Kinesis

eventNameDescriptionSampleRule
anyCatch-all entry for Kinesis rules that match the service but not a specific eventName.NN
AddTagsToStreamAdds or updates tags for the specified Kinesis data stream. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateStreamCreates a Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DecreaseStreamRetentionPeriodDecreases the Kinesis data stream's retention period, which is the length of time data records are accessible after they are added to the stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResourcePolicyDelete a policy for the specified data stream or consumer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteStreamDeletes a Kinesis data stream and all its shards and data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeregisterStreamConsumerTo deregister a consumer, provide its ARN. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeAccountSettingsDescribes the account-level settings for Amazon Kinesis Data Streams. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLimitsDescribes the shard limits and usage for the account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeStreamDescribes the specified Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeStreamConsumerTo get the description of a registered consumer, provide the ARN of the consumer. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeStreamSummaryProvides a summarized description of the specified Kinesis data stream without the shard list. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DisableEnhancedMonitoringDisables enhanced monitoring. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
EnableEnhancedMonitoringEnables enhanced Kinesis data stream monitoring for shard-level metrics. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetRecordsGets data records from a Kinesis data stream's shard. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetResourcePolicyReturns a policy attached to the specified data stream or consumer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetShardIteratorGets an Amazon Kinesis shard iterator. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
IncreaseStreamRetentionPeriodIncreases the Kinesis data stream's retention period, which is the length of time data records are accessible after they are added to the stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListShardsLists the shards in a stream and provides information about each shard. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListStreamConsumersLists the consumers registered to receive data from a stream using enhanced fan-out, and provides information about each consumer. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListStreamsLists your Kinesis data streams.YN
ListTagsForResourceList all tags added to the specified Kinesis resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsForStreamLists the tags for the specified Kinesis data stream. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
MergeShardsMerges two adjacent shards in a Kinesis data stream and combines them into a single shard to reduce the stream's capacity to ingest and transport data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutRecordWrites a single data record into an Amazon Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutRecordsWrites multiple data records into a Kinesis data stream in a single call (also referred to as a PutRecords request). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutResourcePolicyAttaches a resource-based policy to a data stream or registered consumer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RegisterStreamConsumerRegisters a consumer with a Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveTagsFromStreamRemoves tags from the specified Kinesis data stream. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SplitShardSplits a shard into two new shards in the Kinesis data stream, to increase the stream's capacity to ingest and transport data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartStreamEncryptionEnables or updates server-side encryption using an Amazon Web Services KMS key for a specified stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StopStreamEncryptionDisables server-side encryption for a specified stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
SubscribeToShardThis operation establishes an HTTP/2 connection between the consumer you specify in the ConsumerARN parameter and the shard you specify in the ShardId parameter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceAdds or updates tags for the specified Kinesis resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves tags from the specified Kinesis resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAccountSettingsUpdates the account-level settings for Amazon Kinesis Data Streams. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateMaxRecordSizeThis allows you to update the MaxRecordSize of a single record that you can write to, and read from a stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateShardCountUpdates the shard count of the specified stream to the specified number of shards. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateStreamModeUpdates the capacity mode of the data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateStreamWarmThroughputUpdates the warm throughput configuration for the specified Amazon Kinesis Data Streams on-demand data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: Kinesis (catch-all)

#
Service
kinesis

Description

Catch-all entry for Kinesis rules that match the service but not a specific eventName.

AddTagsToStream

#
Service
kinesis

Description

Adds or updates tags for the specified Kinesis data stream. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "895f46c7-17af-4f5e-addc-7f9fb5e8b7d1",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "AddTagsToStream",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "e4f128e5-3eff-3f7f-8612-e93bf2352479",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/5.100.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.36.3 ua/2.1 os/linux lang/go#1.23.10 md/GOOS#linux md/GOARCH#arm64 api/kinesis#1.35.1 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "kinesis.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "type": "AWS::Kinesis::Stream",
      "ARN": "arn:aws:kinesis:us-east-1:123456789012:stream/EXAMPLE"
    }
  ]
}

CreateStream

#
Service
kinesis

Description

Creates a Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DecreaseStreamRetentionPeriod

#
Service
kinesis

Description

Decreases the Kinesis data stream's retention period, which is the length of time data records are accessible after they are added to the stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResourcePolicy

#
Service
kinesis

Description

Delete a policy for the specified data stream or consumer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteStream

#
Service
kinesis

Description

Deletes a Kinesis data stream and all its shards and data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeregisterStreamConsumer

#
Service
kinesis

Description

To deregister a consumer, provide its ARN. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeAccountSettings

#
Service
kinesis

Description

Describes the account-level settings for Amazon Kinesis Data Streams. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLimits

#
Service
kinesis

Description

Describes the shard limits and usage for the account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeStream

#
Service
kinesis

Description

Describes the specified Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeStreamConsumer

#
Service
kinesis

Description

To get the description of a registered consumer, provide the ARN of the consumer. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "16552080-005a-34a8-a0e3-51a6e981496e",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "DescribeStreamConsumer",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e1fdccfc-7ce6-d99e-831e-b558ba0f7d32",
  "userAgent": "aws-sdk-java/2.24.9 Linux/5.15.0-1111-aws OpenJDK_64-Bit_Server_VM/21.0.10+7-LTS Java/21.0.10 scala/2.13.16 kotlin/1.7.10-release-333(1.7.10) vendor/Azul_Systems__Inc. io/sync http/Apache cfg/retry-mode/legacy",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.control-kinesis.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Kinesis::StreamConsumer",
      "ARN": "arn:aws:kinesis:us-east-1:123456789012:stream/EXAMPLE"
    }
  ]
}

DescribeStreamSummary

#
Service
kinesis

Description

Provides a summarized description of the specified Kinesis data stream without the shard list. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "08b46088-85d7-4d39-ba16-0a34304a27c0",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "DescribeStreamSummary",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ef1fae7f-b091-f16e-8dfc-4006beb58fdb",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.control-kinesis.us-west-2.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Kinesis::Stream",
      "ARN": "arn:aws:kinesis:us-west-2:123456789012:stream/EXAMPLE"
    }
  ]
}

DisableEnhancedMonitoring

#
Service
kinesis

Description

Disables enhanced monitoring. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

EnableEnhancedMonitoring

#
Service
kinesis

Description

Enables enhanced Kinesis data stream monitoring for shard-level metrics. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetRecords

#
Service
kinesis

Description

Gets data records from a Kinesis data stream's shard. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetResourcePolicy

#
Service
kinesis

Description

Returns a policy attached to the specified data stream or consumer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetShardIterator

#
Service
kinesis

Description

Gets an Amazon Kinesis shard iterator. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

IncreaseStreamRetentionPeriod

#
Service
kinesis

Description

Increases the Kinesis data stream's retention period, which is the length of time data records are accessible after they are added to the stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListShards

#
Service
kinesis

Description

Lists the shards in a stream and provides information about each shard. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "30ab1a9e-91a9-37dd-95ea-686540f627d5",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "ListShards",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c7103088-2871-3fc0-a5f4-05f99a71edb1",
  "userAgent": "aws-sdk-java/2.24.9 Linux/5.15.0-1111-aws OpenJDK_64-Bit_Server_VM/21.0.10+7-LTS Java/21.0.10 scala/2.13.16 kotlin/1.7.10-release-333(1.7.10) vendor/Azul_Systems__Inc. io/sync http/Apache cfg/retry-mode/legacy",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "kinesis.eu-west-1.amazonaws.com"
  },
  "resources": [
    {
      "type": "AWS::Kinesis::Stream",
      "ARN": "arn:aws:kinesis:eu-west-1:123456789012:stream/EXAMPLE"
    }
  ]
}

ListStreamConsumers

#
Service
kinesis

Description

Lists the consumers registered to receive data from a stream using enhanced fan-out, and provides information about each consumer. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "43943f49-898e-4f5b-94f3-a72095ee12a1",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "ListStreamConsumers",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "df5d764f-e686-7b49-bdbe-fa3f3565f14b",
  "userAgent": "Boto3/1.36.2 md/Botocore#1.36.3 ua/2.0 os/linux#6.1.176-221.360.amzn2023.x86_64 md/arch#x86_64 lang/python#3.12.3 md/pyimpl#CPython cfg/retry-mode#legacy Botocore/1.36.3",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.control-kinesis.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Kinesis::Stream",
      "ARN": "arn:aws:kinesis:us-east-1:123456789012:stream/EXAMPLE"
    }
  ]
}

ListStreams

#
Service
kinesis

Description

Lists your Kinesis data streams.

Example CloudTrail Event #

{
  "awsRegion": "ap-southeast-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: kinesis:ListStreams",
  "eventCategory": "Management",
  "eventID": "6b8e3a4e-998c-4eb1-b0df-2d49b61a816b",
  "eventName": "ListStreams",
  "eventSource": "kinesis.amazonaws.com",
  "eventTime": "2021-04-13T11:35:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "d734aa90-316a-41cc-8fdb-2eabecbbe8bb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListTagsForResource

#
Service
kinesis

Description

List all tags added to the specified Kinesis resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTagsForStream

#
Service
kinesis

Description

Lists the tags for the specified Kinesis data stream. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c70fb538-a35b-48a0-b87a-03c17e92bd08",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "ListTagsForStream",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f04f4295-99d2-fffd-92ac-aced2f62dfdb",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "kinesis.us-west-2.amazonaws.com"
  },
  "resources": [
    {
      "type": "AWS::Kinesis::Stream",
      "ARN": "arn:aws:kinesis:us-west-2:123456789012:stream/EXAMPLE"
    }
  ]
}

MergeShards

#
Service
kinesis

Description

Merges two adjacent shards in a Kinesis data stream and combines them into a single shard to reduce the stream's capacity to ingest and transport data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutRecord

#
Service
kinesis

Description

Writes a single data record into an Amazon Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutRecords

#
Service
kinesis

Description

Writes multiple data records into a Kinesis data stream in a single call (also referred to as a PutRecords request). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutResourcePolicy

#
Service
kinesis

Description

Attaches a resource-based policy to a data stream or registered consumer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RegisterStreamConsumer

#
Service
kinesis

Description

Registers a consumer with a Kinesis data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveTagsFromStream

#
Service
kinesis

Description

Removes tags from the specified Kinesis data stream. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "19d64cea-87ea-4635-a511-ab4a50387e2c",
  "eventSource": "kinesis.amazonaws.com",
  "eventName": "RemoveTagsFromStream",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "dcb83be9-a1ee-c839-be5a-c830d1a29ba2",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/5.100.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.36.3 ua/2.1 os/linux lang/go#1.23.10 md/GOOS#linux md/GOARCH#arm64 api/kinesis#1.35.1 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "kinesis.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "type": "AWS::Kinesis::Stream",
      "ARN": "arn:aws:kinesis:us-east-1:123456789012:stream/EXAMPLE"
    }
  ]
}

SplitShard

#
Service
kinesis

Description

Splits a shard into two new shards in the Kinesis data stream, to increase the stream's capacity to ingest and transport data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartStreamEncryption

#
Service
kinesis

Description

Enables or updates server-side encryption using an Amazon Web Services KMS key for a specified stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StopStreamEncryption

#
Service
kinesis

Description

Disables server-side encryption for a specified stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

SubscribeToShard

#
Service
kinesis

Description

This operation establishes an HTTP/2 connection between the consumer you specify in the ConsumerARN parameter and the shard you specify in the ShardId parameter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
kinesis

Description

Adds or updates tags for the specified Kinesis resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
kinesis

Description

Removes tags from the specified Kinesis resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAccountSettings

#
Service
kinesis

Description

Updates the account-level settings for Amazon Kinesis Data Streams. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateMaxRecordSize

#
Service
kinesis

Description

This allows you to update the MaxRecordSize of a single record that you can write to, and read from a stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateShardCount

#
Service
kinesis

Description

Updates the shard count of the specified stream to the specified number of shards. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateStreamMode

#
Service
kinesis

Description

Updates the capacity mode of the data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateStreamWarmThroughput

#
Service
kinesis

Description

Updates the warm throughput configuration for the specified Amazon Kinesis Data Streams on-demand data stream. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.