CloudWatch Logs

eventNameDescriptionSampleRule
anyCatch-all entry for CloudWatch Logs rules that match the service but not a specific eventName.NN
DeleteLogGroupDeletes the specified CloudWatch Logs log group and all its associated log streams, subscription filters, metric filters, and retention policies.YY
DeleteLogStreamDeletes the specified log stream and permanently deletes all the archived log events associated with the log stream.YY
AssociateKmsKeyAssociates the specified KMS key with either one log group in the account, or with all stored CloudWatch Logs query insights results in the account.NN
AssociateSourceToS3TableIntegrationAssociates a data source with an S3 Table Integration for query access in the 'logs' namespace.NN
CancelExportTaskCancels the specified export task.YN
CancelImportTaskCancels an active import task and stops importing data from the CloudTrail Lake Event Data Store.YN
CreateDeliveryCreates a delivery.NN
CreateExportTaskCreates an export task so that you can efficiently export data from a log group to an Amazon S3 bucket.YN
CreateImportTaskStarts an import from a data source to CloudWatch Log and creates a managed log group as the destination for the imported data.NN
CreateLogAnomalyDetectorCreates an anomaly detector that regularly scans one or more log groups and look for patterns and anomalies in the logs.YN
CreateLogGroupCreates a log group with the specified name.YN
CreateLogStreamCreates a log stream for the specified log group.YN
CreateLookupTableCreates a lookup table by uploading CSV data.NN
CreateScheduledQueryCreates a scheduled query that runs CloudWatch Logs Insights queries at regular intervals.NN
DeleteAccountPolicyDeletes a CloudWatch Logs account policy.YN
DeleteDataProtectionPolicyDeletes the data protection policy from the specified log group.YN
DeleteDeliveryDeletes a delivery.YN
DeleteDeliveryDestinationDeletes a delivery destination.YN
DeleteDeliveryDestinationPolicyDeletes a delivery destination policy.YN
DeleteDeliverySourceDeletes a delivery source.YN
DeleteDestinationDeletes the specified destination, and eventually disables all the subscription filters that publish to it.YN
DeleteIndexPolicyDeletes a log-group level field index policy that was applied to a single log group.YN
DeleteIntegrationDeletes the integration between CloudWatch Logs and OpenSearch Service.YN
DeleteLogAnomalyDetectorDeletes the specified CloudWatch Logs anomaly detector.YN
DeleteLookupTableDeletes a lookup table permanently.NN
DeleteMetricFilterDeletes the specified metric filter.YN
DeleteQueryDefinitionDeletes a saved CloudWatch Logs Insights query definition.YN
DeleteResourcePolicyDeletes a resource policy from this account.YN
DeleteRetentionPolicyDeletes the specified retention policy.YN
DeleteScheduledQueryDeletes a scheduled query and stops all future executions.YN
DeleteSubscriptionFilterDeletes the specified subscription filter.YN
DeleteSyslogConfigurationDeletes a syslog configuration for a log group.YN
DeleteTransformerDeletes the log transformer for the specified log group.YN
DescribeAccountPoliciesReturns a list of all CloudWatch Logs account policies in the account.YN
DescribeConfigurationTemplatesUse this operation to return the valid and default values that are used when creating delivery sources, delivery destinations, and deliveries.YN
DescribeDeliveriesRetrieves a list of the deliveries that have been created in the account.YN
DescribeDeliveryDestinationsRetrieves a list of the delivery destinations that have been created in the account.YN
DescribeDeliverySourcesRetrieves a list of the delivery sources that have been created in the account.YN
DescribeDestinationsLists all your destinations.YN
DescribeExportTasksLists the specified export tasks.YN
DescribeFieldIndexesReturns a list of custom and default field indexes which are discovered in log data.YN
DescribeImportTaskBatchesGets detailed information about the individual batches within an import task, including their status and any error messages.YN
DescribeImportTasksLists and describes import tasks, with optional filtering by import status and source ARN.YN
DescribeIndexPoliciesReturns the field index policies of the specified log group.YN
DescribeLogGroupsReturns information about log groups, including data sources that ingest into each log group.YN
DescribeLogStreamsLists the log streams for the specified log group.YN
DescribeLookupTablesRetrieves metadata about lookup tables in your account.YN
DescribeMetricFiltersLists the specified metric filters.YN
DescribeQueriesReturns a list of CloudWatch Logs Insights queries that are scheduled, running, or have been run recently in this account.YN
DescribeQueryDefinitionsThis operation returns a paginated list of your saved CloudWatch Logs Insights query definitions.YN
DescribeResourcePoliciesLists the resource policies in this account.YN
DescribeSubscriptionFiltersLists the subscription filters for the specified log group.YN
DisassociateKmsKeyDisassociates the specified KMS key from the specified log group or from all CloudWatch Logs Insights query results in the account.YN
DisassociateSourceFromS3TableIntegrationDisassociates a data source from an S3 Table Integration, removing query access and deleting all associated data from the integration.YN
FilterLogEventsLists log events from the specified log group.NN
GetDataProtectionPolicyReturns information about a log group data protection policy.YN
GetDeliveryReturns complete information about one logical delivery.YN
GetDeliveryDestinationRetrieves complete information about one delivery destination.YN
GetDeliveryDestinationPolicyRetrieves the delivery destination policy assigned to the delivery destination that you specify.YN
GetDeliverySourceRetrieves complete information about one delivery source.YN
GetIntegrationReturns information about one integration between CloudWatch Logs and OpenSearch Service.YN
GetLogAnomalyDetectorRetrieves information about the log anomaly detector that you specify.NN
GetLogEventsLists log events from the specified log stream.NN
GetLogFieldsDiscovers available fields for a specific data source and type.YN
GetLogGroupFieldsReturns a list of the fields that are included in log events in the specified log group.YN
GetLogObjectRetrieves a large logging object (LLO) and streams it back.NN
GetLogRecordRetrieves all of the fields and values of a single log event.YN
GetLookupTableRetrieves the full content of a lookup table, including the CSV data.NN
GetQueryResultsReturns the results from the specified query.NN
GetScheduledQueryRetrieves details about a specific scheduled query, including its configuration, execution status, and metadata.YN
GetScheduledQueryHistoryRetrieves the execution history of a scheduled query within a specified time range, including query results and destination processing status.YN
GetTransformerReturns the information about the log transformer associated with this log group.YN
ListAggregateLogGroupSummariesReturns an aggregate summary of all log groups in the Region grouped by specified data source characteristics.YN
ListAnomaliesReturns a list of anomalies that log anomaly detectors have found.YN
ListIntegrationsReturns a list of integrations between CloudWatch Logs and other services in this account.YN
ListLogAnomalyDetectorsRetrieves a list of the log anomaly detectors in the account.YN
ListLogGroupsReturns a list of log groups in the Region in your account.YN
ListLogGroupsForQueryReturns a list of the log groups that were analyzed during a single CloudWatch Logs Insights query.YN
ListScheduledQueriesLists all scheduled queries in your account and region.YN
ListSourcesForS3TableIntegrationReturns a list of data source associations for a specified S3 Table Integration, showing which data sources are currently associated for query access.YN
ListSyslogConfigurationsReturns a list of syslog configurations.YN
ListTagsForResourceDisplays the tags associated with a CloudWatch Logs resource.NN
ListTagsLogGroupThe ListTagsLogGroup operation is on the path to deprecation.YN
PutAccountPolicyCreates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combinat.YN
PutBearerTokenAuthenticationEnables or disables bearer token authentication for the specified log group.NN
PutDataProtectionPolicyCreates a data protection policy for the specified log group.YN
PutDeliveryDestinationCreates or updates a logical delivery destination.NN
PutDeliveryDestinationPolicyCreates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account.NN
PutDeliverySourceCreates or updates a logical delivery source.NN
PutDestinationCreates or updates a destination.NN
PutDestinationPolicyCreates or updates an access policy associated with an existing destination.NN
PutIndexPolicyCreates or updates a field index policy for the specified log group.YN
PutIntegrationCreates an integration between CloudWatch Logs and another service in this account.NN
PutLogEventsUploads a batch of log events to the specified log stream.NN
PutLogGroupDeletionProtectionEnables or disables deletion protection for the specified log group.YN
PutMetricFilterCreates or updates a metric filter and associates it with the specified log group.YN
PutQueryDefinitionCreates or updates a query definition for CloudWatch Logs Insights.YN
PutResourcePolicyCreates or updates a resource policy allowing other Amazon Web Services services to put log events to this account, such as Amazon Route 53.YN
PutRetentionPolicySets the retention of the specified log group.YN
PutSubscriptionFilterCreates or updates a subscription filter and associates it with the specified log group.NN
PutSyslogConfigurationCreates or updates a syslog configuration for a log group.NN
PutTransformerCreates or updates a log transformer for a single log group.YN
StartLiveTailStarts a Live Tail streaming session for one or more log groups.NN
StartQueryStarts a query of one or more log groups or data sources using CloudWatch Logs Insights.YN
StopQueryStops a CloudWatch Logs Insights query that is in progress.YN
TagLogGroupThe TagLogGroup operation is on the path to deprecation.YN
TagResourceAssigns one or more tags (key-value pairs) to the specified CloudWatch Logs resource.YN
TestMetricFilterTests the filter pattern of a metric filter against a sample of log event messages.YN
TestTransformerUse this operation to test a log transformer.YN
UntagLogGroupThe UntagLogGroup operation is on the path to deprecation.YN
UntagResourceRemoves one or more tags from the specified resource.YN
UpdateAnomalyUse this operation to suppress anomaly detection for a specified anomaly or pattern.NN
UpdateDeliveryConfigurationUse this operation to update the configuration of a delivery to change either the S3 path pattern or the format of the delivered logs.YN
UpdateLogAnomalyDetectorUpdates an existing log anomaly detector.NN
UpdateLookupTableUpdates an existing lookup table by replacing all of its CSV content.NN
UpdateScheduledQueryUpdates an existing scheduled query with new configuration.YN
GetStorageTierPolicyReturns the storage tier policy for the account.NN
PutStorageTierPolicySets the storage tier policy for the account.NN

any: CloudWatch Logs (catch-all)

#
Service
logs

Description

Catch-all entry for CloudWatch Logs rules that match the service but not a specific eventName.

DeleteLogGroup

#
Service
logs

Description

Deletes the specified CloudWatch Logs log group and all its associated log streams, subscription filters, metric filters, and retention policies.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "349b65f9-1932-4258-a52e-476cf4fcf6d7",
  "eventName": "DeleteLogGroup",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2023-07-10T12:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "0314119b-6da8-4d0c-a5fa-e3e84c1b89b3",
  "requestParameters": {
    "logGroupName": "/stratus-red-team/vpc-flow-logs"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (splunk rule field)eqsuccess1 rulesplunk
userAgent (splunk rule field)neconsole.amazonaws.com1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS CloudWatch Log Group Deletion source medium: Detects the deletion of an Amazon CloudWatch Log Group using the "DeleteLogGroup" API. CloudWatch log groups store operational and security logs for AWS services and custom applications. Deleting a log group permanently removes all associated log streams and historical log data, which can eliminate forensic evidence and disrupt security monitoring pipelines. Adversaries may delete log groups to conceal malicious activity, disable log forwarding, or impede incident response.T1485, T1562, T1562.001, T1562.008

Splunk #

Kusto #

YARA-L #

References #

DeleteLogStream

#
Service
logs

Description

Deletes the specified log stream and permanently deletes all the archived log events associated with the log stream.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "561c3f4e-17ca-4438-b15d-29903baf7b13",
  "eventName": "DeleteLogStream",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2022-07-20T21:09:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "2d7e859e-d697-426f-8b56-c4c11c4055f3",
  "requestParameters": {
    "logGroupName": "test-logs",
    "logStreamName": "20150601"
  },
  "responseElements": null,
  "sourceIPAddress": "67.171.71.185",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off command/logs.delete-log-stream",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLFLKADUVG",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
    "principalId": "AIDAYTOGP2RLI4PXTGCEU",
    "type": "IAMUser",
    "userName": "gowthamaraj_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS CloudWatch Log Stream Deletion source medium: Detects the deletion of an Amazon CloudWatch log stream using the "DeleteLogStream" API. Deleting a log stream permanently removes its associated log events and may disrupt security visibility, break audit trails, or suppress forensic evidence. Adversaries may delete log streams to conceal malicious actions, impair monitoring pipelines, or remove artifacts generated during post-exploitation activity.T1485, T1562, T1562.001, T1562.008

Splunk #

References #

AssociateKmsKey

#
Service
logs

Description

Associates the specified KMS key with either one log group in the account, or with all stored CloudWatch Logs query insights results in the account.

AssociateSourceToS3TableIntegration

#
Service
logs

Description

Associates a data source with an S3 Table Integration for query access in the 'logs' namespace.

CancelExportTask

#
Service
logs

Description

Cancels the specified export task.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified export task does not exist.",
  "eventCategory": "Management",
  "eventID": "c6468857-9dc8-46fa-8033-5c8913f8b786",
  "eventName": "CancelExportTask",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b61dc63e-5c7f-4872-aa52-b2b01ca09790",
  "requestParameters": {
    "taskId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelImportTask

#
Service
logs

Description

Cancels an active import task and stops importing data from the CloudTrail Lake Event Data Store.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "ImportId must be a valid UUID format",
  "eventCategory": "Management",
  "eventID": "22f89250-6e9a-48c6-a331-c617c46c2b9e",
  "eventName": "CancelImportTask",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "93035088-71f2-4eca-a051-d6c38695939e",
  "requestParameters": {
    "importId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDelivery

#
Service
logs

Description

Creates a delivery.

CreateExportTask

#
Service
logs

Description

Creates an export task so that you can efficiently export data from a log group to an Amazon S3 bucket.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "10cd4043-609b-4855-b6a9-99cb90e37999",
  "eventName": "CreateExportTask",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T18:34:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "1cb2c82e-b8d8-484a-82f3-08fb42aebdc9",
  "requestParameters": {
    "destination": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
    "destinationPrefix": "random123",
    "from": 1625589900000,
    "logGroupName": "/aws/eks/Cluster_Galah/cluster",
    "taskName": "/aws/eks/Cluster_Galah/cluster-1625682879241",
    "to": 1625678040000
  },
  "responseElements": {
    "taskId": "db3f519b-751d-4abe-b251-daa32185c9dc"
  },
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37TTBU6EGN",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

CreateImportTask

#
Service
logs

Description

Starts an import from a data source to CloudWatch Log and creates a managed log group as the destination for the imported data.

CreateLogAnomalyDetector

#
Service
logs

Description

Creates an anomaly detector that regularly scans one or more log groups and look for patterns and anomalies in the logs.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b4fb147e-8bb3-43c4-ac5e-26794663aefd",
  "eventName": "CreateLogAnomalyDetector",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:04:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1f7ca173-3500-42a4-a24c-4019fcc7ae28",
  "requestParameters": {
    "detectorName": "dwfix-ad",
    "logGroupArnList": [
      "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-lg2"
    ]
  },
  "responseElements": {
    "anomalyDetectorArn": "arn:aws:logs:us-west-1:123456789012:anomaly-detector:a72549c0-450b-429c-b9aa-c636f899356b"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateLogGroup

#
Service
logs

Description

Creates a log group with the specified name.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a46276b9-dd85-4736-b9df-6210c69aa8e7",
  "eventName": "CreateLogGroup",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2023-07-10T12:02:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "2aace905-794c-47bb-b7c9-9f0267d13535",
  "requestParameters": {
    "logGroupName": "/stratus-red-team/vpc-flow-logs",
    "tags": {
      "StratusRedTeam": "true"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateLogStream

#
Service
logs

Description

Creates a log stream for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "afa163a7-c50a-48a6-bf64-2e76906ebe93",
  "eventName": "CreateLogStream",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T13:17:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "d9d5811c-3a6b-45b6-b157-84ffc0d036ab",
  "requestParameters": {
    "logGroupName": "aws-cloudtrail-logs-Trail01",
    "logStreamName": "797507667711_CloudTrail_us-east-2"
  },
  "responseElements": null,
  "sourceIPAddress": "cloudtrail.amazonaws.com",
  "userAgent": "cloudtrail.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37QBDGCRN3",
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/CloudTrail_CloudWatchLogs_Role/CloudTrail",
    "invokedBy": "cloudtrail.amazonaws.com",
    "principalId": "AROA3TLZJI375OOYMRDNV:CloudTrail",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T13:17:56Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/service-role/CloudTrail_CloudWatchLogs_Role",
        "principalId": "AROA3TLZJI375OOYMRDNV",
        "type": "Role",
        "userName": "CloudTrail_CloudWatchLogs_Role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

CreateLookupTable

#
Service
logs

Description

Creates a lookup table by uploading CSV data.

CreateScheduledQuery

#
Service
logs

Description

Creates a scheduled query that runs CloudWatch Logs Insights queries at regular intervals.

DeleteAccountPolicy

#
Service
logs

Description

Deletes a CloudWatch Logs account policy.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Specified resource does not exists!",
  "eventCategory": "Management",
  "eventID": "c9a428c8-b00c-4632-9593-a59a595770de",
  "eventName": "DeleteAccountPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cc89f62d-4747-4511-bf73-4e6d6133db9f",
  "requestParameters": {
    "dryRun": false,
    "policyName": "dw-probe",
    "policyType": "DATA_PROTECTION_POLICY"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDataProtectionPolicy

#
Service
logs

Description

Deletes the data protection policy from the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Log group 'ddddd' for owner '123456789012' cannot be found",
  "eventCategory": "Management",
  "eventID": "adb2de80-3c1d-4f5f-ab98-b01396cd8a96",
  "eventName": "DeleteDataProtectionPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cff46c64-1ed9-44fe-8a9f-4a8c0a45caa7",
  "requestParameters": {
    "logGroupIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDelivery

#
Service
logs

Description

Deletes a delivery.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "80f567f8-e821-47f5-816a-d185ec996a3c",
  "eventName": "DeleteDelivery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "69614889-f3e5-4e85-b1be-6ff48fa76954",
  "requestParameters": {
    "id": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDeliveryDestination

#
Service
logs

Description

Deletes a delivery destination.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery Destination does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "c0a2c6ab-d5fa-4982-bc2b-5049b4c06dd6",
  "eventName": "DeleteDeliveryDestination",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b4e954a7-1b78-42cb-bdbe-12474f65bb90",
  "requestParameters": {
    "name": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDeliveryDestinationPolicy

#
Service
logs

Description

Deletes a delivery destination policy.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery Destination does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "46ced92b-d9be-404f-ac2f-386bee7a7563",
  "eventName": "DeleteDeliveryDestinationPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8e85a083-59e7-4927-8e99-297ba89aeadd",
  "requestParameters": {
    "deliveryDestinationName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDeliverySource

#
Service
logs

Description

Deletes a delivery source.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery Source does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "beb008b1-9d47-47fd-9035-f162a36f70c0",
  "eventName": "DeleteDeliverySource",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ea5624c2-3e29-4b72-b932-569ecb97e6ee",
  "requestParameters": {
    "name": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDestination

#
Service
logs

Description

Deletes the specified destination, and eventually disables all the subscription filters that publish to it.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified destination does not exist.",
  "eventCategory": "Management",
  "eventID": "1934af0a-390c-4bcb-bfc7-efee5ee414f7",
  "eventName": "DeleteDestination",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ee325210-1017-4381-8f96-c5d2451c0a74",
  "requestParameters": {
    "destinationName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIndexPolicy

#
Service
logs

Description

Deletes a log-group level field index policy that was applied to a single log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Log group cannot be found.",
  "eventCategory": "Management",
  "eventID": "4b98db06-c3fd-41ef-a370-0eda18b84f7e",
  "eventName": "DeleteIndexPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8d52b5a0-c2fa-4f3c-a61e-7fc895551a3f",
  "requestParameters": {
    "logGroupIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIntegration

#
Service
logs

Description

Deletes the integration between CloudWatch Logs and OpenSearch Service.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Integration with name ddddd does not exist.",
  "eventCategory": "Management",
  "eventID": "248be184-cc92-4164-9592-50e05deb49b9",
  "eventName": "DeleteIntegration",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "926b7d02-8fef-4315-80ab-98dcd8c3e2ac",
  "requestParameters": {
    "force": false,
    "integrationName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLogAnomalyDetector

#
Service
logs

Description

Deletes the specified CloudWatch Logs anomaly detector.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2d24447f-86e4-4478-ae71-50245d6200d2",
  "eventName": "DeleteLogAnomalyDetector",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:04:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5706580f-5a3b-42ba-8a85-fe5518bbd775",
  "requestParameters": {
    "anomalyDetectorArn": "arn:aws:logs:us-west-1:123456789012:anomaly-detector:a72549c0-450b-429c-b9aa-c636f899356b"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLookupTable

#
Service
logs

Description

Deletes a lookup table permanently.

DeleteMetricFilter

#
Service
logs

Description

Deletes the specified metric filter.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "25bfc4fd-0249-4bde-8631-7bfd9464c13f",
  "eventName": "DeleteMetricFilter",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:12:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "afeb6aa7-a5b4-4cca-b365-8a8fd1fec2c2",
  "requestParameters": {
    "filterName": "dw",
    "logGroupName": "dwfix-lg"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteQueryDefinition

#
Service
logs

Description

Deletes a saved CloudWatch Logs Insights query definition.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Query definition id is invalid. (Service: AWSLogs; Status Code: 400; Error Code: ResourceNotFoundException; Request ID: 8dd0be3d-7c0c-46df-bd18-ac6484b8922e; Proxy: null)",
  "eventCategory": "Management",
  "eventID": "44b53490-a0ba-4473-bca1-abd354e4bcb7",
  "eventName": "DeleteQueryDefinition",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "82593d38-82ad-4225-921e-e5c59d51946b",
  "requestParameters": {
    "queryDefinitionId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteResourcePolicy

#
Service
logs

Description

Deletes a resource policy from this account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "DeleteResourcePolicy request must contain policy name or resource arn.",
  "eventCategory": "Management",
  "eventID": "673a535b-b69c-4068-9256-9b6bb6e55454",
  "eventName": "DeleteResourcePolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:45:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "37554653-f4cd-4102-a7b9-292b7f5198f0",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRetentionPolicy

#
Service
logs

Description

Deletes the specified retention policy.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a9c982a6-9079-4dbb-b611-f32075d64e01",
  "eventName": "DeleteRetentionPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:12:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b48cad33-73a4-4345-974c-dde625dac053",
  "requestParameters": {
    "logGroupName": "dwfix-lg"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteScheduledQuery

#
Service
logs

Description

Deletes a scheduled query and stops all future executions.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Scheduled query with identifier ddddd not found",
  "eventCategory": "Management",
  "eventID": "aca26b66-b897-4af5-b593-67a5c652861e",
  "eventName": "DeleteScheduledQuery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4142caa7-44b5-4264-869e-df464b315a36",
  "requestParameters": {
    "identifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSubscriptionFilter

#
Service
logs

Description

Deletes the specified subscription filter.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified log group does not exist.",
  "eventCategory": "Management",
  "eventID": "28f5e0e7-a447-4bda-a24d-4c2dd2e344d0",
  "eventName": "DeleteSubscriptionFilter",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e5e2a407-5e91-4699-ba9f-930dabcb3b2b",
  "requestParameters": {
    "filterName": "ddddd",
    "logGroupName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSyslogConfiguration

#
Service
logs

Description

Deletes a syslog configuration for a log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "vpcEndpointId is required",
  "eventCategory": "Management",
  "eventID": "61c14ab9-b45a-4db6-b20e-2e10459112ff",
  "eventName": "DeleteSyslogConfiguration",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "210f0abd-efd8-48c0-a642-2c0dff9e1d7f",
  "requestParameters": {
    "logGroupIdentifier": "ddddd",
    "removeAll": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransformer

#
Service
logs

Description

Deletes the log transformer for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified log group does not exist.",
  "eventCategory": "Management",
  "eventID": "89a0398f-a029-4048-849d-1285a9fc2f0d",
  "eventName": "DeleteTransformer",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7f8e4a11-ef47-47f2-bd0b-35b807376aa1",
  "requestParameters": {
    "logGroupIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAccountPolicies

#
Service
logs

Description

Returns a list of all CloudWatch Logs account policies in the account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b7bbee2c-c756-4626-97be-05b0168b2d88",
  "eventName": "DescribeAccountPolicies",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f4df2f82-ec28-41b1-8e1f-80c5bb906458",
  "requestParameters": {
    "policyType": "DATA_PROTECTION_POLICY"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeConfigurationTemplates

#
Service
logs

Description

Use this operation to return the valid and default values that are used when creating delivery sources, delivery destinations, and deliveries.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e1a75195-176b-4eb7-885e-1e641f4cb302",
  "eventName": "DescribeConfigurationTemplates",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e5251c2d-c03b-479e-9894-449e629bc4d2",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDeliveries

#
Service
logs

Description

Retrieves a list of the deliveries that have been created in the account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "97d4f5c2-6810-4f99-8ef4-6772c1fd25be",
  "eventName": "DescribeDeliveries",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0041b5dc-62b2-4fd8-8d2a-89f1091ffc57",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDeliveryDestinations

#
Service
logs

Description

Retrieves a list of the delivery destinations that have been created in the account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3b6e24f0-4d00-4322-891d-1b4db8a0c378",
  "eventName": "DescribeDeliveryDestinations",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b4a1bca4-1b69-417e-ab36-46b8ac862d19",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDeliverySources

#
Service
logs

Description

Retrieves a list of the delivery sources that have been created in the account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1d0064d4-7c4b-4922-ad5d-6fc18fbb7ba9",
  "eventName": "DescribeDeliverySources",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cb36e5c6-3a2b-4aa4-b661-02eaca7b426b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDestinations

#
Service
logs

Description

Lists all your destinations.

Example CloudTrail Event #

{
  "apiVersion": "55606",
  "awsRegion": "us-west-2",
  "eventID": "5f6f9cf0-0a44-4931-9512-f65460f1c1",
  "eventName": "DescribeDestinations",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2018-04-23T10:42:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "03b7608b-46e3-11e8-89fd-cd222d206653",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "150.5.17.8",
  "userAgent": "aws-cli/1.11.139 Python/3.6.3 Linux/4.13.0-38-generic botocore/1.6.6",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeExportTasks

#
Service
logs

Description

Lists the specified export tasks.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "e52b4361-6a22-40a2-8ee4-f326e1bcffe6",
  "eventName": "DescribeExportTasks",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T18:21:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "b61f4715-9d8e-447b-b981-ab55a0aa0c70",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37TTBU6EGN",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

DescribeFieldIndexes

#
Service
logs

Description

Returns a list of custom and default field indexes which are discovered in log data.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Log group cannot be found.",
  "eventCategory": "Management",
  "eventID": "80f41029-fa8c-4999-ab00-a5ce6b2d57bd",
  "eventName": "DescribeFieldIndexes",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "863b146b-3ef8-4c32-b8fd-b3440be046fd",
  "requestParameters": {
    "logGroupIdentifiers": [
      "ddddd"
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:logs:us-west-1:123456789012:log-group:ddddd",
      "accountId": "123456789012",
      "type": "AWS::Logs::LogGroup"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeImportTaskBatches

#
Service
logs

Description

Gets detailed information about the individual batches within an import task, including their status and any error messages.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "ImportId must be a valid UUID format",
  "eventCategory": "Management",
  "eventID": "0011422b-ef5c-424a-b59a-97ebcc90a4f7",
  "eventName": "DescribeImportTaskBatches",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c4b4f850-b688-4239-942a-d6e4f47585b5",
  "requestParameters": {
    "importId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeImportTasks

#
Service
logs

Description

Lists and describes import tasks, with optional filtering by import status and source ARN.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "66ead605-a14e-4e90-80c4-784d5f0303a0",
  "eventName": "DescribeImportTasks",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "10b5ef7a-eb3a-4fc4-a693-c5dc96877ee7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIndexPolicies

#
Service
logs

Description

Returns the field index policies of the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Log group cannot be found.",
  "eventCategory": "Management",
  "eventID": "25b1007d-7a7f-4be4-ae95-cc356c0faa8b",
  "eventName": "DescribeIndexPolicies",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8cd940a0-9c26-40db-8a12-714bffdeafcb",
  "requestParameters": {
    "logGroupIdentifiers": [
      "ddddd"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeLogGroups

#
Service
logs

Description

Returns information about log groups, including data sources that ingest into each log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "2633ba8f-4efe-44e0-a03a-33479e371e64",
  "eventName": "DescribeLogGroups",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2023-07-10T12:02:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6b3ee272-731f-4386-bfc3-75a3cb13dc70",
  "requestParameters": {
    "logGroupNamePrefix": "/stratus-red-team/vpc-flow-logs"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeLogStreams

#
Service
logs

Description

Lists the log streams for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "a4350bb4-73e2-4c83-b5d3-98cfe59bab5c",
  "eventName": "DescribeLogStreams",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T13:21:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "c3849bd6-1668-4271-a81d-db0e5e6add00",
  "requestParameters": {
    "descending": true,
    "limit": 50,
    "logGroupName": "aws-cloudtrail-logs-Trail01",
    "orderBy": "LastEventTime"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37TRWHLD2C",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

DescribeLookupTables

#
Service
logs

Description

Retrieves metadata about lookup tables in your account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c5d568f4-794d-4681-bcec-e7efaf75675e",
  "eventName": "DescribeLookupTables",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d946aae9-67d4-4de5-9595-225ae3b5ac56",
  "requestParameters": {
    "maxResults": 0
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMetricFilters

#
Service
logs

Description

Lists the specified metric filters.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "1edcf00d-d8c0-4c02-b004-3c1b6e9402d6",
  "eventName": "DescribeMetricFilters",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T13:08:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "ea053977-4358-4d59-bf89-471196b83e72",
  "requestParameters": {
    "limit": 50
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37TRWHLD2C",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

DescribeQueries

#
Service
logs

Description

Returns a list of CloudWatch Logs Insights queries that are scheduled, running, or have been run recently in this account.

Example CloudTrail Event #

{
  "apiVersion": "55606",
  "awsRegion": "us-east-1",
  "eventID": "fa40f361-ad43-42e5-8d2e-0726d221fc5c",
  "eventName": "DescribeQueries",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2020-03-06T14:33:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "0ea540859-2a6f-43cf-8f4e-07eac51d1c19",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.35.92.20",
  "userAgent": "Boto3/1.12.15 Python/2.7.17 Linux/4.4.0-039049-Microsoft Botocore/1.15.15",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeQueryDefinitions

#
Service
logs

Description

This operation returns a paginated list of your saved CloudWatch Logs Insights query definitions.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "ca777495-7296-408e-ad30-5849ebcd90fa",
  "eventName": "DescribeQueryDefinitions",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T13:23:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "f41db424-1185-4b9f-8b1f-d50a237a1486",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37TRWHLD2C",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

DescribeResourcePolicies

#
Service
logs

Description

Lists the resource policies in this account.

Example CloudTrail Event #

{
  "apiVersion": "55606",
  "awsRegion": "us-west-2",
  "eventID": "dbfb3479-f5b9-45c3-9bd9-1eb21cd23a0d",
  "eventName": "DescribeResourcePolicies",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2018-01-08T14:48:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "94572cd9-f483-11e7-a9ee-b3eb85f2575d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "254.61.99.239",
  "userAgent": "aws-cli/1.14.10 Python/3.6.4 Darwin/17.3.0 botocore/1.8.14",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeSubscriptionFilters

#
Service
logs

Description

Lists the subscription filters for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "55606",
  "awsRegion": "us-east-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified log group does not exist.",
  "eventID": "5676b286-b090-4cfe-b55d-3cb97853680d",
  "eventName": "DescribeSubscriptionFilters",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2020-05-19T17:44:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "a0906e4e-8f4b-4590-96fb-3a0eac700e99",
  "requestParameters": {
    "logGroupName": "dummy_data"
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DisassociateKmsKey

#
Service
logs

Description

Disassociates the specified KMS key from the specified log group or from all CloudWatch Logs Insights query results in the account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Either logGroupName or resourceIdentifier must be specified",
  "eventCategory": "Management",
  "eventID": "0fd2729f-62e4-4e9b-afe2-8c51e68f4fe8",
  "eventName": "DisassociateKmsKey",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:45:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "943d31a3-f9e4-4196-90cc-7297a1496683",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateSourceFromS3TableIntegration

#
Service
logs

Description

Disassociates a data source from an S3 Table Integration, removing query access and deleting all associated data from the integration.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Association not found for identifier: ddddd",
  "eventCategory": "Management",
  "eventID": "6889b3ce-5b28-46c9-a061-92cd956ab52a",
  "eventName": "DisassociateSourceFromS3TableIntegration",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4f73ff7a-d1e5-4616-a904-312b4f81456e",
  "requestParameters": {
    "identifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

FilterLogEvents

#
Service
logs

Description

Lists log events from the specified log group.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "505f9dcf-1c82-4819-ba49-f7e95f13d994",
  "eventSource": "logs.amazonaws.com",
  "eventName": "FilterLogEvents",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "20140328",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "65cc4d39-42ef-462c-8e74-7c5f357566b2",
  "userAgent": "aws-cli/2.35.4 md/awscrt#0.32.2 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.5 md/pyimpl#CPython exec-env/AmazonQ-For-CLI-Version-2.8.0 m/b,s,Z,r,E,C cfg/retry-mode#standard md/installer#source sid/90e059e87448 md/prompt#off md/command#logs.filter-log-events",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Logs::LogGroup",
      "ARN": "arn:aws:logs:us-east-1:123456789012:log-group:/EXAMPLE"
    }
  ]
}

GetDataProtectionPolicy

#
Service
logs

Description

Returns information about a log group data protection policy.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Log group 'ddddd' for owner '123456789012' cannot be found",
  "eventCategory": "Management",
  "eventID": "6b08f785-be25-4ad7-8fce-fae5d28381e6",
  "eventName": "GetDataProtectionPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3db68578-cedc-42d0-8d4d-0b5818c2f71c",
  "requestParameters": {
    "logGroupIdentifier": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:logs:us-west-1:123456789012:log-group:ddddd:log-stream:",
      "accountId": "123456789012",
      "type": "AWS::Logs::LogGroup"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetDelivery

#
Service
logs

Description

Returns complete information about one logical delivery.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "9397ae0c-2ff4-4a4c-a8e8-1f761914f625",
  "eventName": "GetDelivery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a3fb27ba-f0f5-472a-accb-f4e17ad38f71",
  "requestParameters": {
    "id": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetDeliveryDestination

#
Service
logs

Description

Retrieves complete information about one delivery destination.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery Destination does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "ddbdfec2-c2a4-439f-820b-26cad175a4d6",
  "eventName": "GetDeliveryDestination",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "dceec101-795f-4816-955d-f95f77c47fc4",
  "requestParameters": {
    "name": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetDeliveryDestinationPolicy

#
Service
logs

Description

Retrieves the delivery destination policy assigned to the delivery destination that you specify.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery Destination does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "31ffa72c-e05b-40fb-a524-5ef610eb4d34",
  "eventName": "GetDeliveryDestinationPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "eb3d6d90-cdea-43bc-8f2c-df1f9979ee24",
  "requestParameters": {
    "deliveryDestinationName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetDeliverySource

#
Service
logs

Description

Retrieves complete information about one delivery source.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery Source does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "14b19322-d122-4b81-87b9-1f766c22e527",
  "eventName": "GetDeliverySource",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "65d96b0a-13c7-40cd-8031-1ceb6e12f5fd",
  "requestParameters": {
    "name": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIntegration

#
Service
logs

Description

Returns information about one integration between CloudWatch Logs and OpenSearch Service.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Integration with name ddddd does not exist.",
  "eventCategory": "Management",
  "eventID": "a934ae7d-906a-48bc-b307-ad93785dc7c3",
  "eventName": "GetIntegration",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0a8dc415-312b-45ca-8413-557ce1087f20",
  "requestParameters": {
    "integrationName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetLogAnomalyDetector

#
Service
logs

Description

Retrieves information about the log anomaly detector that you specify.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f7ff6a82-48d0-4bb8-8ecf-67d3c3ddc2fd",
  "eventSource": "logs.amazonaws.com",
  "eventName": "GetLogAnomalyDetector",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "apiVersion": "20140328",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c3e7c243-e16c-41ab-8a7a-3b2e3e7e0f29",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/cloudwatchlogs#1.69.0 m/E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.eu-west-1.amazonaws.com"
  }
}

GetLogEvents

#
Service
logs

Description

Lists log events from the specified log stream.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c1192cb7-e2cf-42ed-bd00-9c5d562f930d",
  "eventSource": "logs.amazonaws.com",
  "eventName": "GetLogEvents",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "20140328",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d06ea733-6af7-4a4d-b889-2da8e54a0956",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Logs::LogStream",
      "ARN": "arn:aws:logs:us-east-1:123456789012:log-group:/EXAMPLE]cd651451fcb842b0bfe0bc95a6e1f4cf"
    }
  ]
}

GetLogFields

#
Service
logs

Description

Discovers available fields for a specific data source and type.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a452ef6d-98e0-46ca-b636-a7ae5626a992",
  "eventName": "GetLogFields",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "440c32a3-09d2-49a0-8e73-cbf9a194f6cf",
  "requestParameters": {
    "dataSourceName": "dw-probe",
    "dataSourceType": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetLogGroupFields

#
Service
logs

Description

Returns a list of the fields that are included in log events in the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "cc43eff4-73fc-41c4-8edb-e45df1550957",
  "eventName": "GetLogGroupFields",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2021-07-07T17:20:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "0f92500c-1d5d-4be9-8ff1-ee349af8f675",
  "requestParameters": {
    "logGroupName": "/aws/eks/Cluster_Galah/cluster"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.252",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:89.0) Gecko/20100101 Firefox/89.0",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37RY6YQCLU",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

GetLogObject

#
Service
logs

Description

Retrieves a large logging object (LLO) and streams it back.

GetLogRecord

#
Service
logs

Description

Retrieves all of the fields and values of a single log event.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: logs:GetLogRecord on resource: arn:aws:logs:us-east-1:811596193553:log-group::log-stream:",
  "eventID": "982189-8b17-4f84-ab5c-0a1623c04e56",
  "eventName": "GetLogRecord",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2020-05-19T17:44:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "0e1a9a56-9d92-4d8c-ba5f-855c5c982b6a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetLookupTable

#
Service
logs

Description

Retrieves the full content of a lookup table, including the CSV data.

GetQueryResults

#
Service
logs

Description

Returns the results from the specified query.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "50a84999-53ff-428c-bd1b-ba2d3c6597bc",
  "eventSource": "logs.amazonaws.com",
  "eventName": "GetQueryResults",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "20140328",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "18a44fae-4a59-49a0-9e09-bb27980c8089",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
  }
}

GetScheduledQuery

#
Service
logs

Description

Retrieves details about a specific scheduled query, including its configuration, execution status, and metadata.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Scheduled query with identifier ddddd not found",
  "eventCategory": "Management",
  "eventID": "dc3dd58a-c254-4608-8cb7-bed3add91d1e",
  "eventName": "GetScheduledQuery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e0b53371-c2f2-4e57-b073-3c58bc6fecf2",
  "requestParameters": {
    "identifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetScheduledQueryHistory

#
Service
logs

Description

Retrieves the execution history of a scheduled query within a specified time range, including query results and destination processing status.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Start time cannot be more than 30 days in the past",
  "eventCategory": "Management",
  "eventID": "86bfe0cb-c1fc-4fe2-9a61-3f198ecf8533",
  "eventName": "GetScheduledQueryHistory",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "61b3de0a-7887-4de2-89c1-5b127731ae1a",
  "requestParameters": {
    "endTime": 1,
    "identifier": "ddddd",
    "startTime": 1
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTransformer

#
Service
logs

Description

Returns the information about the log transformer associated with this log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified log group does not exist.",
  "eventCategory": "Management",
  "eventID": "1b76ee04-19e4-4469-b712-586c700f95b4",
  "eventName": "GetTransformer",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6a17223b-8033-499e-9ecc-bc4954ad44a1",
  "requestParameters": {
    "logGroupIdentifier": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAggregateLogGroupSummaries

#
Service
logs

Description

Returns an aggregate summary of all log groups in the Region grouped by specified data source characteristics.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dcfcea1e-ad85-4a39-a388-83644d230e37",
  "eventName": "ListAggregateLogGroupSummaries",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9b61ad27-26b8-4103-9ffb-80d67674df76",
  "requestParameters": {
    "accountIdentifiers": [
      "123456789012"
    ],
    "groupBy": "DATA_SOURCE_NAME_TYPE_AND_FORMAT"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAnomalies

#
Service
logs

Description

Returns a list of anomalies that log anomaly detectors have found.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "89645a09-fe1b-4c38-85b9-617afbb90883",
  "eventName": "ListAnomalies",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cf51cd87-1680-43b3-b603-a748814822b7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListIntegrations

#
Service
logs

Description

Returns a list of integrations between CloudWatch Logs and other services in this account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "55d43e17-b1dd-4ca5-9dc0-34d09c49886c",
  "eventName": "ListIntegrations",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f9c9c47f-929d-4853-b0b8-a62c3caebe1d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListLogAnomalyDetectors

#
Service
logs

Description

Retrieves a list of the log anomaly detectors in the account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "07670b6f-7bef-4b93-9c9f-d6c792f7d39e",
  "eventName": "ListLogAnomalyDetectors",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "13d3376d-b2f1-49c4-be29-e1738e7d9c04",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListLogGroups

#
Service
logs

Description

Returns a list of log groups in the Region in your account.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "74da2140-a14a-4916-8efd-c0ee7c28a9ea",
  "eventName": "ListLogGroups",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "68121750-6cd9-4b1a-9180-82ec451d3ae1",
  "requestParameters": {
    "accountIdentifiers": [
      "123456789012"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListLogGroupsForQuery

#
Service
logs

Description

Returns a list of the log groups that were analyzed during a single CloudWatch Logs Insights query.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "An unknown error occurred",
  "eventCategory": "Management",
  "eventID": "00e361b6-8d42-4c55-81b8-0eda3fdc7baa",
  "eventName": "ListLogGroupsForQuery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "017203d0-b81d-46ee-b9f9-aff9a993a7f1",
  "requestParameters": {
    "queryId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListScheduledQueries

#
Service
logs

Description

Lists all scheduled queries in your account and region.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a808d01a-88bb-451a-9bff-f7f54747a795",
  "eventName": "ListScheduledQueries",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8162ebc2-c082-4e8b-b79b-713f5fb1bcf7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListSourcesForS3TableIntegration

#
Service
logs

Description

Returns a list of data source associations for a specified S3 Table Integration, showing which data sources are currently associated for query access.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Invalid S3 table integration ARN format. Expected: s3tableintegration/{integration-id}: arn:aws:iam::123456789012:role/dw-probe",
  "eventCategory": "Management",
  "eventID": "da37b8af-35fd-40b5-bd77-e471dc0d9b1a",
  "eventName": "ListSourcesForS3TableIntegration",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "53e3b56c-c3ed-4a26-b72f-b97a7d8d918e",
  "requestParameters": {
    "integrationArn": "arn:aws:iam::123456789012:role/dw-probe",
    "maxResults": 0
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListSyslogConfigurations

#
Service
logs

Description

Returns a list of syslog configurations.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "37cdf3ce-7d0a-4982-981c-820486589f7e",
  "eventName": "ListSyslogConfigurations",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b5e7c7e6-5410-4a72-8e91-734757fd4479",
  "requestParameters": {
    "maxResults": 0
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTagsForResource

#
Service
logs

Description

Displays the tags associated with a CloudWatch Logs resource.

ListTagsLogGroup

#
Service
logs

Description

The ListTagsLogGroup operation is on the path to deprecation.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "9283ebb4-3daf-4052-a4f2-52eb0a29f074",
  "eventName": "ListTagsLogGroup",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2023-07-10T12:02:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "30daf7a2-0d64-468c-b195-2470dd609b5c",
  "requestParameters": {
    "logGroupName": "/stratus-red-team/vpc-flow-logs"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "logs.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

PutAccountPolicy

#
Service
logs

Description

Creates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combinat.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Invalid selection criteria provided.",
  "eventCategory": "Management",
  "eventID": "c264e17c-4d67-4826-867a-d1ca9b14c20c",
  "eventName": "PutAccountPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "853c07f4-1df3-4f5a-82a8-823606be0ba8",
  "requestParameters": {
    "dryRun": false,
    "policyDocument": {
      "Fields": [
        "level",
        "requestId"
      ]
    },
    "policyName": "dwfix-ap-vx8ojsm7",
    "policyType": "FIELD_INDEX_POLICY",
    "selectionCriteria": "LogGroupName = \"dwfix-logs-vx8ojsm7\""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBearerTokenAuthentication

#
Service
logs

Description

Enables or disables bearer token authentication for the specified log group.

PutDataProtectionPolicy

#
Service
logs

Description

Creates a data protection policy for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Policy can only have two statements. One for Audit Operation and one for Deidentify Operation",
  "eventCategory": "Management",
  "eventID": "bbc05834-f8cf-41bd-8680-ac3d4e6b3694",
  "eventName": "PutDataProtectionPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:04:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9ada9748-1abc-4ac3-b159-53b80215ffd7",
  "requestParameters": {
    "logGroupIdentifier": "dwfix-lg2",
    "policyDocument": {
      "Name": "dw",
      "Version": "2021-06-01",
      "Statement": [
        {
          "Sid": "a",
          "DataIdentifier": [
            "arn:aws:dataprotection::aws:data-identifier/EmailAddress"
          ],
          "Operation": {
            "Audit": {
              "FindingsDestination": {}
            }
          }
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutDeliveryDestination

#
Service
logs

Description

Creates or updates a logical delivery destination.

PutDeliveryDestinationPolicy

#
Service
logs

Description

Creates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account.

PutDeliverySource

#
Service
logs

Description

Creates or updates a logical delivery source.

PutDestination

#
Service
logs

Description

Creates or updates a destination.

PutDestinationPolicy

#
Service
logs

Description

Creates or updates an access policy associated with an existing destination.

PutIndexPolicy

#
Service
logs

Description

Creates or updates a field index policy for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "74f64219-edd2-45d1-a7d0-aca6e38d889c",
  "eventName": "PutIndexPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "60634013-8d05-48d5-aaf2-52d354ad7ffe",
  "requestParameters": {
    "logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
    "policyDocument": {
      "Fields": [
        "level",
        "requestId",
        "errorCode"
      ]
    }
  },
  "responseElements": {
    "indexPolicy": {
      "lastUpdateTime": 1782766740731,
      "logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
      "policyDocument": {
        "Fields": [
          "level",
          "requestId",
          "errorCode"
        ]
      },
      "source": "LOG_GROUP"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutIntegration

#
Service
logs

Description

Creates an integration between CloudWatch Logs and another service in this account.

PutLogEvents

#
Service
logs

Description

Uploads a batch of log events to the specified log stream.

PutLogGroupDeletionProtection

#
Service
logs

Description

Enables or disables deletion protection for the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d33d7eab-c71c-42e0-8637-a75991ca63d2",
  "eventName": "PutLogGroupDeletionProtection",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3c56d6c2-e5ce-40c1-bc42-4b7bdbeeb69f",
  "requestParameters": {
    "deletionProtectionEnabled": true,
    "logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutMetricFilter

#
Service
logs

Description

Creates or updates a metric filter and associates it with the specified log group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: logs:PutMetricFilter on resource: arn:aws:logs:us-west-2:811596193553:log-group:sec545-logging-hampsterdam:log-stream:",
  "eventID": "e03464a-547d-44f8-82ca-ffd6ddd287d6",
  "eventName": "PutMetricFilter",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2020-02-28T20:41:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "4e5b3318-18c9-4b8b-9445-158437b5b1",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "250.0.35.1",
  "userAgent": "aws-cli/1.18.5 Python/3.7.0 Windows/10 botocore/1.15.5",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

PutQueryDefinition

#
Service
logs

Description

Creates or updates a query definition for CloudWatch Logs Insights.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0514d305-e7aa-4fba-a937-5019056945ae",
  "eventName": "PutQueryDefinition",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:04:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "59cdb4ed-4d49-43b6-a0c1-2e486d98a9e8",
  "requestParameters": {
    "clientToken": "529526c8-55ac-4882-ba56-f4f139de156e",
    "name": "dwfix-q",
    "queryLanguage": "CWLI",
    "queryString": "fields @timestamp"
  },
  "responseElements": {
    "queryDefinitionId": "3630c631-ac9c-4655-9ea3-737267e3f655"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutResourcePolicy

#
Service
logs

Description

Creates or updates a resource policy allowing other Amazon Web Services services to put log events to this account, such as Amazon Route 53.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "18055e58-b015-4433-92ce-2bcf91a487e1",
  "eventName": "PutResourcePolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7f49fef4-e94d-4dbc-9930-cbfac748b747",
  "requestParameters": {
    "policyDocument": {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DwFixDeliveryAccess",
          "Effect": "Allow",
          "Principal": {
            "Service": "delivery.logs.amazonaws.com"
          },
          "Action": [
            "logs:PutLogEvents",
            "logs:CreateLogStream"
          ],
          "Resource": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7:*",
          "Condition": {
            "StringEquals": {
              "aws:SourceAccount": "123456789012"
            }
          }
        }
      ]
    },
    "policyName": "dwfix-rp-vx8ojsm7"
  },
  "responseElements": {
    "resourcePolicy": {
      "lastUpdatedTime": 1782766741408,
      "policyDocument": {
        "Version": "2012-10-17",
        "Statement": [
          {
            "Sid": "DwFixDeliveryAccess",
            "Effect": "Allow",
            "Principal": {
              "Service": "delivery.logs.amazonaws.com"
            },
            "Action": [
              "logs:PutLogEvents",
              "logs:CreateLogStream"
            ],
            "Resource": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7:*",
            "Condition": {
              "StringEquals": {
                "aws:SourceAccount": "123456789012"
              }
            }
          }
        ]
      },
      "policyName": "dwfix-rp-vx8ojsm7",
      "policyScope": "ACCOUNT"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutRetentionPolicy

#
Service
logs

Description

Sets the retention of the specified log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4acbd1f7-90ba-4679-a41b-2d6397d165d8",
  "eventName": "PutRetentionPolicy",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:12:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6d5ce61b-7073-44be-bbda-25b4b8337614",
  "requestParameters": {
    "logGroupName": "dwfix-lg",
    "retentionInDays": 1
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutSubscriptionFilter

#
Service
logs

Description

Creates or updates a subscription filter and associates it with the specified log group.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3cbf550c-ebcc-3e60-9bef-cdf2604e195f",
  "eventSource": "logs.amazonaws.com",
  "eventName": "PutSubscriptionFilter",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "apiVersion": "20140328",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "50d6c6d0-194d-4bad-8aa7-7f767f8ce363",
  "userAgent": "application-insights.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Logs::Destination",
      "ARN": "arn:aws:logs:eu-west-1:123456789012:destination:EXAMPLE"
    },
    {
      "accountId": "123456789012",
      "type": "AWS::Logs::LogGroup",
      "ARN": "arn:aws:logs:eu-west-1:123456789012:log-group:EXAMPLE"
    }
  ]
}

PutSyslogConfiguration

#
Service
logs

Description

Creates or updates a syslog configuration for a log group.

PutTransformer

#
Service
logs

Description

Creates or updates a log transformer for a single log group.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Transformer config should begin with parser. Allowed parsers are parsePostgres, parseWAF, parseCloudfront, parseCloudfrontOCSF, parseRoute53, parseLambda, parseVPC, parseSyslog, parseRDS, parseCiscoFTD, parseToOCSF, parseJSON, grok, csv, parseKeyValue",
  "eventCategory": "Management",
  "eventID": "9d358936-e39a-45ea-b863-d4f04f245984",
  "eventName": "PutTransformer",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e1ce3ad1-0a39-45de-82ea-316a557b9de9",
  "requestParameters": {
    "logGroupIdentifier": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
    "transformerConfig": [
      {
        "lowerCaseString": {
          "withKeys": [
            "level"
          ]
        }
      },
      {
        "addKeys": {
          "entries": [
            {
              "key": "dwfix_processed",
              "overwriteIfExists": true,
              "value": "true"
            }
          ]
        }
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartLiveTail

#
Service
logs

Description

Starts a Live Tail streaming session for one or more log groups.

StartQuery

#
Service
logs

Description

Starts a query of one or more log groups or data sources using CloudWatch Logs Insights.

Example CloudTrail Event #

{
  "additionalEventData": {
    "queryId": "f21f44f0-56fb-4275-83c6-23ac74b87269"
  },
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "01d99b94-363e-4fbd-9be8-cd6a42944ca4",
  "eventName": "StartQuery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7a7e9f67-817b-46ea-9f61-7c046d35472b",
  "requestParameters": {
    "dryRun": false,
    "endTime": 1782766741,
    "forceAnalyticsTier": false,
    "logGroupName": "dwfix-logs-vx8ojsm7",
    "queryLanguage": "CWLI",
    "queryString": "fields @timestamp, @message | limit 3",
    "startTime": 1782766441
  },
  "resources": [
    {
      "ARN": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
      "accountId": "123456789012",
      "type": "AWS::Logs::LogGroup"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StopQuery

#
Service
logs

Description

Stops a CloudWatch Logs Insights query that is in progress.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The provided queryId=ddddd is invalid.",
  "eventCategory": "Management",
  "eventID": "bd002fd3-3c83-4236-9025-c6088d48b3c2",
  "eventName": "StopQuery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ca99a9be-7c45-4cd8-9d58-5ac019aed61f",
  "requestParameters": {
    "dryRun": false,
    "queryId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TagLogGroup

#
Service
logs

Description

The TagLogGroup operation is on the path to deprecation.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ce406901-dc31-4366-8529-a45bc475938e",
  "eventName": "TagLogGroup",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:12:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0fbf2599-0998-4808-95a7-99b021bb18a5",
  "requestParameters": {
    "logGroupName": "dwfix-lg",
    "tags": {
      "dw": "f"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TagResource

#
Service
logs

Description

Assigns one or more tags (key-value pairs) to the specified CloudWatch Logs resource.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e8fd4c1e-7101-47c6-bcf5-9d05e7425fdf",
  "eventName": "TagResource",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9b1b9d57-e0c5-46b0-9ff7-3a43dc0392e9",
  "requestParameters": {
    "resourceArn": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
    "tags": {
      "env": "dwfix",
      "recipe": "logs",
      "tier": "test"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TestMetricFilter

#
Service
logs

Description

Tests the filter pattern of a metric filter against a sample of log event messages.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: logs:TestMetricFilter on resource: arn:aws:logs:us-east-1:811596193553:log-group::log-stream:",
  "eventID": "ec182c55-66de-4008-a4f5-b1fd66fdc04d",
  "eventName": "TestMetricFilter",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2020-05-19T17:44:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "d60ef732-94a3-460f-bcf3-8ddef950fc83",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

TestTransformer

#
Service
logs

Description

Use this operation to test a log transformer.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Transformer config should begin with parser. Allowed parsers are parsePostgres, parseWAF, parseCloudfront, parseCloudfrontOCSF, parseRoute53, parseLambda, parseVPC, parseSyslog, parseRDS, parseCiscoFTD, parseToOCSF, parseJSON, grok, csv, parseKeyValue",
  "eventCategory": "Management",
  "eventID": "c11e6c80-d6e3-4ddb-9764-ba5d06f0aad3",
  "eventName": "TestTransformer",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cd6dd587-48ab-4af6-b00e-6d940e10d8b8",
  "requestParameters": {
    "logEventMessages": [
      {
        "level": "ERROR",
        "requestId": "abc-123",
        "msg": "test"
      },
      {
        "level": "INFO",
        "requestId": "def-456",
        "msg": "ok"
      }
    ],
    "transformerConfig": [
      {
        "lowerCaseString": {
          "withKeys": [
            "level"
          ]
        }
      },
      {
        "addKeys": {
          "entries": [
            {
              "key": "dwfix_processed",
              "overwriteIfExists": true,
              "value": "true"
            }
          ]
        }
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UntagLogGroup

#
Service
logs

Description

The UntagLogGroup operation is on the path to deprecation.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "The specified log group does not exist.",
  "eventCategory": "Management",
  "eventID": "ee4c946c-2731-49a8-b3d7-bdac113cbbd3",
  "eventName": "UntagLogGroup",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cc6df18e-2ee7-40f1-8483-710980ab6a4b",
  "requestParameters": {
    "logGroupName": "ddddd",
    "tags": [
      "ddddd"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UntagResource

#
Service
logs

Description

Removes one or more tags from the specified resource.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "25b3330b-547b-408b-b666-b4b9034f7c48",
  "eventName": "UntagResource",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T20:59:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7d052d99-a303-458c-89b2-faec011d7d6d",
  "requestParameters": {
    "resourceArn": "arn:aws:logs:us-west-1:123456789012:log-group:dwfix-logs-vx8ojsm7",
    "tagKeys": [
      "env",
      "recipe",
      "tier",
      "updated"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateAnomaly

#
Service
logs

Description

Use this operation to suppress anomaly detection for a specified anomaly or pattern.

UpdateDeliveryConfiguration

#
Service
logs

Description

Use this operation to update the configuration of a delivery to change either the S3 path pattern or the format of the delivered logs.

Example CloudTrail Event #

{
  "apiVersion": "20140328",
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "Requested Delivery does not exist in this account.",
  "eventCategory": "Management",
  "eventID": "24869d5b-2e2e-4f86-af4e-4e36efdae10b",
  "eventName": "UpdateDeliveryConfiguration",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e7dd899f-1f75-4b02-a3d5-046b2fc3cb7c",
  "requestParameters": {
    "id": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateLogAnomalyDetector

#
Service
logs

Description

Updates an existing log anomaly detector.

UpdateLookupTable

#
Service
logs

Description

Updates an existing lookup table by replacing all of its CSV content.

UpdateScheduledQuery

#
Service
logs

Description

Updates an existing scheduled query with new configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Cross-account pass role is not allowed.",
  "eventCategory": "Management",
  "eventID": "c7e66248-69fc-4465-a1df-bb1153adb43d",
  "eventName": "UpdateScheduledQuery",
  "eventSource": "logs.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ebb615ce-c594-4396-bb71-b3953921282b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "logs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetStorageTierPolicy

#
Service
logs

Description

Returns the storage tier policy for the account.

PutStorageTierPolicy

#
Service
logs

Description

Sets the storage tier policy for the account.