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AddDataSource

#
Service
es

Description

Creates a new direct-query data source to the specified domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AddDirectQueryDataSource

#
Service
es

Description

Adds a new data source in Amazon OpenSearch Service so that you can perform direct queries on external data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AddTags

#
Service
es

Description

Attaches tags to an existing Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociatePackage

#
Service
es

Description

Associates a package with an Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociatePackages

#
Service
es

Description

Operation in the Amazon OpenSearch Service API for associating multiple packages with a domain simultaneously. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AttachDataSource

#
Service
es

Description

Attaches a data source to an OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AuthorizeVpcEndpointAccess

#
Service
es

Description

Provides access to an Amazon OpenSearch Service domain through the use of an interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CancelDomainConfigChange

#
Service
es

Description

Cancels a pending configuration change on an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CancelElasticsearchServiceSoftwareUpdate

#
Service
es

Description

Cancels a scheduled service software update for an Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CancelServiceSoftwareUpdate

#
Service
es

Description

Cancels a scheduled service software update for an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateApplication

#
Service
es

Description

Creates an OpenSearch UI application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateDomain

#
Service
es

Description

Creates an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateElasticsearchDomain

#
Service
es

Description

Creates a new Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateIndex

#
Service
es

Description

Creates an OpenSearch index with optional automatic semantic enrichment for specified text fields. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateOutboundConnection

#
Service
es

Description

Creates a new cross-cluster search connection from a source Amazon OpenSearch Service domain to a destination domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateOutboundCrossClusterSearchConnection

#
Service
es

Description

Creates a new cross-cluster search connection from a source domain to a destination domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreatePackage

#
Service
es

Description

Create a package for use with Amazon ES domains. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9a3ade8f-34d9-4bfe-a4b6-f38f06a57841",
  "eventSource": "es.amazonaws.com",
  "eventName": "CreatePackage",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "28b3511f-d9b1-428a-8a1f-81d4d3e40f63",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.13.3 (+https://www.terraform.io) terraform-provider-aws/6.14.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.39.0 ua/2.1 os/linux lang/go#1.24.6 md/GOOS#linux md/GOARCH#arm64 api/opensearch#1.52.3 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.eu-west-1.amazonaws.com"
  }
}

CreateVpcEndpoint

#
Service
es

Description

Creates an Amazon OpenSearch Service-managed VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteApplication

#
Service
es

Description

Deletes a specified OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteDataSource

#
Service
es

Description

Deletes a direct-query data source. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteDirectQueryDataSource

#
Service
es

Description

Deletes a previously configured direct query data source from Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteDomain

#
Service
es

Description

Deletes an Amazon OpenSearch Service domain and all of its data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteElasticsearchDomain

#
Service
es

Description

Permanently deletes the specified Elasticsearch domain and all of its data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteElasticsearchServiceRole

#
Service
es

Description

Deletes the service-linked role that Elasticsearch Service uses to manage and maintain VPC domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteInboundConnection

#
Service
es

Description

Allows the destination Amazon OpenSearch Service domain owner to delete an existing inbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteInboundCrossClusterSearchConnection

#
Service
es

Description

Allows the destination domain owner to delete an existing inbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteIndex

#
Service
es

Description

Deletes an OpenSearch index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteOutboundConnection

#
Service
es

Description

Allows the source Amazon OpenSearch Service domain owner to delete an existing outbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteOutboundCrossClusterSearchConnection

#
Service
es

Description

Allows the source domain owner to delete an existing outbound cross-cluster search connection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeletePackage

#
Service
es

Description

Delete the package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteVpcEndpoint

#
Service
es

Description

Deletes an Amazon OpenSearch Service-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeregisterCapability

#
Service
es

Description

Deregisters a capability from an OpenSearch UI application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDataSourceAttachment

#
Service
es

Description

Returns the current status and details of a specific data source attachment for an OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDomain

#
Service
es

Description

Describes the domain configuration for the specified Amazon OpenSearch Service domain, including the domain ID, domain service endpoint, and domain ARN. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "591c154d-a4c5-4c03-bbaa-91797535507a",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeDomain",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "6b4d62e6-60bd-4f6d-895e-fe1191e8f1af",
  "userAgent": "Boto3/1.43.52 md/Botocore#1.43.52 ua/2.1 os/linux#6.1.175-219.359.amzn2023.aarch64 md/arch#aarch64 lang/python#3.14.6 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.52",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.ap-southeast-2.amazonaws.com"
  }
}

DescribeDomainAutoTunes

#
Service
es

Description

Provides scheduled Auto-Tune action details for the Elasticsearch domain, such as Auto-Tune action type, description, severity, and scheduled date. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDomainChangeProgress

#
Service
es

Description

Returns information about the current blue/green deployment happening on a domain, including a change ID, status, and progress stages. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ad1d31a9-2fbf-43f8-a83a-a377446323f1",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeDomainChangeProgress",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "526898fb-150d-4f23-8f22-1b0a731d9929",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-2.amazonaws.com"
  }
}

DescribeDomainConfig

#
Service
es

Description

Returns the configuration of an Amazon OpenSearch Service domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6df3ddb0-b22d-44b8-b45c-283e02a1e25b",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeDomainConfig",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a4c9c0db-93e4-41d2-89fb-fa70a96fa151",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.13.3 (+https://www.terraform.io) terraform-provider-aws/5.100.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.36.3 ua/2.1 os/linux lang/go#1.23.10 md/GOOS#linux md/GOARCH#amd64 api/opensearch#1.46.4 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

DescribeDomainHealth

#
Service
es

Description

Returns information about domain and node health, the standby Availability Zone, number of nodes per Availability Zone, and shard count per node. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDomainNodes

#
Service
es

Description

Returns information about domain and nodes, including data nodes, master nodes, ultrawarm nodes, Availability Zone(s), standby nodes, node configurations, and node states. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "14f2a524-0b9d-4e21-8cb4-4def34dc8ec5",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeDomainNodes",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "21d2b51a-cd90-4a28-a710-62ab6770086f",
  "userAgent": "aws-sdk-go-v2/1.38.1 ua/2.1 os/linux lang/go#1.25.0 md/GOOS#linux md/GOARCH#arm64 exec-env/AWS_ECS_FARGATE api/opensearch#1.50.0 app/APN_1.1-pc_70z3wc9b95eq8x71w5uctkf9r$ m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

DescribeDomains

#
Service
es

Description

Returns domain configuration information about the specified Amazon OpenSearch Service domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDryRunProgress

#
Service
es

Description

Describes the progress of a pre-update dry run analysis on an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeElasticsearchDomain

#
Service
es

Description

Returns domain configuration information about the specified Elasticsearch domain, including the domain ID, domain endpoint, and domain ARN. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "52fb97cc-ea97-4aa5-8f7b-e6694dc08a3c",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeElasticsearchDomain",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "aa3f46e5-ef90-4f5f-a063-1f2867125c0a",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#adaptive",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.ca-central-1.amazonaws.com"
  }
}

DescribeElasticsearchDomainConfig

#
Service
es

Description

Provides cluster configuration information about the specified Elasticsearch domain, such as the state, creation date, update version, and update date for cluster options. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bd5dc313-14cd-411a-83a9-cff85144a451",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeElasticsearchDomainConfig",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "cb167876-50dd-4cde-9bb5-dff7d5c687c7",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/elasticsearchservice#1.42.4 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

DescribeElasticsearchDomains

#
Service
es

Description

Returns domain configuration information about the specified Elasticsearch domains, including the domain ID, domain endpoint, and domain ARN. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "87b044c4-8f37-4069-bf0e-23e7e6cde899",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeElasticsearchDomains",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "98a653f7-e152-4419-b87f-49ce2a0eb000",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/elasticsearchservice#1.33.6 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-2.amazonaws.com"
  }
}

DescribeElasticsearchInstanceTypeLimits

#
Service
es

Description

Describe Elasticsearch Limits for a given InstanceType and ElasticsearchVersion. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeInboundConnections

#
Service
es

Description

Lists all the inbound cross-cluster search connections for a destination (remote) Amazon OpenSearch Service domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "cb429ff1-ef66-4a1c-b218-66ab49fc6247",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeInboundConnections",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c429c4e2-a053-40f8-a86d-24ee907eaf19",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-2.amazonaws.com"
  }
}

DescribeInboundCrossClusterSearchConnections

#
Service
es

Description

Lists all the inbound cross-cluster search connections for a destination domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeInsightDetails

#
Service
es

Description

Describes the details of an existing insight for an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeInstanceTypeLimits

#
Service
es

Description

Describes the instance count, storage, and master node limits for a given OpenSearch or Elasticsearch version and instance type. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeOutboundConnections

#
Service
es

Description

Lists all the outbound cross-cluster connections for a local (source) Amazon OpenSearch Service domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a3a15990-4e7c-4f18-ac4b-56d69d07ac46",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeOutboundConnections",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "717f9e5e-fca6-4de5-9a57-11e9f28c49b2",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

DescribeOutboundCrossClusterSearchConnections

#
Service
es

Description

Lists all the outbound cross-cluster search connections for a source domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribePackages

#
Service
es

Description

Describes all packages available to Amazon ES. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b5c7c350-2146-409c-8cbb-b7c358b08049",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribePackages",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "68f2568e-2168-4f23-8073-cf7c503c5446",
  "userAgent": "aws-sdk-go/1.54.20 (go1.21.13; linux; amd64)",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

DescribeReservedElasticsearchInstanceOfferings

#
Service
es

Description

Lists available reserved Elasticsearch instance offerings. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeReservedElasticsearchInstances

#
Service
es

Description

Returns information about reserved Elasticsearch instances for this account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "40c10db7-33b1-4093-9850-184f0e8b7f71",
  "eventSource": "es.amazonaws.com",
  "eventName": "DescribeReservedElasticsearchInstances",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "8094c028-e382-42fe-a023-12a3c21e1d88",
  "userAgent": "aws-sdk-go-v2/1.38.1 ua/2.1 os/linux lang/go#1.25.0 md/GOOS#linux md/GOARCH#arm64 exec-env/AWS_ECS_FARGATE api/elasticsearchservice#1.35.0 app/APN_1.1-pc_70z3wc9b95eq8x71w5uctkf9r$ m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.ca-central-1.amazonaws.com"
  }
}

DescribeReservedInstanceOfferings

#
Service
es

Description

Describes the available Amazon OpenSearch Service Reserved Instance offerings for a given Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeReservedInstances

#
Service
es

Description

Describes the Amazon OpenSearch Service instances that you have reserved in a given Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeVpcEndpoints

#
Service
es

Description

Describes one or more Amazon OpenSearch Service-managed VPC endpoints. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DetachDataSource

#
Service
es

Description

Removes a data source from an OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DissociatePackage

#
Service
es

Description

Dissociates a package from the Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DissociatePackages

#
Service
es

Description

Dissociates multiple packages from a domain simultaneously. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetApplication

#
Service
es

Description

Retrieves the configuration and status of an existing OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetCapability

#
Service
es

Description

Retrieves information about a registered capability for an OpenSearch UI application, including its configuration and current status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetCompatibleElasticsearchVersions

#
Service
es

Description

Returns a list of upgrade compatible Elastisearch versions. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0b2e38ee-0e5b-4342-b59e-8939fcf12e78",
  "eventSource": "es.amazonaws.com",
  "eventName": "GetCompatibleElasticsearchVersions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "9df1da1e-90ed-4ebd-b132-50a6e0213b9b",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/elasticsearchservice#1.42.4 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

GetCompatibleVersions

#
Service
es

Description

Returns a map of OpenSearch or Elasticsearch versions and the versions you can upgrade them to. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "024810b5-d782-40e1-86bf-a403e4d42f02",
  "eventSource": "es.amazonaws.com",
  "eventName": "GetCompatibleVersions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d91f0744-6564-4f82-8271-f049ce3f50db",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.13.3 (+https://www.terraform.io) terraform-provider-aws/5.100.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.36.3 ua/2.1 os/linux lang/go#1.23.10 md/GOOS#linux md/GOARCH#amd64 api/opensearch#1.46.4 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

GetDataSource

#
Service
es

Description

Retrieves information about a direct query data source. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetDefaultApplicationSetting

#
Service
es

Description

Gets the ARN of the current default application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetDirectQueryDataSource

#
Service
es

Description

Returns detailed configuration information for a specific direct query data source in Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetDomainMaintenanceStatus

#
Service
es

Description

The status of the maintenance action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetIndex

#
Service
es

Description

Retrieves information about an OpenSearch index including its schema and semantic enrichment configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetPackageVersionHistory

#
Service
es

Description

Returns a list of versions of the package, along with their creation time and commit message. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetUpgradeHistory

#
Service
es

Description

Retrieves the complete history of the last 10 upgrades that were performed on the domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "833d6293-27b0-4867-b6db-06c0d3480005",
  "eventSource": "es.amazonaws.com",
  "eventName": "GetUpgradeHistory",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "80621c73-8310-471b-a99b-f753cf70bddc",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-2.amazonaws.com"
  }
}

GetUpgradeStatus

#
Service
es

Description

Retrieves the latest status of the last upgrade or upgrade eligibility check that was performed on the domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListApplications

#
Service
es

Description

Lists all OpenSearch applications under your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDataSourceAttachments

#
Service
es

Description

Returns a paginated list of all data source attachments for an OpenSearch application, including attachments in all states (PENDING, ATTACHED, and FAILED). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDataSources

#
Service
es

Description

Lists direct-query data sources for a specific domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDirectQueryDataSources

#
Service
es

Description

Lists an inventory of all the direct query data sources that you have configured within Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDomainMaintenances

#
Service
es

Description

A list of maintenance actions for the domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDomainNames

#
Service
es

Description

Returns the name of all Elasticsearch domains owned by the current user's account.

Example CloudTrail Event #

{
  "awsRegion": "ap-southeast-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: es:ListDomainNames on resource: arn:aws:es:ap-southeast-2:731544447609:domain/*",
  "eventCategory": "Management",
  "eventID": "af391d8f-0278-4c96-8d86-1fd80d41be2c",
  "eventName": "ListDomainNames",
  "eventSource": "es.amazonaws.com",
  "eventTime": "2021-04-13T11:35:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "75db5494-cc40-4603-bdd8-0d7433d0514f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListDomainsForPackage

#
Service
es

Description

Lists all Amazon ES domains associated with the package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListElasticsearchInstanceTypes

#
Service
es

Description

List all Elasticsearch instance types that are supported for given ElasticsearchVersion Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListElasticsearchVersions

#
Service
es

Description

List all supported Elasticsearch versions Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListInsights

#
Service
es

Description

Lists insights for an Amazon OpenSearch Service domain or Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f5dee248-253c-41ec-bc02-952a8a084de3",
  "eventSource": "es.amazonaws.com",
  "eventName": "ListInsights",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "684c2408-6756-493f-bb96-5a49a2d85800",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

ListInstanceTypeDetails

#
Service
es

Description

Lists all instance types and available features for a given OpenSearch or Elasticsearch version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListPackagesForDomain

#
Service
es

Description

Lists all packages associated with the Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListScheduledActions

#
Service
es

Description

Retrieves a list of configuration changes that are scheduled for a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTags

#
Service
es

Description

Returns all tags for the given Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListVersions

#
Service
es

Description

Lists all versions of OpenSearch and Elasticsearch that Amazon OpenSearch Service supports. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c5c5b6b3-b535-4aaf-8d32-943c7cfe7445",
  "eventSource": "es.amazonaws.com",
  "eventName": "ListVersions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "77c7e377-c33c-47fa-954c-9ce5d17aea3c",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-1.amazonaws.com"
  }
}

ListVpcEndpointAccess

#
Service
es

Description

Retrieves information about each principal that is allowed to access a given Amazon OpenSearch Service domain through the use of an interface VPC endpoint. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "54837ca2-b1a5-4030-a2f8-2c67f71de15e",
  "eventSource": "es.amazonaws.com",
  "eventName": "ListVpcEndpointAccess",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e1aa86bf-8195-4ec7-9128-17323af5ea36",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-2.amazonaws.com"
  }
}

ListVpcEndpoints

#
Service
es

Description

Retrieves all Amazon OpenSearch Service-managed VPC endpoints in the current account and Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListVpcEndpointsForDomain

#
Service
es

Description

Retrieves all Amazon OpenSearch Service-managed VPC endpoints associated with a particular domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8c3541dc-e09e-4939-bf69-019b33a9b600",
  "eventSource": "es.amazonaws.com",
  "eventName": "ListVpcEndpointsForDomain",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7708a9aa-8115-4a05-93fd-9f58db37d663",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "es.us-east-2.amazonaws.com"
  }
}

PurchaseReservedElasticsearchInstanceOffering

#
Service
es

Description

Allows you to purchase reserved Elasticsearch instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PurchaseReservedInstanceOffering

#
Service
es

Description

Allows you to purchase Amazon OpenSearch Service Reserved Instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutDefaultApplicationSetting

#
Service
es

Description

Sets the default application to the application with the specified ARN. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RegisterCapability

#
Service
es

Description

Registers a capability for an OpenSearch UI application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RejectInboundConnection

#
Service
es

Description

Allows the remote Amazon OpenSearch Service domain owner to reject an inbound cross-cluster connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RejectInboundCrossClusterSearchConnection

#
Service
es

Description

Allows the destination domain owner to reject an inbound cross-cluster search connection request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveTags

#
Service
es

Description

Removes the specified set of tags from the specified Elasticsearch domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RevokeVpcEndpointAccess

#
Service
es

Description

Revokes access to an Amazon OpenSearch Service domain that was provided through an interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RollbackServiceSoftwareUpdate

#
Service
es

Description

Rolls back a service software update for a domain to the previous version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartDomainMaintenance

#
Service
es

Description

Starts the node maintenance process on the data node. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartElasticsearchServiceSoftwareUpdate

#
Service
es

Description

Schedules a service software update for an Amazon ES domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartServiceSoftwareUpdate

#
Service
es

Description

Schedules a service software update for an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateApplication

#
Service
es

Description

Updates the configuration and settings of an existing OpenSearch application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDataSource

#
Service
es

Description

Updates a direct-query data source. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDirectQueryDataSource

#
Service
es

Description

Updates the configuration or properties of an existing direct query data source in Amazon OpenSearch Service. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDomainConfig

#
Service
es

Description

Modifies the cluster configuration of the specified Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateElasticsearchDomainConfig

#
Service
es

Description

Modifies the cluster configuration of the specified Elasticsearch domain, setting as setting the instance type and the number of instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateIndex

#
Service
es

Description

Updates an existing OpenSearch index schema and semantic enrichment configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdatePackage

#
Service
es

Description

Updates a package for use with Amazon ES domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdatePackageScope

#
Service
es

Description

Updates the scope of a package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateScheduledAction

#
Service
es

Description

Reschedules a planned domain configuration change for a later time. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateVpcEndpoint

#
Service
es

Description

Modifies an Amazon OpenSearch Service-managed interface VPC endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpgradeDomain

#
Service
es

Description

Allows you to either upgrade your Amazon OpenSearch Service domain or perform an upgrade eligibility check to a compatible version of OpenSearch or Elasticsearch. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpgradeElasticsearchDomain

#
Service
es

Description

Allows you to either upgrade your domain or perform an Upgrade eligibility check to a compatible Elasticsearch version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetMigration

#
Service
es

Description

Retrieves the current status and progress of a migration job, including the number of exported and imported objects and error details if the migration failed. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

InsightFeedback

#
Service
es

Description

Submits feedback for an existing insight in an Amazon OpenSearch Service domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListMigrations

#
Service
es

Description

Lists migration jobs for an Amazon OpenSearch Service application. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartMigration

#
Service
es

Description

Initiates a migration job to migrate saved objects from a data source to an Amazon OpenSearch Service application workspace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.