CloudWatch Logs
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for CloudWatch Logs rules that match the service but not a specific eventName. | N | N |
| Delete | Deletes the specified CloudWatch Logs log group and all its associated log streams, subscription filters, metric filters, and retention policies. | Y | Y |
| Delete | Deletes the specified log stream and permanently deletes all the archived log events associated with the log stream. | Y | Y |
| Associate | Associates the specified KMS key with either one log group in the account, or with all stored CloudWatch Logs query insights results in the account. | N | N |
| Associate | Associates a data source with an S3 Table Integration for query access in the 'logs' namespace. | N | N |
| Cancel | Cancels the specified export task. | Y | N |
| Cancel | Cancels an active import task and stops importing data from the CloudTrail Lake Event Data Store. | Y | N |
| Create | Creates a delivery. | N | N |
| Create | Creates an export task so that you can efficiently export data from a log group to an Amazon S3 bucket. | Y | N |
| Create | Starts an import from a data source to CloudWatch Log and creates a managed log group as the destination for the imported data. | N | N |
| Create | Creates an anomaly detector that regularly scans one or more log groups and look for patterns and anomalies in the logs. | Y | N |
| Create | Creates a log group with the specified name. | Y | N |
| Create | Creates a log stream for the specified log group. | Y | N |
| Create | Creates a lookup table by uploading CSV data. | N | N |
| Create | Creates a scheduled query that runs CloudWatch Logs Insights queries at regular intervals. | N | N |
| Delete | Deletes a CloudWatch Logs account policy. | Y | N |
| Delete | Deletes the data protection policy from the specified log group. | Y | N |
| Delete | Deletes a delivery. | Y | N |
| Delete | Deletes a delivery destination. | Y | N |
| Delete | Deletes a delivery destination policy. | Y | N |
| Delete | Deletes a delivery source. | Y | N |
| Delete | Deletes the specified destination, and eventually disables all the subscription filters that publish to it. | Y | N |
| Delete | Deletes a log-group level field index policy that was applied to a single log group. | Y | N |
| Delete | Deletes the integration between CloudWatch Logs and OpenSearch Service. | Y | N |
| Delete | Deletes the specified CloudWatch Logs anomaly detector. | Y | N |
| Delete | Deletes a lookup table permanently. | N | N |
| Delete | Deletes the specified metric filter. | Y | N |
| Delete | Deletes a saved CloudWatch Logs Insights query definition. | Y | N |
| Delete | Deletes a resource policy from this account. | Y | N |
| Delete | Deletes the specified retention policy. | Y | N |
| Delete | Deletes a scheduled query and stops all future executions. | Y | N |
| Delete | Deletes the specified subscription filter. | Y | N |
| Delete | Deletes a syslog configuration for a log group. | Y | N |
| Delete | Deletes the log transformer for the specified log group. | Y | N |
| Describe | Returns a list of all CloudWatch Logs account policies in the account. | Y | N |
| Describe | Use this operation to return the valid and default values that are used when creating delivery sources, delivery destinations, and deliveries. | Y | N |
| Describe | Retrieves a list of the deliveries that have been created in the account. | Y | N |
| Describe | Retrieves a list of the delivery destinations that have been created in the account. | Y | N |
| Describe | Retrieves a list of the delivery sources that have been created in the account. | Y | N |
| Describe | Lists all your destinations. | Y | N |
| Describe | Lists the specified export tasks. | Y | N |
| Describe | Returns a list of custom and default field indexes which are discovered in log data. | Y | N |
| Describe | Gets detailed information about the individual batches within an import task, including their status and any error messages. | Y | N |
| Describe | Lists and describes import tasks, with optional filtering by import status and source ARN. | Y | N |
| Describe | Returns the field index policies of the specified log group. | Y | N |
| Describe | Returns information about log groups, including data sources that ingest into each log group. | Y | N |
| Describe | Lists the log streams for the specified log group. | Y | N |
| Describe | Retrieves metadata about lookup tables in your account. | Y | N |
| Describe | Lists the specified metric filters. | Y | N |
| Describe | Returns a list of CloudWatch Logs Insights queries that are scheduled, running, or have been run recently in this account. | Y | N |
| Describe | This operation returns a paginated list of your saved CloudWatch Logs Insights query definitions. | Y | N |
| Describe | Lists the resource policies in this account. | Y | N |
| Describe | Lists the subscription filters for the specified log group. | Y | N |
| Disassociate | Disassociates the specified KMS key from the specified log group or from all CloudWatch Logs Insights query results in the account. | Y | N |
| Disassociate | Disassociates a data source from an S3 Table Integration, removing query access and deleting all associated data from the integration. | Y | N |
| Filter | Lists log events from the specified log group. | N | N |
| Get | Returns information about a log group data protection policy. | Y | N |
| Get | Returns complete information about one logical delivery. | Y | N |
| Get | Retrieves complete information about one delivery destination. | Y | N |
| Get | Retrieves the delivery destination policy assigned to the delivery destination that you specify. | Y | N |
| Get | Retrieves complete information about one delivery source. | Y | N |
| Get | Returns information about one integration between CloudWatch Logs and OpenSearch Service. | Y | N |
| Get | Retrieves information about the log anomaly detector that you specify. | N | N |
| Get | Lists log events from the specified log stream. | N | N |
| Get | Discovers available fields for a specific data source and type. | Y | N |
| Get | Returns a list of the fields that are included in log events in the specified log group. | Y | N |
| Get | Retrieves a large logging object (LLO) and streams it back. | N | N |
| Get | Retrieves all of the fields and values of a single log event. | Y | N |
| Get | Retrieves the full content of a lookup table, including the CSV data. | N | N |
| Get | Returns the results from the specified query. | N | N |
| Get | Retrieves details about a specific scheduled query, including its configuration, execution status, and metadata. | Y | N |
| Get | Retrieves the execution history of a scheduled query within a specified time range, including query results and destination processing status. | Y | N |
| Get | Returns the information about the log transformer associated with this log group. | Y | N |
| List | Returns an aggregate summary of all log groups in the Region grouped by specified data source characteristics. | Y | N |
| List | Returns a list of anomalies that log anomaly detectors have found. | Y | N |
| List | Returns a list of integrations between CloudWatch Logs and other services in this account. | Y | N |
| List | Retrieves a list of the log anomaly detectors in the account. | Y | N |
| List | Returns a list of log groups in the Region in your account. | Y | N |
| List | Returns a list of the log groups that were analyzed during a single CloudWatch Logs Insights query. | Y | N |
| List | Lists all scheduled queries in your account and region. | Y | N |
| List | Returns a list of data source associations for a specified S3 Table Integration, showing which data sources are currently associated for query access. | Y | N |
| List | Returns a list of syslog configurations. | Y | N |
| List | Displays the tags associated with a CloudWatch Logs resource. | N | N |
| List | The ListTagsLogGroup operation is on the path to deprecation. | Y | N |
| Put | Creates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combinat. | Y | N |
| Put | Enables or disables bearer token authentication for the specified log group. | N | N |
| Put | Creates a data protection policy for the specified log group. | Y | N |
| Put | Creates or updates a logical delivery destination. | N | N |
| Put | Creates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account. | N | N |
| Put | Creates or updates a logical delivery source. | N | N |
| Put | Creates or updates a destination. | N | N |
| Put | Creates or updates an access policy associated with an existing destination. | N | N |
| Put | Creates or updates a field index policy for the specified log group. | Y | N |
| Put | Creates an integration between CloudWatch Logs and another service in this account. | N | N |
| Put | Uploads a batch of log events to the specified log stream. | N | N |
| Put | Enables or disables deletion protection for the specified log group. | Y | N |
| Put | Creates or updates a metric filter and associates it with the specified log group. | Y | N |
| Put | Creates or updates a query definition for CloudWatch Logs Insights. | Y | N |
| Put | Creates or updates a resource policy allowing other Amazon Web Services services to put log events to this account, such as Amazon Route 53. | Y | N |
| Put | Sets the retention of the specified log group. | Y | N |
| Put | Creates or updates a subscription filter and associates it with the specified log group. | N | N |
| Put | Creates or updates a syslog configuration for a log group. | N | N |
| Put | Creates or updates a log transformer for a single log group. | Y | N |
| Start | Starts a Live Tail streaming session for one or more log groups. | N | N |
| Start | Starts a query of one or more log groups or data sources using CloudWatch Logs Insights. | Y | N |
| Stop | Stops a CloudWatch Logs Insights query that is in progress. | Y | N |
| Tag | The TagLogGroup operation is on the path to deprecation. | Y | N |
| Tag | Assigns one or more tags (key-value pairs) to the specified CloudWatch Logs resource. | Y | N |
| Test | Tests the filter pattern of a metric filter against a sample of log event messages. | Y | N |
| Test | Use this operation to test a log transformer. | Y | N |
| Untag | The UntagLogGroup operation is on the path to deprecation. | Y | N |
| Untag | Removes one or more tags from the specified resource. | Y | N |
| Update | Use this operation to suppress anomaly detection for a specified anomaly or pattern. | N | N |
| Update | Use this operation to update the configuration of a delivery to change either the S3 path pattern or the format of the delivered logs. | Y | N |
| Update | Updates an existing log anomaly detector. | N | N |
| Update | Updates an existing lookup table by replacing all of its CSV content. | N | N |
| Update | Updates an existing scheduled query with new configuration. | Y | N |
| Get | Returns the storage tier policy for the account. | N | N |
| Put | Sets the storage tier policy for the account. | N | N |
any: CloudWatch Logs (catch-all)
#Description
Catch-all entry for CloudWatch Logs rules that match the service but not a specific eventName.
DeleteLogGroup
#Description
Deletes the specified CloudWatch Logs log group and all its associated log streams, subscription filters, metric filters, and retention policies.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "349b65f9-1932-4258-a52e-476cf4fcf6d7",
"eventName": "DeleteLogGroup",
"eventSource": "logs.amazonaws.com",
"eventTime": "2023-07-10T12:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "0314119b-6da8-4d0c-a5fa-e3e84c1b89b3",
"requestParameters": {
"logGroupName": "/stratus-red-team/vpc-flow-logs"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (splunk rule field) | eq | success | 1 rule | splunk |
userAgent (splunk rule field) | ne | console.amazonaws.com | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1562, T1562.001, T1562.008Splunk #
DeleteLogGroup events in CloudTrail logs. This method leverages Amazon Security Lake logs parsed in the OCSF format. The activity is…T1685, T1685.002DeleteLogGroup events in CloudTrail logs. This detection leverages CloudTrail data to monitor for successful log group deletions, excluding…T1685, T1685.002Kusto #
T1562, T1562.008YARA-L #
T1562
References #
DeleteLogStream
#Description
Deletes the specified log stream and permanently deletes all the archived log events associated with the log stream.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-2",
"eventCategory": "Management",
"eventID": "561c3f4e-17ca-4438-b15d-29903baf7b13",
"eventName": "DeleteLogStream",
"eventSource": "logs.amazonaws.com",
"eventTime": "2022-07-20T21:09:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "2d7e859e-d697-426f-8b56-c4c11c4055f3",
"requestParameters": {
"logGroupName": "test-logs",
"logStreamName": "20150601"
},
"responseElements": null,
"sourceIPAddress": "67.171.71.185",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "logs.us-west-2.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off command/logs.delete-log-stream",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLFLKADUVG",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"principalId": "AIDAYTOGP2RLI4PXTGCEU",
"type": "IAMUser",
"userName": "gowthamaraj_cli"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1562, T1562.001, T1562.008Splunk #
T1685, T1685.002
References #
AssociateKmsKey
#Description
Associates the specified KMS key with either one log group in the account, or with all stored CloudWatch Logs query insights results in the account.
AssociateSourceToS3TableIntegration
#Description
Associates a data source with an S3 Table Integration for query access in the 'logs' namespace.
CancelExportTask
#Description
Cancels the specified export task.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified export task does not exist.",
"eventCategory": "Management",
"eventID": "c6468857-9dc8-46fa-8033-5c8913f8b786",
"eventName": "CancelExportTask",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b61dc63e-5c7f-4872-aa52-b2b01ca09790",
"requestParameters": {
"taskId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelImportTask
#Description
Cancels an active import task and stops importing data from the CloudTrail Lake Event Data Store.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "ImportId must be a valid UUID format",
"eventCategory": "Management",
"eventID": "22f89250-6e9a-48c6-a331-c617c46c2b9e",
"eventName": "CancelImportTask",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "93035088-71f2-4eca-a051-d6c38695939e",
"requestParameters": {
"importId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDelivery
#Description
Creates a delivery.
CreateExportTask
#Description
Creates an export task so that you can efficiently export data from a log group to an Amazon S3 bucket.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "10cd4043-609b-4855-b6a9-99cb90e37999",
"eventName": "CreateExportTask",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T18:34:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "1cb2c82e-b8d8-484a-82f3-08fb42aebdc9",
"requestParameters": {
"destination": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
"destinationPrefix": "random123",
"from": 1625589900000,
"logGroupName": "/aws/eks/Cluster_Galah/cluster",
"taskName": "/aws/eks/Cluster_Galah/cluster-1625682879241",
"to": 1625678040000
},
"responseElements": {
"taskId": "db3f519b-751d-4abe-b251-daa32185c9dc"
},
"sourceIPAddress": "213.205.197.162",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37TTBU6EGN",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
CreateImportTask
#Description
Starts an import from a data source to CloudWatch Log and creates a managed log group as the destination for the imported data.
CreateLogAnomalyDetector
#Description
Creates an anomaly detector that regularly scans one or more log groups and look for patterns and anomalies in the logs.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b4fb147e-8bb3-43c4-ac5e-26794663aefd",
"eventName": "CreateLogAnomalyDetector",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:04:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1f7ca173-3500-42a4-a24c-4019fcc7ae28",
"requestParameters": {
"detectorName": "dwfix-ad",
"logGroupArnList": [
"arn:aws:logs:us-west-1:123456789012:log-group:dwfix-lg2"
]
},
"responseElements": {
"anomalyDetectorArn": "arn:aws:logs:us-west-1:123456789012:anomaly-detector:a72549c0-450b-429c-b9aa-c636f899356b"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateLogGroup
#Description
Creates a log group with the specified name.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a46276b9-dd85-4736-b9df-6210c69aa8e7",
"eventName": "CreateLogGroup",
"eventSource": "logs.amazonaws.com",
"eventTime": "2023-07-10T12:02:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "2aace905-794c-47bb-b7c9-9f0267d13535",
"requestParameters": {
"logGroupName": "/stratus-red-team/vpc-flow-logs",
"tags": {
"StratusRedTeam": "true"
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateLogStream
#Description
Creates a log stream for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "afa163a7-c50a-48a6-bf64-2e76906ebe93",
"eventName": "CreateLogStream",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T13:17:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "d9d5811c-3a6b-45b6-b157-84ffc0d036ab",
"requestParameters": {
"logGroupName": "aws-cloudtrail-logs-Trail01",
"logStreamName": "797507667711_CloudTrail_us-east-2"
},
"responseElements": null,
"sourceIPAddress": "cloudtrail.amazonaws.com",
"userAgent": "cloudtrail.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37QBDGCRN3",
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/CloudTrail_CloudWatchLogs_Role/CloudTrail",
"invokedBy": "cloudtrail.amazonaws.com",
"principalId": "AROA3TLZJI375OOYMRDNV:CloudTrail",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T13:17:56Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/service-role/CloudTrail_CloudWatchLogs_Role",
"principalId": "AROA3TLZJI375OOYMRDNV",
"type": "Role",
"userName": "CloudTrail_CloudWatchLogs_Role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
CreateLookupTable
#Description
Creates a lookup table by uploading CSV data.
CreateScheduledQuery
#Description
Creates a scheduled query that runs CloudWatch Logs Insights queries at regular intervals.
DeleteAccountPolicy
#Description
Deletes a CloudWatch Logs account policy.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Specified resource does not exists!",
"eventCategory": "Management",
"eventID": "c9a428c8-b00c-4632-9593-a59a595770de",
"eventName": "DeleteAccountPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cc89f62d-4747-4511-bf73-4e6d6133db9f",
"requestParameters": {
"dryRun": false,
"policyName": "dw-probe",
"policyType": "DATA_PROTECTION_POLICY"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDataProtectionPolicy
#Description
Deletes the data protection policy from the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Log group 'ddddd' for owner '123456789012' cannot be found",
"eventCategory": "Management",
"eventID": "adb2de80-3c1d-4f5f-ab98-b01396cd8a96",
"eventName": "DeleteDataProtectionPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cff46c64-1ed9-44fe-8a9f-4a8c0a45caa7",
"requestParameters": {
"logGroupIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDelivery
#Description
Deletes a delivery.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery does not exist in this account.",
"eventCategory": "Management",
"eventID": "80f567f8-e821-47f5-816a-d185ec996a3c",
"eventName": "DeleteDelivery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "69614889-f3e5-4e85-b1be-6ff48fa76954",
"requestParameters": {
"id": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDeliveryDestination
#Description
Deletes a delivery destination.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery Destination does not exist in this account.",
"eventCategory": "Management",
"eventID": "c0a2c6ab-d5fa-4982-bc2b-5049b4c06dd6",
"eventName": "DeleteDeliveryDestination",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b4e954a7-1b78-42cb-bdbe-12474f65bb90",
"requestParameters": {
"name": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDeliveryDestinationPolicy
#Description
Deletes a delivery destination policy.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery Destination does not exist in this account.",
"eventCategory": "Management",
"eventID": "46ced92b-d9be-404f-ac2f-386bee7a7563",
"eventName": "DeleteDeliveryDestinationPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8e85a083-59e7-4927-8e99-297ba89aeadd",
"requestParameters": {
"deliveryDestinationName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDeliverySource
#Description
Deletes a delivery source.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery Source does not exist in this account.",
"eventCategory": "Management",
"eventID": "beb008b1-9d47-47fd-9035-f162a36f70c0",
"eventName": "DeleteDeliverySource",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ea5624c2-3e29-4b72-b932-569ecb97e6ee",
"requestParameters": {
"name": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDestination
#Description
Deletes the specified destination, and eventually disables all the subscription filters that publish to it.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified destination does not exist.",
"eventCategory": "Management",
"eventID": "1934af0a-390c-4bcb-bfc7-efee5ee414f7",
"eventName": "DeleteDestination",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ee325210-1017-4381-8f96-c5d2451c0a74",
"requestParameters": {
"destinationName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIndexPolicy
#Description
Deletes a log-group level field index policy that was applied to a single log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Log group cannot be found.",
"eventCategory": "Management",
"eventID": "4b98db06-c3fd-41ef-a370-0eda18b84f7e",
"eventName": "DeleteIndexPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8d52b5a0-c2fa-4f3c-a61e-7fc895551a3f",
"requestParameters": {
"logGroupIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIntegration
#Description
Deletes the integration between CloudWatch Logs and OpenSearch Service.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Integration with name ddddd does not exist.",
"eventCategory": "Management",
"eventID": "248be184-cc92-4164-9592-50e05deb49b9",
"eventName": "DeleteIntegration",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "926b7d02-8fef-4315-80ab-98dcd8c3e2ac",
"requestParameters": {
"force": false,
"integrationName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLogAnomalyDetector
#Description
Deletes the specified CloudWatch Logs anomaly detector.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2d24447f-86e4-4478-ae71-50245d6200d2",
"eventName": "DeleteLogAnomalyDetector",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:04:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5706580f-5a3b-42ba-8a85-fe5518bbd775",
"requestParameters": {
"anomalyDetectorArn": "arn:aws:logs:us-west-1:123456789012:anomaly-detector:a72549c0-450b-429c-b9aa-c636f899356b"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLookupTable
#Description
Deletes a lookup table permanently.
DeleteMetricFilter
#Description
Deletes the specified metric filter.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "25bfc4fd-0249-4bde-8631-7bfd9464c13f",
"eventName": "DeleteMetricFilter",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:12:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "afeb6aa7-a5b4-4cca-b365-8a8fd1fec2c2",
"requestParameters": {
"filterName": "dw",
"logGroupName": "dwfix-lg"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteQueryDefinition
#Description
Deletes a saved CloudWatch Logs Insights query definition.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Query definition id is invalid. (Service: AWSLogs; Status Code: 400; Error Code: ResourceNotFoundException; Request ID: 8dd0be3d-7c0c-46df-bd18-ac6484b8922e; Proxy: null)",
"eventCategory": "Management",
"eventID": "44b53490-a0ba-4473-bca1-abd354e4bcb7",
"eventName": "DeleteQueryDefinition",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "82593d38-82ad-4225-921e-e5c59d51946b",
"requestParameters": {
"queryDefinitionId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteResourcePolicy
#Description
Deletes a resource policy from this account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "DeleteResourcePolicy request must contain policy name or resource arn.",
"eventCategory": "Management",
"eventID": "673a535b-b69c-4068-9256-9b6bb6e55454",
"eventName": "DeleteResourcePolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:45:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "37554653-f4cd-4102-a7b9-292b7f5198f0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRetentionPolicy
#Description
Deletes the specified retention policy.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a9c982a6-9079-4dbb-b611-f32075d64e01",
"eventName": "DeleteRetentionPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:12:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b48cad33-73a4-4345-974c-dde625dac053",
"requestParameters": {
"logGroupName": "dwfix-lg"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteScheduledQuery
#Description
Deletes a scheduled query and stops all future executions.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Scheduled query with identifier ddddd not found",
"eventCategory": "Management",
"eventID": "aca26b66-b897-4af5-b593-67a5c652861e",
"eventName": "DeleteScheduledQuery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4142caa7-44b5-4264-869e-df464b315a36",
"requestParameters": {
"identifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteSubscriptionFilter
#Description
Deletes the specified subscription filter.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified log group does not exist.",
"eventCategory": "Management",
"eventID": "28f5e0e7-a447-4bda-a24d-4c2dd2e344d0",
"eventName": "DeleteSubscriptionFilter",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e5e2a407-5e91-4699-ba9f-930dabcb3b2b",
"requestParameters": {
"filterName": "ddddd",
"logGroupName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteSyslogConfiguration
#Description
Deletes a syslog configuration for a log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "vpcEndpointId is required",
"eventCategory": "Management",
"eventID": "61c14ab9-b45a-4db6-b20e-2e10459112ff",
"eventName": "DeleteSyslogConfiguration",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "210f0abd-efd8-48c0-a642-2c0dff9e1d7f",
"requestParameters": {
"logGroupIdentifier": "ddddd",
"removeAll": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransformer
#Description
Deletes the log transformer for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified log group does not exist.",
"eventCategory": "Management",
"eventID": "89a0398f-a029-4048-849d-1285a9fc2f0d",
"eventName": "DeleteTransformer",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7f8e4a11-ef47-47f2-bd0b-35b807376aa1",
"requestParameters": {
"logGroupIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAccountPolicies
#Description
Returns a list of all CloudWatch Logs account policies in the account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b7bbee2c-c756-4626-97be-05b0168b2d88",
"eventName": "DescribeAccountPolicies",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f4df2f82-ec28-41b1-8e1f-80c5bb906458",
"requestParameters": {
"policyType": "DATA_PROTECTION_POLICY"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeConfigurationTemplates
#Description
Use this operation to return the valid and default values that are used when creating delivery sources, delivery destinations, and deliveries.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e1a75195-176b-4eb7-885e-1e641f4cb302",
"eventName": "DescribeConfigurationTemplates",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e5251c2d-c03b-479e-9894-449e629bc4d2",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDeliveries
#Description
Retrieves a list of the deliveries that have been created in the account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "97d4f5c2-6810-4f99-8ef4-6772c1fd25be",
"eventName": "DescribeDeliveries",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0041b5dc-62b2-4fd8-8d2a-89f1091ffc57",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDeliveryDestinations
#Description
Retrieves a list of the delivery destinations that have been created in the account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3b6e24f0-4d00-4322-891d-1b4db8a0c378",
"eventName": "DescribeDeliveryDestinations",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b4a1bca4-1b69-417e-ab36-46b8ac862d19",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDeliverySources
#Description
Retrieves a list of the delivery sources that have been created in the account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1d0064d4-7c4b-4922-ad5d-6fc18fbb7ba9",
"eventName": "DescribeDeliverySources",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cb36e5c6-3a2b-4aa4-b661-02eaca7b426b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeDestinations
#Description
Lists all your destinations.
Example CloudTrail Event #
{
"apiVersion": "55606",
"awsRegion": "us-west-2",
"eventID": "5f6f9cf0-0a44-4931-9512-f65460f1c1",
"eventName": "DescribeDestinations",
"eventSource": "logs.amazonaws.com",
"eventTime": "2018-04-23T10:42:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "03b7608b-46e3-11e8-89fd-cd222d206653",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "150.5.17.8",
"userAgent": "aws-cli/1.11.139 Python/3.6.3 Linux/4.13.0-38-generic botocore/1.6.6",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeExportTasks
#Description
Lists the specified export tasks.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "e52b4361-6a22-40a2-8ee4-f326e1bcffe6",
"eventName": "DescribeExportTasks",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T18:21:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "b61f4715-9d8e-447b-b981-ab55a0aa0c70",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37TTBU6EGN",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
DescribeFieldIndexes
#Description
Returns a list of custom and default field indexes which are discovered in log data.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Log group cannot be found.",
"eventCategory": "Management",
"eventID": "80f41029-fa8c-4999-ab00-a5ce6b2d57bd",
"eventName": "DescribeFieldIndexes",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "863b146b-3ef8-4c32-b8fd-b3440be046fd",
"requestParameters": {
"logGroupIdentifiers": [
"ddddd"
]
},
"resources": [
{
"ARN": "arn:aws:logs:us-west-1:123456789012:log-group:ddddd",
"accountId": "123456789012",
"type": "AWS::Logs::LogGroup"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeImportTaskBatches
#Description
Gets detailed information about the individual batches within an import task, including their status and any error messages.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "ImportId must be a valid UUID format",
"eventCategory": "Management",
"eventID": "0011422b-ef5c-424a-b59a-97ebcc90a4f7",
"eventName": "DescribeImportTaskBatches",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c4b4f850-b688-4239-942a-d6e4f47585b5",
"requestParameters": {
"importId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeImportTasks
#Description
Lists and describes import tasks, with optional filtering by import status and source ARN.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "66ead605-a14e-4e90-80c4-784d5f0303a0",
"eventName": "DescribeImportTasks",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "10b5ef7a-eb3a-4fc4-a693-c5dc96877ee7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIndexPolicies
#Description
Returns the field index policies of the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Log group cannot be found.",
"eventCategory": "Management",
"eventID": "25b1007d-7a7f-4be4-ae95-cc356c0faa8b",
"eventName": "DescribeIndexPolicies",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8cd940a0-9c26-40db-8a12-714bffdeafcb",
"requestParameters": {
"logGroupIdentifiers": [
"ddddd"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeLogGroups
#Description
Returns information about log groups, including data sources that ingest into each log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "2633ba8f-4efe-44e0-a03a-33479e371e64",
"eventName": "DescribeLogGroups",
"eventSource": "logs.amazonaws.com",
"eventTime": "2023-07-10T12:02:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6b3ee272-731f-4386-bfc3-75a3cb13dc70",
"requestParameters": {
"logGroupNamePrefix": "/stratus-red-team/vpc-flow-logs"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeLogStreams
#Description
Lists the log streams for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "a4350bb4-73e2-4c83-b5d3-98cfe59bab5c",
"eventName": "DescribeLogStreams",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T13:21:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "c3849bd6-1668-4271-a81d-db0e5e6add00",
"requestParameters": {
"descending": true,
"limit": 50,
"logGroupName": "aws-cloudtrail-logs-Trail01",
"orderBy": "LastEventTime"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37TRWHLD2C",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
DescribeLookupTables
#Description
Retrieves metadata about lookup tables in your account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c5d568f4-794d-4681-bcec-e7efaf75675e",
"eventName": "DescribeLookupTables",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d946aae9-67d4-4de5-9595-225ae3b5ac56",
"requestParameters": {
"maxResults": 0
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMetricFilters
#Description
Lists the specified metric filters.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "1edcf00d-d8c0-4c02-b004-3c1b6e9402d6",
"eventName": "DescribeMetricFilters",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T13:08:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "ea053977-4358-4d59-bf89-471196b83e72",
"requestParameters": {
"limit": 50
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37TRWHLD2C",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
DescribeQueries
#Description
Returns a list of CloudWatch Logs Insights queries that are scheduled, running, or have been run recently in this account.
Example CloudTrail Event #
{
"apiVersion": "55606",
"awsRegion": "us-east-1",
"eventID": "fa40f361-ad43-42e5-8d2e-0726d221fc5c",
"eventName": "DescribeQueries",
"eventSource": "logs.amazonaws.com",
"eventTime": "2020-03-06T14:33:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "0ea540859-2a6f-43cf-8f4e-07eac51d1c19",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.35.92.20",
"userAgent": "Boto3/1.12.15 Python/2.7.17 Linux/4.4.0-039049-Microsoft Botocore/1.15.15",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeQueryDefinitions
#Description
This operation returns a paginated list of your saved CloudWatch Logs Insights query definitions.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "ca777495-7296-408e-ad30-5849ebcd90fa",
"eventName": "DescribeQueryDefinitions",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T13:23:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "f41db424-1185-4b9f-8b1f-d50a237a1486",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37TRWHLD2C",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
DescribeResourcePolicies
#Description
Lists the resource policies in this account.
Example CloudTrail Event #
{
"apiVersion": "55606",
"awsRegion": "us-west-2",
"eventID": "dbfb3479-f5b9-45c3-9bd9-1eb21cd23a0d",
"eventName": "DescribeResourcePolicies",
"eventSource": "logs.amazonaws.com",
"eventTime": "2018-01-08T14:48:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "94572cd9-f483-11e7-a9ee-b3eb85f2575d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "254.61.99.239",
"userAgent": "aws-cli/1.14.10 Python/3.6.4 Darwin/17.3.0 botocore/1.8.14",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeSubscriptionFilters
#Description
Lists the subscription filters for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "55606",
"awsRegion": "us-east-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified log group does not exist.",
"eventID": "5676b286-b090-4cfe-b55d-3cb97853680d",
"eventName": "DescribeSubscriptionFilters",
"eventSource": "logs.amazonaws.com",
"eventTime": "2020-05-19T17:44:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a0906e4e-8f4b-4590-96fb-3a0eac700e99",
"requestParameters": {
"logGroupName": "dummy_data"
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DisassociateKmsKey
#Description
Disassociates the specified KMS key from the specified log group or from all CloudWatch Logs Insights query results in the account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Either logGroupName or resourceIdentifier must be specified",
"eventCategory": "Management",
"eventID": "0fd2729f-62e4-4e9b-afe2-8c51e68f4fe8",
"eventName": "DisassociateKmsKey",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:45:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "943d31a3-f9e4-4196-90cc-7297a1496683",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateSourceFromS3TableIntegration
#Description
Disassociates a data source from an S3 Table Integration, removing query access and deleting all associated data from the integration.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Association not found for identifier: ddddd",
"eventCategory": "Management",
"eventID": "6889b3ce-5b28-46c9-a061-92cd956ab52a",
"eventName": "DisassociateSourceFromS3TableIntegration",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4f73ff7a-d1e5-4616-a904-312b4f81456e",
"requestParameters": {
"identifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
FilterLogEvents
#Description
Lists log events from the specified log group.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "505f9dcf-1c82-4819-ba49-f7e95f13d994",
"eventSource": "logs.amazonaws.com",
"eventName": "FilterLogEvents",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "20140328",
"readOnly": true,
"managementEvent": true,
"requestID": "65cc4d39-42ef-462c-8e74-7c5f357566b2",
"userAgent": "aws-cli/2.35.4 md/awscrt#0.32.2 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.5 md/pyimpl#CPython exec-env/AmazonQ-For-CLI-Version-2.8.0 m/b,s,Z,r,E,C cfg/retry-mode#standard md/installer#source sid/90e059e87448 md/prompt#off md/command#logs.filter-log-events",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"type": "AWS::Logs::LogGroup",
"ARN": "arn:aws:logs:us-east-1:123456789012:log-group:/EXAMPLE"
}
]
}
GetDataProtectionPolicy
#Description
Returns information about a log group data protection policy.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Log group 'ddddd' for owner '123456789012' cannot be found",
"eventCategory": "Management",
"eventID": "6b08f785-be25-4ad7-8fce-fae5d28381e6",
"eventName": "GetDataProtectionPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3db68578-cedc-42d0-8d4d-0b5818c2f71c",
"requestParameters": {
"logGroupIdentifier": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:logs:us-west-1:123456789012:log-group:ddddd:log-stream:",
"accountId": "123456789012",
"type": "AWS::Logs::LogGroup"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetDelivery
#Description
Returns complete information about one logical delivery.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery does not exist in this account.",
"eventCategory": "Management",
"eventID": "9397ae0c-2ff4-4a4c-a8e8-1f761914f625",
"eventName": "GetDelivery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a3fb27ba-f0f5-472a-accb-f4e17ad38f71",
"requestParameters": {
"id": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetDeliveryDestination
#Description
Retrieves complete information about one delivery destination.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery Destination does not exist in this account.",
"eventCategory": "Management",
"eventID": "ddbdfec2-c2a4-439f-820b-26cad175a4d6",
"eventName": "GetDeliveryDestination",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "dceec101-795f-4816-955d-f95f77c47fc4",
"requestParameters": {
"name": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetDeliveryDestinationPolicy
#Description
Retrieves the delivery destination policy assigned to the delivery destination that you specify.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery Destination does not exist in this account.",
"eventCategory": "Management",
"eventID": "31ffa72c-e05b-40fb-a524-5ef610eb4d34",
"eventName": "GetDeliveryDestinationPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "eb3d6d90-cdea-43bc-8f2c-df1f9979ee24",
"requestParameters": {
"deliveryDestinationName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetDeliverySource
#Description
Retrieves complete information about one delivery source.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery Source does not exist in this account.",
"eventCategory": "Management",
"eventID": "14b19322-d122-4b81-87b9-1f766c22e527",
"eventName": "GetDeliverySource",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "65d96b0a-13c7-40cd-8031-1ceb6e12f5fd",
"requestParameters": {
"name": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIntegration
#Description
Returns information about one integration between CloudWatch Logs and OpenSearch Service.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Integration with name ddddd does not exist.",
"eventCategory": "Management",
"eventID": "a934ae7d-906a-48bc-b307-ad93785dc7c3",
"eventName": "GetIntegration",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0a8dc415-312b-45ca-8413-557ce1087f20",
"requestParameters": {
"integrationName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetLogAnomalyDetector
#Description
Retrieves information about the log anomaly detector that you specify.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f7ff6a82-48d0-4bb8-8ecf-67d3c3ddc2fd",
"eventSource": "logs.amazonaws.com",
"eventName": "GetLogAnomalyDetector",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"apiVersion": "20140328",
"readOnly": true,
"managementEvent": true,
"requestID": "c3e7c243-e16c-41ab-8a7a-3b2e3e7e0f29",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/cloudwatchlogs#1.69.0 m/E",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.eu-west-1.amazonaws.com"
}
}
GetLogEvents
#Description
Lists log events from the specified log stream.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "c1192cb7-e2cf-42ed-bd00-9c5d562f930d",
"eventSource": "logs.amazonaws.com",
"eventName": "GetLogEvents",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "20140328",
"readOnly": true,
"managementEvent": true,
"requestID": "d06ea733-6af7-4a4d-b889-2da8e54a0956",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"type": "AWS::Logs::LogStream",
"ARN": "arn:aws:logs:us-east-1:123456789012:log-group:/EXAMPLE]cd651451fcb842b0bfe0bc95a6e1f4cf"
}
]
}
GetLogFields
#Description
Discovers available fields for a specific data source and type.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a452ef6d-98e0-46ca-b636-a7ae5626a992",
"eventName": "GetLogFields",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "440c32a3-09d2-49a0-8e73-cbf9a194f6cf",
"requestParameters": {
"dataSourceName": "dw-probe",
"dataSourceType": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetLogGroupFields
#Description
Returns a list of the fields that are included in log events in the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "cc43eff4-73fc-41c4-8edb-e45df1550957",
"eventName": "GetLogGroupFields",
"eventSource": "logs.amazonaws.com",
"eventTime": "2021-07-07T17:20:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "0f92500c-1d5d-4be9-8ff1-ee349af8f675",
"requestParameters": {
"logGroupName": "/aws/eks/Cluster_Galah/cluster"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.252",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37RY6YQCLU",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
GetLogObject
#Description
Retrieves a large logging object (LLO) and streams it back.
GetLogRecord
#Description
Retrieves all of the fields and values of a single log event.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: logs:GetLogRecord on resource: arn:aws:logs:us-east-1:811596193553:log-group::log-stream:",
"eventID": "982189-8b17-4f84-ab5c-0a1623c04e56",
"eventName": "GetLogRecord",
"eventSource": "logs.amazonaws.com",
"eventTime": "2020-05-19T17:44:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "0e1a9a56-9d92-4d8c-ba5f-855c5c982b6a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetLookupTable
#Description
Retrieves the full content of a lookup table, including the CSV data.
GetQueryResults
#Description
Returns the results from the specified query.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "50a84999-53ff-428c-bd1b-ba2d3c6597bc",
"eventSource": "logs.amazonaws.com",
"eventName": "GetQueryResults",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "20140328",
"readOnly": true,
"managementEvent": true,
"requestID": "18a44fae-4a59-49a0-9e09-bb27980c8089",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
}
}
GetScheduledQuery
#Description
Retrieves details about a specific scheduled query, including its configuration, execution status, and metadata.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Scheduled query with identifier ddddd not found",
"eventCategory": "Management",
"eventID": "dc3dd58a-c254-4608-8cb7-bed3add91d1e",
"eventName": "GetScheduledQuery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e0b53371-c2f2-4e57-b073-3c58bc6fecf2",
"requestParameters": {
"identifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetScheduledQueryHistory
#Description
Retrieves the execution history of a scheduled query within a specified time range, including query results and destination processing status.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Start time cannot be more than 30 days in the past",
"eventCategory": "Management",
"eventID": "86bfe0cb-c1fc-4fe2-9a61-3f198ecf8533",
"eventName": "GetScheduledQueryHistory",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "61b3de0a-7887-4de2-89c1-5b127731ae1a",
"requestParameters": {
"endTime": 1,
"identifier": "ddddd",
"startTime": 1
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTransformer
#Description
Returns the information about the log transformer associated with this log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified log group does not exist.",
"eventCategory": "Management",
"eventID": "1b76ee04-19e4-4469-b712-586c700f95b4",
"eventName": "GetTransformer",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6a17223b-8033-499e-9ecc-bc4954ad44a1",
"requestParameters": {
"logGroupIdentifier": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAggregateLogGroupSummaries
#Description
Returns an aggregate summary of all log groups in the Region grouped by specified data source characteristics.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dcfcea1e-ad85-4a39-a388-83644d230e37",
"eventName": "ListAggregateLogGroupSummaries",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9b61ad27-26b8-4103-9ffb-80d67674df76",
"requestParameters": {
"accountIdentifiers": [
"123456789012"
],
"groupBy": "DATA_SOURCE_NAME_TYPE_AND_FORMAT"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAnomalies
#Description
Returns a list of anomalies that log anomaly detectors have found.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "89645a09-fe1b-4c38-85b9-617afbb90883",
"eventName": "ListAnomalies",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cf51cd87-1680-43b3-b603-a748814822b7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListIntegrations
#Description
Returns a list of integrations between CloudWatch Logs and other services in this account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "55d43e17-b1dd-4ca5-9dc0-34d09c49886c",
"eventName": "ListIntegrations",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f9c9c47f-929d-4853-b0b8-a62c3caebe1d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListLogAnomalyDetectors
#Description
Retrieves a list of the log anomaly detectors in the account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "07670b6f-7bef-4b93-9c9f-d6c792f7d39e",
"eventName": "ListLogAnomalyDetectors",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "13d3376d-b2f1-49c4-be29-e1738e7d9c04",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListLogGroups
#Description
Returns a list of log groups in the Region in your account.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "74da2140-a14a-4916-8efd-c0ee7c28a9ea",
"eventName": "ListLogGroups",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "68121750-6cd9-4b1a-9180-82ec451d3ae1",
"requestParameters": {
"accountIdentifiers": [
"123456789012"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListLogGroupsForQuery
#Description
Returns a list of the log groups that were analyzed during a single CloudWatch Logs Insights query.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "An unknown error occurred",
"eventCategory": "Management",
"eventID": "00e361b6-8d42-4c55-81b8-0eda3fdc7baa",
"eventName": "ListLogGroupsForQuery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "017203d0-b81d-46ee-b9f9-aff9a993a7f1",
"requestParameters": {
"queryId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListScheduledQueries
#Description
Lists all scheduled queries in your account and region.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a808d01a-88bb-451a-9bff-f7f54747a795",
"eventName": "ListScheduledQueries",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8162ebc2-c082-4e8b-b79b-713f5fb1bcf7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListSourcesForS3TableIntegration
#Description
Returns a list of data source associations for a specified S3 Table Integration, showing which data sources are currently associated for query access.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Invalid S3 table integration ARN format. Expected: s3tableintegration/{integration-id}: arn:aws:iam::123456789012:role/dw-probe",
"eventCategory": "Management",
"eventID": "da37b8af-35fd-40b5-bd77-e471dc0d9b1a",
"eventName": "ListSourcesForS3TableIntegration",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "53e3b56c-c3ed-4a26-b72f-b97a7d8d918e",
"requestParameters": {
"integrationArn": "arn:aws:iam::123456789012:role/dw-probe",
"maxResults": 0
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListSyslogConfigurations
#Description
Returns a list of syslog configurations.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "37cdf3ce-7d0a-4982-981c-820486589f7e",
"eventName": "ListSyslogConfigurations",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b5e7c7e6-5410-4a72-8e91-734757fd4479",
"requestParameters": {
"maxResults": 0
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutAccountPolicy
#Description
Creates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combinat.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Invalid selection criteria provided.",
"eventCategory": "Management",
"eventID": "c264e17c-4d67-4826-867a-d1ca9b14c20c",
"eventName": "PutAccountPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "853c07f4-1df3-4f5a-82a8-823606be0ba8",
"requestParameters": {
"dryRun": false,
"policyDocument": {
"Fields": [
"level",
"requestId"
]
},
"policyName": "dwfix-ap-vx8ojsm7",
"policyType": "FIELD_INDEX_POLICY",
"selectionCriteria": "LogGroupName = \"dwfix-logs-vx8ojsm7\""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBearerTokenAuthentication
#Description
Enables or disables bearer token authentication for the specified log group.
PutDataProtectionPolicy
#Description
Creates a data protection policy for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Policy can only have two statements. One for Audit Operation and one for Deidentify Operation",
"eventCategory": "Management",
"eventID": "bbc05834-f8cf-41bd-8680-ac3d4e6b3694",
"eventName": "PutDataProtectionPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:04:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9ada9748-1abc-4ac3-b159-53b80215ffd7",
"requestParameters": {
"logGroupIdentifier": "dwfix-lg2",
"policyDocument": {
"Name": "dw",
"Version": "2021-06-01",
"Statement": [
{
"Sid": "a",
"DataIdentifier": [
"arn:aws:dataprotection::aws:data-identifier/EmailAddress"
],
"Operation": {
"Audit": {
"FindingsDestination": {}
}
}
}
]
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutDeliveryDestination
#Description
Creates or updates a logical delivery destination.
PutDeliveryDestinationPolicy
#Description
Creates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account.
PutDeliverySource
#Description
Creates or updates a logical delivery source.
PutDestination
#Description
Creates or updates a destination.
PutDestinationPolicy
#Description
Creates or updates an access policy associated with an existing destination.
PutIndexPolicy
#Description
Creates or updates a field index policy for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "74f64219-edd2-45d1-a7d0-aca6e38d889c",
"eventName": "PutIndexPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "60634013-8d05-48d5-aaf2-52d354ad7ffe",
"requestParameters": {
"logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
"policyDocument": {
"Fields": [
"level",
"requestId",
"errorCode"
]
}
},
"responseElements": {
"indexPolicy": {
"lastUpdateTime": 1782766740731,
"logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
"policyDocument": {
"Fields": [
"level",
"requestId",
"errorCode"
]
},
"source": "LOG_GROUP"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutIntegration
#Description
Creates an integration between CloudWatch Logs and another service in this account.
PutLogEvents
#Description
Uploads a batch of log events to the specified log stream.
PutLogGroupDeletionProtection
#Description
Enables or disables deletion protection for the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d33d7eab-c71c-42e0-8637-a75991ca63d2",
"eventName": "PutLogGroupDeletionProtection",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3c56d6c2-e5ce-40c1-bc42-4b7bdbeeb69f",
"requestParameters": {
"deletionProtectionEnabled": true,
"logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutMetricFilter
#Description
Creates or updates a metric filter and associates it with the specified log group.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: logs:PutMetricFilter on resource: arn:aws:logs:us-west-2:811596193553:log-group:sec545-logging-hampsterdam:log-stream:",
"eventID": "e03464a-547d-44f8-82ca-ffd6ddd287d6",
"eventName": "PutMetricFilter",
"eventSource": "logs.amazonaws.com",
"eventTime": "2020-02-28T20:41:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "4e5b3318-18c9-4b8b-9445-158437b5b1",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "250.0.35.1",
"userAgent": "aws-cli/1.18.5 Python/3.7.0 Windows/10 botocore/1.15.5",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
PutQueryDefinition
#Description
Creates or updates a query definition for CloudWatch Logs Insights.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0514d305-e7aa-4fba-a937-5019056945ae",
"eventName": "PutQueryDefinition",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:04:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "59cdb4ed-4d49-43b6-a0c1-2e486d98a9e8",
"requestParameters": {
"clientToken": "529526c8-55ac-4882-ba56-f4f139de156e",
"name": "dwfix-q",
"queryLanguage": "CWLI",
"queryString": "fields @timestamp"
},
"responseElements": {
"queryDefinitionId": "3630c631-ac9c-4655-9ea3-737267e3f655"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutResourcePolicy
#Description
Creates or updates a resource policy allowing other Amazon Web Services services to put log events to this account, such as Amazon Route 53.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "18055e58-b015-4433-92ce-2bcf91a487e1",
"eventName": "PutResourcePolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7f49fef4-e94d-4dbc-9930-cbfac748b747",
"requestParameters": {
"policyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DwFixDeliveryAccess",
"Effect": "Allow",
"Principal": {
"Service": "delivery.logs.amazonaws.com"
},
"Action": [
"logs:PutLogEvents",
"logs:CreateLogStream"
],
"Resource": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7:*",
"Condition": {
"StringEquals": {
"aws:SourceAccount": "123456789012"
}
}
}
]
},
"policyName": "dwfix-rp-vx8ojsm7"
},
"responseElements": {
"resourcePolicy": {
"lastUpdatedTime": 1782766741408,
"policyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DwFixDeliveryAccess",
"Effect": "Allow",
"Principal": {
"Service": "delivery.logs.amazonaws.com"
},
"Action": [
"logs:PutLogEvents",
"logs:CreateLogStream"
],
"Resource": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7:*",
"Condition": {
"StringEquals": {
"aws:SourceAccount": "123456789012"
}
}
}
]
},
"policyName": "dwfix-rp-vx8ojsm7",
"policyScope": "ACCOUNT"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutRetentionPolicy
#Description
Sets the retention of the specified log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4acbd1f7-90ba-4679-a41b-2d6397d165d8",
"eventName": "PutRetentionPolicy",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:12:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6d5ce61b-7073-44be-bbda-25b4b8337614",
"requestParameters": {
"logGroupName": "dwfix-lg",
"retentionInDays": 1
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutSubscriptionFilter
#Description
Creates or updates a subscription filter and associates it with the specified log group.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "3cbf550c-ebcc-3e60-9bef-cdf2604e195f",
"eventSource": "logs.amazonaws.com",
"eventName": "PutSubscriptionFilter",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"apiVersion": "20140328",
"readOnly": false,
"managementEvent": true,
"requestID": "50d6c6d0-194d-4bad-8aa7-7f767f8ce363",
"userAgent": "application-insights.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::Logs::Destination",
"ARN": "arn:aws:logs:eu-west-1:123456789012:destination:EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::Logs::LogGroup",
"ARN": "arn:aws:logs:eu-west-1:123456789012:log-group:EXAMPLE"
}
]
}
PutSyslogConfiguration
#Description
Creates or updates a syslog configuration for a log group.
PutTransformer
#Description
Creates or updates a log transformer for a single log group.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Transformer config should begin with parser. Allowed parsers are parsePostgres, parseWAF, parseCloudfront, parseCloudfrontOCSF, parseRoute53, parseLambda, parseVPC, parseSyslog, parseRDS, parseCiscoFTD, parseToOCSF, parseJSON, grok, csv, parseKeyValue",
"eventCategory": "Management",
"eventID": "9d358936-e39a-45ea-b863-d4f04f245984",
"eventName": "PutTransformer",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e1ce3ad1-0a39-45de-82ea-316a557b9de9",
"requestParameters": {
"logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
"transformerConfig": [
{
"lowerCaseString": {
"withKeys": [
"level"
]
}
},
{
"addKeys": {
"entries": [
{
"key": "dwfix_processed",
"overwriteIfExists": true,
"value": "true"
}
]
}
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartLiveTail
#Description
Starts a Live Tail streaming session for one or more log groups.
StartQuery
#Description
Starts a query of one or more log groups or data sources using CloudWatch Logs Insights.
Example CloudTrail Event #
{
"additionalEventData": {
"queryId": "f21f44f0-56fb-4275-83c6-23ac74b87269"
},
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "01d99b94-363e-4fbd-9be8-cd6a42944ca4",
"eventName": "StartQuery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7a7e9f67-817b-46ea-9f61-7c046d35472b",
"requestParameters": {
"dryRun": false,
"endTime": 1782766741,
"forceAnalyticsTier": false,
"logGroupName": "dwfix-logs-vx8ojsm7",
"queryLanguage": "CWLI",
"queryString": "fields @timestamp, @message | limit 3",
"startTime": 1782766441
},
"resources": [
{
"ARN": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
"accountId": "123456789012",
"type": "AWS::Logs::LogGroup"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StopQuery
#Description
Stops a CloudWatch Logs Insights query that is in progress.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The provided queryId=ddddd is invalid.",
"eventCategory": "Management",
"eventID": "bd002fd3-3c83-4236-9025-c6088d48b3c2",
"eventName": "StopQuery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ca99a9be-7c45-4cd8-9d58-5ac019aed61f",
"requestParameters": {
"dryRun": false,
"queryId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TagLogGroup
#Description
The TagLogGroup operation is on the path to deprecation.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ce406901-dc31-4366-8529-a45bc475938e",
"eventName": "TagLogGroup",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:12:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0fbf2599-0998-4808-95a7-99b021bb18a5",
"requestParameters": {
"logGroupName": "dwfix-lg",
"tags": {
"dw": "f"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TagResource
#Description
Assigns one or more tags (key-value pairs) to the specified CloudWatch Logs resource.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e8fd4c1e-7101-47c6-bcf5-9d05e7425fdf",
"eventName": "TagResource",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9b1b9d57-e0c5-46b0-9ff7-3a43dc0392e9",
"requestParameters": {
"resourceArn": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
"tags": {
"env": "dwfix",
"recipe": "logs",
"tier": "test"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TestMetricFilter
#Description
Tests the filter pattern of a metric filter against a sample of log event messages.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: logs:TestMetricFilter on resource: arn:aws:logs:us-east-1:811596193553:log-group::log-stream:",
"eventID": "ec182c55-66de-4008-a4f5-b1fd66fdc04d",
"eventName": "TestMetricFilter",
"eventSource": "logs.amazonaws.com",
"eventTime": "2020-05-19T17:44:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "d60ef732-94a3-460f-bcf3-8ddef950fc83",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
TestTransformer
#Description
Use this operation to test a log transformer.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Transformer config should begin with parser. Allowed parsers are parsePostgres, parseWAF, parseCloudfront, parseCloudfrontOCSF, parseRoute53, parseLambda, parseVPC, parseSyslog, parseRDS, parseCiscoFTD, parseToOCSF, parseJSON, grok, csv, parseKeyValue",
"eventCategory": "Management",
"eventID": "c11e6c80-d6e3-4ddb-9764-ba5d06f0aad3",
"eventName": "TestTransformer",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cd6dd587-48ab-4af6-b00e-6d940e10d8b8",
"requestParameters": {
"logEventMessages": [
{
"level": "ERROR",
"requestId": "abc-123",
"msg": "test"
},
{
"level": "INFO",
"requestId": "def-456",
"msg": "ok"
}
],
"transformerConfig": [
{
"lowerCaseString": {
"withKeys": [
"level"
]
}
},
{
"addKeys": {
"entries": [
{
"key": "dwfix_processed",
"overwriteIfExists": true,
"value": "true"
}
]
}
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagLogGroup
#Description
The UntagLogGroup operation is on the path to deprecation.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "The specified log group does not exist.",
"eventCategory": "Management",
"eventID": "ee4c946c-2731-49a8-b3d7-bdac113cbbd3",
"eventName": "UntagLogGroup",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cc6df18e-2ee7-40f1-8483-710980ab6a4b",
"requestParameters": {
"logGroupName": "ddddd",
"tags": [
"ddddd"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagResource
#Description
Removes one or more tags from the specified resource.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "25b3330b-547b-408b-b666-b4b9034f7c48",
"eventName": "UntagResource",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T20:59:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7d052d99-a303-458c-89b2-faec011d7d6d",
"requestParameters": {
"resourceArn": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
"tagKeys": [
"env",
"recipe",
"tier",
"updated"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAnomaly
#Description
Use this operation to suppress anomaly detection for a specified anomaly or pattern.
UpdateDeliveryConfiguration
#Description
Use this operation to update the configuration of a delivery to change either the S3 path pattern or the format of the delivered logs.
Example CloudTrail Event #
{
"apiVersion": "20140328",
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"errorMessage": "Requested Delivery does not exist in this account.",
"eventCategory": "Management",
"eventID": "24869d5b-2e2e-4f86-af4e-4e36efdae10b",
"eventName": "UpdateDeliveryConfiguration",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e7dd899f-1f75-4b02-a3d5-046b2fc3cb7c",
"requestParameters": {
"id": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateLogAnomalyDetector
#Description
Updates an existing log anomaly detector.
UpdateLookupTable
#Description
Updates an existing lookup table by replacing all of its CSV content.
UpdateScheduledQuery
#Description
Updates an existing scheduled query with new configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"errorMessage": "Cross-account pass role is not allowed.",
"eventCategory": "Management",
"eventID": "c7e66248-69fc-4465-a1df-bb1153adb43d",
"eventName": "UpdateScheduledQuery",
"eventSource": "logs.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ebb615ce-c594-4396-bb71-b3953921282b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetStorageTierPolicy
#Description
Returns the storage tier policy for the account.
PutStorageTierPolicy
#Description
Sets the storage tier policy for the account.