AWS Lake Formation

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Lake Formation rules that match the service but not a specific eventName.NN
AddLFTagsToResourceAttaches one or more LF-tags to an existing resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssumeDecoratedRoleWithSAMLAllows a caller to assume an IAM role decorated as the SAML user specified in the SAML assertion included in the request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
BatchGrantPermissionsBatch operation to grant permissions to the principal. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
BatchRevokePermissionsBatch operation to revoke permissions from the principal. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CancelTransactionAttempts to cancel the specified transaction. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CommitTransactionAttempts to commit the specified transaction. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateDataCellsFilterCreates a data cell filter to allow one to grant access to certain columns on certain rows. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLakeFormationIdentityCenterConfigurationCreates an IAM Identity Center connection with Lake Formation to allow IAM Identity Center users and groups to access Data Catalog resources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLakeFormationOptInEnforce Lake Formation permissions for the given databases, tables, and principals. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLFTagCreates an LF-tag with the specified name and values. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateLFTagExpressionCreates a new LF-Tag expression with the provided name, description, catalog ID, and expression body. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteDataCellsFilterDeletes a data cell filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteLakeFormationIdentityCenterConfigurationDeletes an IAM Identity Center connection with Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteLakeFormationOptInRemove the Lake Formation permissions enforcement of the given databases, tables, and principals. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteLFTagDeletes an LF-tag by its key name. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteLFTagExpressionDeletes the LF-Tag expression. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteObjectsOnCancelFor a specific governed table, provides a list of Amazon S3 objects that will be written during the current transaction and that can be automatically deleted if the transaction is canceled. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeregisterResourceDeregisters the resource as managed by the Data Catalog. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLakeFormationIdentityCenterConfigurationRetrieves the instance ARN and application ARN for the connection. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeResourceRetrieves the current data access role for the given resource registered in Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeTransactionReturns the details of a single transaction. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ExtendTransactionIndicates to the service that the specified transaction is still active and should not be treated as idle and aborted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetDataCellsFilterReturns a data cells filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetDataLakePrincipalReturns the identity of the invoking principal. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetDataLakeSettingsRetrieves the list of the data lake administrators of a Lake Formation-managed data lake. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetEffectivePermissionsForPathReturns the Lake Formation permissions for a specified table or database resource located at a path in Amazon S3. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetLFTagReturns an LF-tag definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetLFTagExpressionReturns the details about the LF-Tag expression. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetQueryStateReturns the state of a query previously submitted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetQueryStatisticsRetrieves statistics on the planning and execution of a query. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetResourceLFTagsReturns the LF-tags applied to a resource. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetTableObjectsReturns the set of Amazon S3 objects that make up the specified governed table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTemporaryDataLocationCredentialsAllows a user or application in a secure environment to access data in a specific Amazon S3 location registered with Lake Formation by providing temporary scoped credentials that are limited to the requested data location and the caller's a. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTemporaryGluePartitionCredentialsThis API is identical to GetTemporaryTableCredentials except that this is used when the target Data Catalog resource is of type Partition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTemporaryGlueTableCredentialsAllows a caller in a secure environment to assume a role with permission to access Amazon S3. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetWorkUnitResultsReturns the work units resulting from the query. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetWorkUnitsRetrieves the work units generated by the StartQueryPlanning operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GrantPermissionsGrants permissions to the principal to access metadata in the Data Catalog and data organized in underlying data storage such as Amazon S3. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListDataCellsFilterLists all the data cell filters on a table. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListLakeFormationOptInsRetrieve the current list of resources and principals that are opt in to enforce Lake Formation permissions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListLFTagExpressionsReturns the LF-Tag expressions in caller’s account filtered based on caller's permissions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListLFTagsLists LF-tags that the requester has permission to view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListPermissionsReturns a list of the principal permissions on the resource, filtered by the permissions of the caller. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListResourcesLists the resources registered to be managed by the Data Catalog. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTableStorageOptimizersReturns the configuration of all storage optimizers associated with a specified table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTransactionsReturns metadata about transactions and their status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutDataLakeSettingsSets the list of data lake administrators who have admin privileges on all resources managed by Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RegisterResourceRegisters the resource as managed by the Data Catalog. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RemoveLFTagsFromResourceRemoves an LF-tag from the resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RevokePermissionsRevokes permissions to the principal to access metadata in the Data Catalog and data organized in underlying data storage such as Amazon S3. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
SearchDatabasesByLFTagsThis operation allows a search on DATABASE resources by TagCondition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
SearchTablesByLFTagsThis operation allows a search on TABLE resources by LFTags. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartQueryPlanningSubmits a request to process a query statement. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartTransactionStarts a new transaction and returns its transaction ID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDataCellsFilterUpdates a data cell filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLakeFormationIdentityCenterConfigurationUpdates the IAM Identity Center connection parameters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLFTagUpdates the list of possible values for the specified LF-tag key. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLFTagExpressionUpdates the name of the LF-Tag expression to the new description and expression body provided. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateResourceUpdates the data access role used for vending access to the given (registered) resource in Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTableObjectsUpdates the manifest of Amazon S3 objects that make up the specified governed table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTableStorageOptimizerUpdates the configuration of the storage optimizers for a table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: AWS Lake Formation (catch-all)

#
Service
lakeformation

Description

Catch-all entry for AWS Lake Formation rules that match the service but not a specific eventName.

AddLFTagsToResource

#
Service
lakeformation

Description

Attaches one or more LF-tags to an existing resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssumeDecoratedRoleWithSAML

#
Service
lakeformation

Description

Allows a caller to assume an IAM role decorated as the SAML user specified in the SAML assertion included in the request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

BatchGrantPermissions

#
Service
lakeformation

Description

Batch operation to grant permissions to the principal. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

BatchRevokePermissions

#
Service
lakeformation

Description

Batch operation to revoke permissions from the principal. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CancelTransaction

#
Service
lakeformation

Description

Attempts to cancel the specified transaction. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CommitTransaction

#
Service
lakeformation

Description

Attempts to commit the specified transaction. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateDataCellsFilter

#
Service
lakeformation

Description

Creates a data cell filter to allow one to grant access to certain columns on certain rows. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLakeFormationIdentityCenterConfiguration

#
Service
lakeformation

Description

Creates an IAM Identity Center connection with Lake Formation to allow IAM Identity Center users and groups to access Data Catalog resources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLakeFormationOptIn

#
Service
lakeformation

Description

Enforce Lake Formation permissions for the given databases, tables, and principals. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLFTag

#
Service
lakeformation

Description

Creates an LF-tag with the specified name and values. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateLFTagExpression

#
Service
lakeformation

Description

Creates a new LF-Tag expression with the provided name, description, catalog ID, and expression body. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteDataCellsFilter

#
Service
lakeformation

Description

Deletes a data cell filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteLakeFormationIdentityCenterConfiguration

#
Service
lakeformation

Description

Deletes an IAM Identity Center connection with Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteLakeFormationOptIn

#
Service
lakeformation

Description

Remove the Lake Formation permissions enforcement of the given databases, tables, and principals. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteLFTag

#
Service
lakeformation

Description

Deletes an LF-tag by its key name. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteLFTagExpression

#
Service
lakeformation

Description

Deletes the LF-Tag expression. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteObjectsOnCancel

#
Service
lakeformation

Description

For a specific governed table, provides a list of Amazon S3 objects that will be written during the current transaction and that can be automatically deleted if the transaction is canceled. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeregisterResource

#
Service
lakeformation

Description

Deregisters the resource as managed by the Data Catalog. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLakeFormationIdentityCenterConfiguration

#
Service
lakeformation

Description

Retrieves the instance ARN and application ARN for the connection. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "08fb6c08-1dd0-4dd7-abb4-d594b29eda94",
  "eventSource": "lakeformation.amazonaws.com",
  "eventName": "DescribeLakeFormationIdentityCenterConfiguration",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e4f5a3a3-e12c-48a2-8dbd-772d194c91e2",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "EntityNotFoundException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

DescribeResource

#
Service
lakeformation

Description

Retrieves the current data access role for the given resource registered in Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeTransaction

#
Service
lakeformation

Description

Returns the details of a single transaction. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ExtendTransaction

#
Service
lakeformation

Description

Indicates to the service that the specified transaction is still active and should not be treated as idle and aborted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetDataCellsFilter

#
Service
lakeformation

Description

Returns a data cells filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetDataLakePrincipal

#
Service
lakeformation

Description

Returns the identity of the invoking principal. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e4c34d63-f791-4765-aa46-dcb757b52559",
  "eventSource": "lakeformation.amazonaws.com",
  "eventName": "GetDataLakePrincipal",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "eb9f496e-0a9a-4d8f-b945-1c30532b8253",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
  }
}

GetDataLakeSettings

#
Service
lakeformation

Description

Retrieves the list of the data lake administrators of a Lake Formation-managed data lake. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetEffectivePermissionsForPath

#
Service
lakeformation

Description

Returns the Lake Formation permissions for a specified table or database resource located at a path in Amazon S3. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6b3525c9-f411-4353-8cb6-73483e82f900",
  "eventSource": "lakeformation.amazonaws.com",
  "eventName": "GetEffectivePermissionsForPath",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c158697d-a034-445d-9ee3-561acad0c180",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
  }
}

GetLFTag

#
Service
lakeformation

Description

Returns an LF-tag definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetLFTagExpression

#
Service
lakeformation

Description

Returns the details about the LF-Tag expression. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetQueryState

#
Service
lakeformation

Description

Returns the state of a query previously submitted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetQueryStatistics

#
Service
lakeformation

Description

Retrieves statistics on the planning and execution of a query. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetResourceLFTags

#
Service
lakeformation

Description

Returns the LF-tags applied to a resource. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e9c5de50-1271-4bb8-ace1-aeee1790822b",
  "eventSource": "lakeformation.amazonaws.com",
  "eventName": "GetResourceLFTags",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b1536c10-6f21-49c7-8a95-98d359985caf",
  "userAgent": "aws-sdk-java/2.46.8 md/io#sync md/http#UrlConnection md/internal ua/2.1 api/LakeFormation#2.42.x os/Linux#5.10.255-259-299.1043.amzn2.x86_64 lang/java#17.0.20 md/OpenJDK_64-Bit_Server_VM#17.0.20+8-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.1.21-release-317 exec-env/AWS_Lambda_java17 m/E,e",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-2.amazonaws.com"
  }
}

GetTableObjects

#
Service
lakeformation

Description

Returns the set of Amazon S3 objects that make up the specified governed table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTemporaryDataLocationCredentials

#
Service
lakeformation

Description

Allows a user or application in a secure environment to access data in a specific Amazon S3 location registered with Lake Formation by providing temporary scoped credentials that are limited to the requested data location and the caller's a. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTemporaryGluePartitionCredentials

#
Service
lakeformation

Description

This API is identical to GetTemporaryTableCredentials except that this is used when the target Data Catalog resource is of type Partition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTemporaryGlueTableCredentials

#
Service
lakeformation

Description

Allows a caller in a secure environment to assume a role with permission to access Amazon S3. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetWorkUnitResults

#
Service
lakeformation

Description

Returns the work units resulting from the query. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetWorkUnits

#
Service
lakeformation

Description

Retrieves the work units generated by the StartQueryPlanning operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GrantPermissions

#
Service
lakeformation

Description

Grants permissions to the principal to access metadata in the Data Catalog and data organized in underlying data storage such as Amazon S3. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListDataCellsFilter

#
Service
lakeformation

Description

Lists all the data cell filters on a table. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "13c9e1ee-09a7-4b88-9847-9d99f049c07b",
  "eventSource": "lakeformation.amazonaws.com",
  "eventName": "ListDataCellsFilter",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "2cc1ec35-e512-4e40-bd23-4cd63516966d",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListLakeFormationOptIns

#
Service
lakeformation

Description

Retrieve the current list of resources and principals that are opt in to enforce Lake Formation permissions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListLFTagExpressions

#
Service
lakeformation

Description

Returns the LF-Tag expressions in caller’s account filtered based on caller's permissions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListLFTags

#
Service
lakeformation

Description

Lists LF-tags that the requester has permission to view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListPermissions

#
Service
lakeformation

Description

Returns a list of the principal permissions on the resource, filtered by the permissions of the caller. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5798e2b1-d017-479d-bc74-510dca4ae9c0",
  "eventSource": "lakeformation.amazonaws.com",
  "eventName": "ListPermissions",
  "awsRegion": "ca-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ea2aad20-35a4-4cb6-9edd-7e28ddb46f37",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ca-west-1.amazonaws.com"
  }
}

ListResources

#
Service
lakeformation

Description

Lists the resources registered to be managed by the Data Catalog. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTableStorageOptimizers

#
Service
lakeformation

Description

Returns the configuration of all storage optimizers associated with a specified table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTransactions

#
Service
lakeformation

Description

Returns metadata about transactions and their status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutDataLakeSettings

#
Service
lakeformation

Description

Sets the list of data lake administrators who have admin privileges on all resources managed by Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RegisterResource

#
Service
lakeformation

Description

Registers the resource as managed by the Data Catalog. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RemoveLFTagsFromResource

#
Service
lakeformation

Description

Removes an LF-tag from the resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RevokePermissions

#
Service
lakeformation

Description

Revokes permissions to the principal to access metadata in the Data Catalog and data organized in underlying data storage such as Amazon S3. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

SearchDatabasesByLFTags

#
Service
lakeformation

Description

This operation allows a search on DATABASE resources by TagCondition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

SearchTablesByLFTags

#
Service
lakeformation

Description

This operation allows a search on TABLE resources by LFTags. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartQueryPlanning

#
Service
lakeformation

Description

Submits a request to process a query statement. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartTransaction

#
Service
lakeformation

Description

Starts a new transaction and returns its transaction ID. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDataCellsFilter

#
Service
lakeformation

Description

Updates a data cell filter. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLakeFormationIdentityCenterConfiguration

#
Service
lakeformation

Description

Updates the IAM Identity Center connection parameters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLFTag

#
Service
lakeformation

Description

Updates the list of possible values for the specified LF-tag key. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLFTagExpression

#
Service
lakeformation

Description

Updates the name of the LF-Tag expression to the new description and expression body provided. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateResource

#
Service
lakeformation

Description

Updates the data access role used for vending access to the given (registered) resource in Lake Formation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTableObjects

#
Service
lakeformation

Description

Updates the manifest of Amazon S3 objects that make up the specified governed table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTableStorageOptimizer

#
Service
lakeformation

Description

Updates the configuration of the storage optimizers for a table. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.