Macie

eventNameDescriptionSampleRule
anyCatch-all entry for Macie rules that match the service but not a specific eventName.NN
CreateFindingsFilterCreates a findings filter rule in Amazon Macie that automatically archives or suppresses findings matching specified criteria.YY
DeleteMemberRemoves an account from the set of member accounts managed by the Amazon Macie administrator account.YN
DisableMacieDisables Amazon Macie for the current account and deletes the Macie service-linked role.YY
DisableOrganizationAdminAccountRevokes the designation of an account as the Amazon Macie delegated administrator for an AWS Organizations organization.YN
DisassociateFromMasterAccountDisassociates the current Macie member account from its administrator account, ending the membership relationship.YN
DisassociateMemberDisassociates a member account from the Amazon Macie administrator account, revoking the administrator's access to findings for that member.YN
UpdateClassificationJobUpdates the status or configuration of an Amazon Macie S3 data classification job.YY
UpdateFindingsFilterUpdates the criteria, action, or name of an existing Amazon Macie findings filter.YY
UpdateMacieSessionUpdates the configuration or status of the Amazon Macie session for the current account, such as enabling or suspending Macie.YY
UpdateMemberSessionUpdates the Amazon Macie status for a member account, enabling or suspending Macie for that account from the administrator account.YY
AcceptInvitationAccepts an Amazon Macie membership invitation that was received from a specific account.NN
BatchGetCustomDataIdentifiersRetrieves information about one or more custom data identifiers.YN
BatchUpdateAutomatedDiscoveryAccountsChanges the status of automated sensitive data discovery for one or more accounts.NN
CreateAllowListCreates and defines the settings for an allow list.YN
CreateClassificationJobCreates and defines the settings for a classification job.NN
CreateCustomDataIdentifierCreates and defines the criteria and other settings for a custom data identifier.YN
CreateInvitationsSends an Amazon Macie membership invitation to one or more accounts.NN
CreateMemberAssociates an account with an Amazon Macie administrator account.NN
CreateSampleFindingsCreates sample findings.YN
DeclineInvitationsDeclines Amazon Macie membership invitations that were received from specific accounts.NN
DeleteAllowListDeletes an allow list.YN
DeleteCustomDataIdentifierSoft deletes a custom data identifier.YN
DeleteFindingsFilterDeletes a findings filter.YN
DeleteInvitationsDeletes Amazon Macie membership invitations that were received from specific accounts.YN
DescribeBucketsRetrieves (queries) statistical data and other information about one or more S3 buckets that Amazon Macie monitors and analyzes for an account.YN
DescribeClassificationJobRetrieves the status and settings for a classification job.YN
DescribeOrganizationConfigurationRetrieves the Amazon Macie configuration settings for an organization in Organizations.YN
DisassociateFromAdministratorAccountDisassociates a member account from its Amazon Macie administrator account.YN
EnableMacieEnables Amazon Macie and specifies the configuration settings for a Macie account.YN
EnableOrganizationAdminAccountDesignates an account as the delegated Amazon Macie administrator account for an organization in Organizations.NN
GetAdministratorAccountRetrieves information about the Amazon Macie administrator account for an account.YN
GetAllowListRetrieves the settings and status of an allow list.YN
GetAutomatedDiscoveryConfigurationRetrieves the configuration settings and status of automated sensitive data discovery for an organization or standalone account.YN
GetBucketStatisticsRetrieves (queries) aggregated statistical data about all the S3 buckets that Amazon Macie monitors and analyzes for an account.YN
GetClassificationExportConfigurationRetrieves the configuration settings for storing data classification results.YN
GetClassificationScopeRetrieves the classification scope settings for an account.YN
GetCustomDataIdentifierRetrieves the criteria and other settings for a custom data identifier.YN
GetFindingsRetrieves the details of one or more findings.YN
GetFindingsFilterRetrieves the criteria and other settings for a findings filter.YN
GetFindingsPublicationConfigurationRetrieves the configuration settings for publishing findings to Security Hub.YN
GetFindingStatisticsRetrieves (queries) aggregated statistical data about findings.YN
GetInvitationsCountRetrieves the count of Amazon Macie membership invitations that were received by an account.YN
GetMacieSessionRetrieves the status and configuration settings for an Amazon Macie account.YN
GetMasterAccount(Deprecated) Retrieves information about the Amazon Macie administrator account for an account.YN
GetMemberRetrieves information about an account that's associated with an Amazon Macie administrator account.YN
GetResourceProfileRetrieves (queries) sensitive data discovery statistics and the sensitivity score for an S3 bucket.YN
GetRevealConfigurationRetrieves the status and configuration settings for retrieving occurrences of sensitive data reported by findings.YN
GetSensitiveDataOccurrencesRetrieves occurrences of sensitive data reported by a finding.YN
GetSensitiveDataOccurrencesAvailabilityChecks whether occurrences of sensitive data can be retrieved for a finding.YN
GetSensitivityInspectionTemplateRetrieves the settings for the sensitivity inspection template for an account.YN
GetUsageStatisticsRetrieves (queries) quotas and aggregated usage data for one or more accounts.YN
GetUsageTotalsRetrieves (queries) aggregated usage data for an account.YN
ListAllowListsRetrieves a subset of information about all the allow lists for an account.YN
ListAutomatedDiscoveryAccountsRetrieves the status of automated sensitive data discovery for one or more accounts.YN
ListClassificationJobsRetrieves a subset of information about one or more classification jobs.YN
ListClassificationScopesRetrieves a subset of information about the classification scope for an account.YN
ListCustomDataIdentifiersRetrieves a subset of information about the custom data identifiers for an account.YN
ListFindingsRetrieves a subset of information about one or more findings.YN
ListFindingsFiltersRetrieves a subset of information about all the findings filters for an account.YN
ListInvitationsRetrieves information about Amazon Macie membership invitations that were received by an account.YN
ListManagedDataIdentifiersRetrieves information about all the managed data identifiers that Amazon Macie currently provides.YN
ListMembersRetrieves information about the accounts that are associated with an Amazon Macie administrator account.YN
ListOrganizationAdminAccountsRetrieves information about the delegated Amazon Macie administrator account for an organization in Organizations.YN
ListResourceProfileArtifactsRetrieves information about objects that Amazon Macie selected from an S3 bucket for automated sensitive data discovery.YN
ListResourceProfileDetectionsRetrieves information about the types and amount of sensitive data that Amazon Macie found in an S3 bucket.YN
ListSensitivityInspectionTemplatesRetrieves a subset of information about the sensitivity inspection template for an account.YN
ListTagsForResourceRetrieves the tags (keys and values) that are associated with an Amazon Macie resource.YN
PutClassificationExportConfigurationAdds or updates the configuration settings for storing data classification results.NN
PutFindingsPublicationConfigurationUpdates the configuration settings for publishing findings to Security Hub.YN
SearchResourcesRetrieves (queries) statistical data and other information about Amazon Web Services resources that Amazon Macie monitors and analyzes for an account.YN
TagResourceAdds or updates one or more tags (keys and values) that are associated with an Amazon Macie resource.YN
TestCustomDataIdentifierTests criteria for a custom data identifier.YN
UntagResourceRemoves one or more tags (keys and values) from an Amazon Macie resource.YN
UpdateAllowListUpdates the settings for an allow list.YN
UpdateAutomatedDiscoveryConfigurationChanges the configuration settings and status of automated sensitive data discovery for an organization or standalone account.YN
UpdateClassificationScopeUpdates the classification scope settings for an account.YN
UpdateOrganizationConfigurationUpdates the Amazon Macie configuration settings for an organization in Organizations.YN
UpdateResourceProfileUpdates the sensitivity score for an S3 bucket.YN
UpdateResourceProfileDetectionsUpdates the sensitivity scoring settings for an S3 bucket.YN
UpdateRevealConfigurationUpdates the status and configuration settings for retrieving occurrences of sensitive data reported by findings.YN
UpdateSensitivityInspectionTemplateUpdates the settings for the sensitivity inspection template for an account.YN

any: Macie (catch-all)

#
Service
macie2

Description

Catch-all entry for Macie rules that match the service but not a specific eventName.

CreateFindingsFilter

#
Service
macie2

Description

Creates a findings filter rule in Amazon Macie that automatically archives or suppresses findings matching specified criteria.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "10b7f426-7ff7-4325-af8a-d4f44dbc6f1b",
  "eventName": "CreateFindingsFilter",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f02622a9-3de2-460c-909e-bceaab36f154",
  "requestParameters": {
    "action": "NOOP",
    "clientToken": "1cb01d12-c160-4ace-a96b-211916f7875e",
    "description": "dwfix test findings filter",
    "findingCriteria": {
      "criterion": {
        "severity.description": {
          "eq": [
            "High"
          ]
        }
      }
    },
    "name": "dwfix-ff-206c92d2",
    "tags": {
      "dwfix": "true"
    }
  },
  "responseElements": {
    "arn": "arn:aws:macie2:us-west-1:123456789012:findings-filter/712877ee-87ff-427d-bc8c-7d57272d2991",
    "id": "712877ee-87ff-427d-bc8c-7d57272d2991"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteMember

#
Service
macie2

Description

Removes an account from the set of member accounts managed by the Amazon Macie administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "5d82d707-e8d6-42c4-b1d1-454c93bbb4a0",
  "eventName": "DeleteMember",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7a33901f-a0a7-4b94-bbc8-b3aa8e76cac6",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "message": "Macie is not enabled"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableMacie

#
Service
macie2

Description

Disables Amazon Macie for the current account and deletes the Macie service-linked role.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "f2905533-b944-4cb8-ae5a-4e0183855251",
  "eventName": "DisableMacie",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eec92787-d760-4127-9c63-e43851879aa2",
  "requestParameters": null,
  "responseElements": {
    "message": "Macie is not enabled"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DisableOrganizationAdminAccount

#
Service
macie2

Description

Revokes the designation of an account as the Amazon Macie delegated administrator for an AWS Organizations organization.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "68aa8ec9-9584-4e19-8070-282077218fc0",
  "eventName": "DisableOrganizationAdminAccount",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "61a2c832-0fc8-49f7-9329-9c2b562c4600",
  "requestParameters": {
    "adminAccountId": "dw-probe"
  },
  "responseElements": {
    "message": "1 validation error detected: Value 'dw-probe' at 'adminAccountId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9]{12}"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateFromMasterAccount

#
Service
macie2

Description

Disassociates the current Macie member account from its administrator account, ending the membership relationship.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "bada3b1b-a6ab-41fd-be3a-19d411175746",
  "eventName": "DisassociateFromMasterAccount",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f30f9252-b93f-4fe8-8d62-03477615472c",
  "requestParameters": null,
  "responseElements": {
    "message": "Macie is not enabled"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateMember

#
Service
macie2

Description

Disassociates a member account from the Amazon Macie administrator account, revoking the administrator's access to findings for that member.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "5a19c734-f46e-4ad1-8439-a18845edc212",
  "eventName": "DisassociateMember",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0d11bc99-6801-40e1-b818-a91b9b5ebe4c",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "message": "1 validation error detected: Value 'dw-probe' at 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9]{12}"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateClassificationJob

#
Service
macie2

Description

Updates the status or configuration of an Amazon Macie S3 data classification job.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "aeac6276-cada-4b64-90f7-3cadf7e28029",
  "eventName": "UpdateClassificationJob",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "57bc8630-4bd7-4ac7-a1a8-bbe38e38c6fd",
  "requestParameters": {
    "jobId": "dw-probe",
    "jobStatus": "RUNNING"
  },
  "responseElements": {
    "errorCode": "AccessDeniedException",
    "message": "Macie is not enabled."
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

UpdateFindingsFilter

#
Service
macie2

Description

Updates the criteria, action, or name of an existing Amazon Macie findings filter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "d1f6cd2b-af02-45e8-94bd-a25e391aad4f",
  "eventName": "UpdateFindingsFilter",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2ba5b26b-c34f-4965-88dd-39e5a7769258",
  "requestParameters": {
    "clientToken": "a04c8ccf-f966-4d46-94af-870971f8e58d",
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

UpdateMacieSession

#
Service
macie2

Description

Updates the configuration or status of the Amazon Macie session for the current account, such as enabling or suspending Macie.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9da96cc0-4b94-485a-9b92-65429dde8740",
  "eventName": "UpdateMacieSession",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e20babd4-81f1-4819-be0e-817ea8b54584",
  "requestParameters": {
    "findingPublishingFrequency": "ONE_HOUR"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

UpdateMemberSession

#
Service
macie2

Description

Updates the Amazon Macie status for a member account, enabling or suspending Macie for that account from the administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "1195742c-f990-4a70-8e59-dac88704db5d",
  "eventName": "UpdateMemberSession",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c6003d6d-2902-4b2c-8930-06f0264242ef",
  "requestParameters": {
    "id": "dw-probe",
    "status": "PAUSED"
  },
  "responseElements": {
    "message": "1 validation error detected: Value 'dw-probe' at 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9]{12}"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

AcceptInvitation

#
Service
macie2

Description

Accepts an Amazon Macie membership invitation that was received from a specific account.

BatchGetCustomDataIdentifiers

#
Service
macie2

Description

Retrieves information about one or more custom data identifiers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "196494f0-aba8-4a40-a6cb-ec2bcd2f6eb7",
  "eventName": "BatchGetCustomDataIdentifiers",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c82d7215-1285-4ff0-8619-dbc7da842e05",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

BatchUpdateAutomatedDiscoveryAccounts

#
Service
macie2

Description

Changes the status of automated sensitive data discovery for one or more accounts.

CreateAllowList

#
Service
macie2

Description

Creates and defines the settings for an allow list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "54845f10-2e74-4f6e-9a67-8665f0fe84da",
  "eventName": "CreateAllowList",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4493b08d-16d0-4ba0-b858-2f48aac48e5c",
  "requestParameters": {
    "clientToken": "f82636ff-1a93-4f69-ac4b-0a4cf8f31349",
    "criteria": {
      "regex": "***"
    },
    "description": "dwfix test allow list — safe to delete",
    "name": "dwfix-al-707bcee2",
    "tags": {
      "dwfix": "true"
    }
  },
  "responseElements": {
    "arn": "arn:aws:macie2:us-west-1:123456789012:allow-list/3xufg2bfclxgufwnqjlg55",
    "id": "3xufg2bfclxgufwnqjlg55"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateClassificationJob

#
Service
macie2

Description

Creates and defines the settings for a classification job.

CreateCustomDataIdentifier

#
Service
macie2

Description

Creates and defines the criteria and other settings for a custom data identifier.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "adeef724-aa99-4fdb-82d5-480b67995d3b",
  "eventName": "CreateCustomDataIdentifier",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5b7b6354-27c8-4f4a-b3f5-0eda01f3aed1",
  "requestParameters": {
    "clientToken": "3060fc1d-6f8b-44ca-b735-1c3bff97dfec",
    "description": "dwfix test custom data identifier — safe to delete",
    "keywords": [
      "SSN",
      "social security"
    ],
    "name": "dwfix-cdi-159ba078",
    "regex": "***",
    "tags": {
      "Purpose": "sample-collection",
      "dwfix": "true"
    }
  },
  "responseElements": {
    "customDataIdentifierId": "87db561c-4124-42dc-bf53-1e36c5141358"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateInvitations

#
Service
macie2

Description

Sends an Amazon Macie membership invitation to one or more accounts.

CreateMember

#
Service
macie2

Description

Associates an account with an Amazon Macie administrator account.

CreateSampleFindings

#
Service
macie2

Description

Creates sample findings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "60b924a3-188c-407b-bd46-bed7ccadb3ed",
  "eventName": "CreateSampleFindings",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "62b003bc-ecc7-4552-81d0-b188d6d3a658",
  "requestParameters": {
    "findingTypes": [
      "Policy:IAMUser/S3BucketPublic"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeclineInvitations

#
Service
macie2

Description

Declines Amazon Macie membership invitations that were received from specific accounts.

DeleteAllowList

#
Service
macie2

Description

Deletes an allow list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "ff98fd9f-5fa9-4321-b892-990db7ba6d7a",
  "eventName": "DeleteAllowList",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "60a3feae-68d1-4947-823d-d464fa3a0e01",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "message": "2 validation errors detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-z0-9]{22}; Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 22"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCustomDataIdentifier

#
Service
macie2

Description

Soft deletes a custom data identifier.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "9305176c-f1db-4bac-ac4d-2d3ee4f4b762",
  "eventName": "DeleteCustomDataIdentifier",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d2ac0b6a-ff9c-49cb-aa51-ced4d6a61098",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "message": "2 validation errors detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 36; Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}$"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteFindingsFilter

#
Service
macie2

Description

Deletes a findings filter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "eb04b51e-ad8e-4b05-ab7a-6b890e7a0e49",
  "eventName": "DeleteFindingsFilter",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "579ea4b4-dbe4-4648-8b0b-d447de91562d",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "message": "1 validation error detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 32"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInvitations

#
Service
macie2

Description

Deletes Amazon Macie membership invitations that were received from specific accounts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "03c1de93-9e28-4d4b-83f7-f4604f9b1cc2",
  "eventName": "DeleteInvitations",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "280f79f2-f5e9-454f-b88e-25c035014ade",
  "requestParameters": {
    "accountIds": [
      "dw-probe"
    ]
  },
  "responseElements": {
    "message": "1 validation error detected: Value '[dw-probe]' at 'accountIds' failed to satisfy constraint: Member must satisfy constraint: [Member must satisfy regular expression pattern: [0-9]{12}]"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeBuckets

#
Service
macie2

Description

Retrieves (queries) statistical data and other information about one or more S3 buckets that Amazon Macie monitors and analyzes for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "0323bb93-3705-42b4-97d3-6ab9d39876",
  "eventName": "DescribeBuckets",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "e027ba8a-e50a-4d99-a6ef-028e8a8e550f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeClassificationJob

#
Service
macie2

Description

Retrieves the status and settings for a classification job.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "82dc55ab-0281-4345-ac39-ad5765b3d513",
  "eventName": "DescribeClassificationJob",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "99c3e7ed-082a-41b3-bad9-b97ba9db8820",
  "requestParameters": {
    "jobId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeOrganizationConfiguration

#
Service
macie2

Description

Retrieves the Amazon Macie configuration settings for an organization in Organizations.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "c0dc2150-1989-41f5-ab21-58b4eeaa4706",
  "eventName": "DescribeOrganizationConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "f0e195d8-a14a-4506-a45a-f9548757c2b2",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DisassociateFromAdministratorAccount

#
Service
macie2

Description

Disassociates a member account from its Amazon Macie administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "ce4ed07f-6618-4d40-b8c7-46f3da0fe05d",
  "eventName": "DisassociateFromAdministratorAccount",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c9c0015e-1a6f-45c0-8186-b0f6269c1864",
  "requestParameters": null,
  "responseElements": {
    "message": "Macie is not enabled"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableMacie

#
Service
macie2

Description

Enables Amazon Macie and specifies the configuration settings for a Macie account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "35932af5-b5d0-4fe7-957e-364f91b5a3bd",
  "eventName": "EnableMacie",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "729d1f07-c3e9-4036-b500-a4105490f2c9",
  "requestParameters": {
    "clientToken": "d1d3b0c0-6cce-4530-80a8-22fd191c213d",
    "findingPublishingFrequency": "SIX_HOURS",
    "status": "ENABLED"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableOrganizationAdminAccount

#
Service
macie2

Description

Designates an account as the delegated Amazon Macie administrator account for an organization in Organizations.

GetAdministratorAccount

#
Service
macie2

Description

Retrieves information about the Amazon Macie administrator account for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "9208d7b2-079c-4255-ae7a-f4c6434c5ce2",
  "eventName": "GetAdministratorAccount",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "93f1e931-90e6-4135-8182-0f10ac679e84",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetAllowList

#
Service
macie2

Description

Retrieves the settings and status of an allow list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "6fae7a9a-d0cd-4a88-85f1-7f686ed06862",
  "eventName": "GetAllowList",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9355e441-ac72-42b5-a766-e0f3bb42837c",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetAutomatedDiscoveryConfiguration

#
Service
macie2

Description

Retrieves the configuration settings and status of automated sensitive data discovery for an organization or standalone account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "f0a51e96-d446-4aff-8420-7b8aa46b8423",
  "eventName": "GetAutomatedDiscoveryConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9c801552-3c98-4595-ab44-f0f40493e062",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBucketStatistics

#
Service
macie2

Description

Retrieves (queries) aggregated statistical data about all the S3 buckets that Amazon Macie monitors and analyzes for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "672b1f9c-3493-4f0a-87a9-6a407d92d601",
  "eventName": "GetBucketStatistics",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d7581538-1a2e-4736-9243-5ecf5161a524",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetClassificationExportConfiguration

#
Service
macie2

Description

Retrieves the configuration settings for storing data classification results.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceNotFoundException",
  "eventCategory": "Management",
  "eventID": "a48660ca-ef31-4d13-ba5d-414f35f2da6d",
  "eventName": "GetClassificationExportConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "264d68ef-3251-42cd-8957-b7184f9cf965",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetClassificationScope

#
Service
macie2

Description

Retrieves the classification scope settings for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "c5691eef-7f3a-438a-a1df-b4d52d8655df",
  "eventName": "GetClassificationScope",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ca3978d1-9b1f-4606-a4e1-63c0697cff8e",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCustomDataIdentifier

#
Service
macie2

Description

Retrieves the criteria and other settings for a custom data identifier.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "f809b7f8-a084-449c-ba2a-a3a04cae26c3",
  "eventName": "GetCustomDataIdentifier",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a29f95f6-6665-420e-a0db-246d1bfb29cf",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetFindings

#
Service
macie2

Description

Retrieves the details of one or more findings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "6c5e19f5-90bb-40da-b34b-2d041ab9d55e",
  "eventName": "GetFindings",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "731db781-9a72-46ca-a5f6-97e9835c7276",
  "requestParameters": {
    "findingIds": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetFindingsFilter

#
Service
macie2

Description

Retrieves the criteria and other settings for a findings filter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "537d8f22-86a7-417f-a5cd-dbdef20caff9",
  "eventName": "GetFindingsFilter",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6535f288-69e2-4090-bf25-11a51912484f",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetFindingsPublicationConfiguration

#
Service
macie2

Description

Retrieves the configuration settings for publishing findings to Security Hub.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "3248f655-5abc-43a1-8534-dd0412eafd42",
  "eventName": "GetFindingsPublicationConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "93791cac-e27a-4e94-b158-e210ff6506a2",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetFindingStatistics

#
Service
macie2

Description

Retrieves (queries) aggregated statistical data about findings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "4745509d-3952-4c70-bda4-72ac34d0e7ec",
  "eventName": "GetFindingStatistics",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f4129f08-46d4-4c72-a5ce-77577a56de03",
  "requestParameters": {
    "groupBy": "resourcesAffected.s3Bucket.name"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInvitationsCount

#
Service
macie2

Description

Retrieves the count of Amazon Macie membership invitations that were received by an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "37dd345f-0343-48fb-9179-df32335ed3b7",
  "eventName": "GetInvitationsCount",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cd01c707-82fb-49ca-952e-3921dac213c6",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMacieSession

#
Service
macie2

Description

Retrieves the status and configuration settings for an Amazon Macie account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "5117c084-5019-487c-8292-d7695b72de25",
  "eventName": "GetMacieSession",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "603d0768-2adc-4bef-b9ac-88f114be96d0",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMasterAccount

#
Service
macie2

Description

(Deprecated) Retrieves information about the Amazon Macie administrator account for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "c5b0cbe8-253d-4f9f-bcb6-4901302be33b",
  "eventName": "GetMasterAccount",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c90032a3-0bc2-4d50-b2e6-70b885ef5acd",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMember

#
Service
macie2

Description

Retrieves information about an account that's associated with an Amazon Macie administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "89e1e7d0-7244-40b1-9966-352ecfdcd97c",
  "eventName": "GetMember",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e050a92a-5e6c-42fe-8049-a9779d414e34",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetResourceProfile

#
Service
macie2

Description

Retrieves (queries) sensitive data discovery statistics and the sensitivity score for an S3 bucket.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "090a3ce7-3b71-44d1-924c-6148a62bb3d4",
  "eventName": "GetResourceProfile",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "20410d16-a88a-4b46-b66b-99d34a1fafd4",
  "requestParameters": {
    "resourceArn": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRevealConfiguration

#
Service
macie2

Description

Retrieves the status and configuration settings for retrieving occurrences of sensitive data reported by findings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "c9f3c8b5-afd9-4646-b3aa-aeb74f7508ba",
  "eventName": "GetRevealConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e7395294-dc97-4109-94e7-0d9a7c6b173f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSensitiveDataOccurrences

#
Service
macie2

Description

Retrieves occurrences of sensitive data reported by a finding.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "6d051e56-545b-4f09-a111-dbe883b50774",
  "eventName": "GetSensitiveDataOccurrences",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f746a1cc-43e9-492b-9dbd-37c531175fed",
  "requestParameters": {
    "findingId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSensitiveDataOccurrencesAvailability

#
Service
macie2

Description

Checks whether occurrences of sensitive data can be retrieved for a finding.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "9b5667f7-e446-49f6-8aa9-0048e48daee2",
  "eventName": "GetSensitiveDataOccurrencesAvailability",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8ef5fb39-a701-4bf4-9376-29b32c23774f",
  "requestParameters": {
    "findingId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSensitivityInspectionTemplate

#
Service
macie2

Description

Retrieves the settings for the sensitivity inspection template for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "870fbe61-a307-46db-be6d-65ae4a7d2eed",
  "eventName": "GetSensitivityInspectionTemplate",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "99dc55de-0a60-4d02-a21c-795954c769d1",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetUsageStatistics

#
Service
macie2

Description

Retrieves (queries) quotas and aggregated usage data for one or more accounts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UnauthorizedException",
  "eventCategory": "Management",
  "eventID": "79353786-ca3c-402b-9399-ce35bdf5460c",
  "eventName": "GetUsageStatistics",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c0c7c729-030a-4348-8cc1-0d6aa4106ad2",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetUsageTotals

#
Service
macie2

Description

Retrieves (queries) aggregated usage data for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UnauthorizedException",
  "eventCategory": "Management",
  "eventID": "8c1ae29a-9ac1-4e66-91e2-d7c2d92d14f9",
  "eventName": "GetUsageTotals",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cec3b2b2-cf61-4ab1-a79d-52a2069b2575",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAllowLists

#
Service
macie2

Description

Retrieves a subset of information about all the allow lists for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "24c57704-1c26-4f4c-8220-7d3e0dd782c8",
  "eventName": "ListAllowLists",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "72725d9c-9bec-471d-9703-b5f0c833afaa",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAutomatedDiscoveryAccounts

#
Service
macie2

Description

Retrieves the status of automated sensitive data discovery for one or more accounts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "36f81915-86b8-4caf-b3fe-2485af139dce",
  "eventName": "ListAutomatedDiscoveryAccounts",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "488e9bcf-359b-40b7-91d5-87f01fcd479e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListClassificationJobs

#
Service
macie2

Description

Retrieves a subset of information about one or more classification jobs.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "ea786ce0-0896-45f7-8243-857353802766",
  "eventName": "ListClassificationJobs",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "a3823c1b-8bee-4d19-9ad0-2d5f280414c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListClassificationScopes

#
Service
macie2

Description

Retrieves a subset of information about the classification scope for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "8eafc7ec-2d11-469e-936e-8f4f9a90bbe3",
  "eventName": "ListClassificationScopes",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "772e3e88-1459-4ce2-b84c-a2e3186d7fb5",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListCustomDataIdentifiers

#
Service
macie2

Description

Retrieves a subset of information about the custom data identifiers for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "6f3ae159-6cfb-4b76-a169-13cbf8e41df2",
  "eventName": "ListCustomDataIdentifiers",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "1d00d7ba-dfee-4ea1-a559-bc6e4c0d25d1",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListFindings

#
Service
macie2

Description

Retrieves a subset of information about one or more findings.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "813901cc8-6013-44f9-a13d-a144376b2236",
  "eventName": "ListFindings",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "011bd27f-382d-4521-8ce3-5a0d303ce462",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListFindingsFilters

#
Service
macie2

Description

Retrieves a subset of information about all the findings filters for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "0647cc3d-acd2-4212-8593-59ec61e445542",
  "eventName": "ListFindingsFilters",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "4cb3c43e-e052-4f93-96f3-0f9a5b271043",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListInvitations

#
Service
macie2

Description

Retrieves information about Amazon Macie membership invitations that were received by an account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "270f705f-a0c6-464a-9894-b0f15d6285f6",
  "eventName": "ListInvitations",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "dc7cfca5-1950-42ca-9722-7a4e73c722943",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListManagedDataIdentifiers

#
Service
macie2

Description

Retrieves information about all the managed data identifiers that Amazon Macie currently provides.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "07cb6ecb-3b00-40a2-98c7-1391cd8fad64",
  "eventName": "ListManagedDataIdentifiers",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0d786c86-97cc-4ece-8d53-d4a03b39357b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListMembers

#
Service
macie2

Description

Retrieves information about the accounts that are associated with an Amazon Macie administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "89c0bc0b-7fb1-425e-bb53-abec0af2cbfe",
  "eventName": "ListMembers",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "ba0f06a8-5b89-49f0-856a-2e6dcc4c42d3",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListOrganizationAdminAccounts

#
Service
macie2

Description

Retrieves information about the delegated Amazon Macie administrator account for an organization in Organizations.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "f26f65bf-662a-458d-ad5b-1383fbb2ab99",
  "eventName": "ListOrganizationAdminAccounts",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2020-06-10T05:30:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "a277b5b2-e83b-4d00-b87e-c3e352fe6045",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListResourceProfileArtifacts

#
Service
macie2

Description

Retrieves information about objects that Amazon Macie selected from an S3 bucket for automated sensitive data discovery.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "c867ce76-b16c-4a30-97a7-0edbf5963d14",
  "eventName": "ListResourceProfileArtifacts",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2c69935c-82d8-4455-943e-ff3f5b678106",
  "requestParameters": {
    "resourceArn": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListResourceProfileDetections

#
Service
macie2

Description

Retrieves information about the types and amount of sensitive data that Amazon Macie found in an S3 bucket.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "407b0daa-8039-4838-82ee-2cc4ac7416e0",
  "eventName": "ListResourceProfileDetections",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "40391b4f-3272-44c1-9b7c-081fd6b04f61",
  "requestParameters": {
    "resourceArn": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListSensitivityInspectionTemplates

#
Service
macie2

Description

Retrieves a subset of information about the sensitivity inspection template for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "214c732a-d77b-4ca8-b156-cbaace61096b",
  "eventName": "ListSensitivityInspectionTemplates",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "83b8e7c1-9ceb-4dcc-81ea-f41fa7435652",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTagsForResource

#
Service
macie2

Description

Retrieves the tags (keys and values) that are associated with an Amazon Macie resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "b436d2ba-8409-44ff-a590-7ed81c61306e",
  "eventName": "ListTagsForResource",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:45:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6da9009d-b4b8-49bb-9db9-478cfc09efc4",
  "requestParameters": {
    "resourceArn": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutClassificationExportConfiguration

#
Service
macie2

Description

Adds or updates the configuration settings for storing data classification results.

PutFindingsPublicationConfiguration

#
Service
macie2

Description

Updates the configuration settings for publishing findings to Security Hub.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2194517a-70a7-4120-b518-f7e45ef711d3",
  "eventName": "PutFindingsPublicationConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "137d6ee8-c7c4-445d-ac68-053619e3165d",
  "requestParameters": {
    "clientToken": "43f99386-f7c3-4fdc-ae38-4cf4570cdc3b",
    "securityHubConfiguration": {
      "publishClassificationFindings": false,
      "publishPolicyFindings": false
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SearchResources

#
Service
macie2

Description

Retrieves (queries) statistical data and other information about Amazon Web Services resources that Amazon Macie monitors and analyzes for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "cae60404-9614-4412-90aa-3b3af8fa9897",
  "eventName": "SearchResources",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T18:32:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ccac722e-d3a6-4701-8a20-9cfed8a33f28",
  "requestParameters": null,
  "responseElements": {
    "message": "Macie is not enabled."
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TagResource

#
Service
macie2

Description

Adds or updates one or more tags (keys and values) that are associated with an Amazon Macie resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "72a21fa0-7f25-459e-a2d3-bcf5cf0c54a3",
  "eventName": "TagResource",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1ac0936b-a58f-49e2-8778-a0e366a406ef",
  "requestParameters": {
    "resourceArn": "arn:aws:macie2:us-west-1:123456789012:findings-filter/712877ee-87ff-427d-bc8c-7d57272d2991",
    "tags": {
      "Environment": "test",
      "SampleCollector": "dwfix"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TestCustomDataIdentifier

#
Service
macie2

Description

Tests criteria for a custom data identifier.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "37105ffe-3246-485d-9b8a-1b82482c32c8",
  "eventName": "TestCustomDataIdentifier",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T21:46:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b3ad9705-4b4c-403a-8a8d-c7c9abe91d4a",
  "requestParameters": {
    "keywords": [
      "SSN"
    ],
    "regex": "***",
    "sampleText": "***"
  },
  "responseElements": {
    "Access-Control-Expose-Headers": "x-amzn-errortype,x-amzn-requestid,x-amzn-errormessage,x-amzn-trace-id,x-amz-apigw-id,date",
    "matchCount": 1
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UntagResource

#
Service
macie2

Description

Removes one or more tags (keys and values) from an Amazon Macie resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "c2ed2114-607d-4f83-a1aa-9df50b7eda39",
  "eventName": "UntagResource",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "97854756-e0d0-4869-94e4-275e6ee2aa93",
  "requestParameters": {
    "resourceArn": "dw-probe",
    "tagKeys": "dw-probe"
  },
  "responseElements": {
    "message": "Invalid input resource arn: bad syntax"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateAllowList

#
Service
macie2

Description

Updates the settings for an allow list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "aa2811f0-7a22-442b-b30d-055d0ad075d5",
  "eventName": "UpdateAllowList",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2fca7af2-c220-4383-ad4c-b9db3393b222",
  "requestParameters": {
    "criteria": {},
    "id": "dw-probe",
    "name": "ddddd"
  },
  "responseElements": {
    "message": "2 validation errors detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-z0-9]{22}; Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 22"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateAutomatedDiscoveryConfiguration

#
Service
macie2

Description

Changes the configuration settings and status of automated sensitive data discovery for an organization or standalone account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "5614fdff-df93-4c13-be5d-bbc3988639d1",
  "eventName": "UpdateAutomatedDiscoveryConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6771f97a-3923-4f38-8538-8872e2db10b0",
  "requestParameters": {
    "status": "ENABLED"
  },
  "responseElements": {
    "message": "Account Id: [123456789012] has not been onboarded"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateClassificationScope

#
Service
macie2

Description

Updates the classification scope settings for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "16baade5-ea56-4457-8e17-46add479a07f",
  "eventName": "UpdateClassificationScope",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "99d7c115-2d89-4784-9fae-0b44540b2dca",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "message": "1 validation error detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-z]*"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateOrganizationConfiguration

#
Service
macie2

Description

Updates the Amazon Macie configuration settings for an organization in Organizations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "7869a614-4f5c-4aec-90ad-c6957eecb456",
  "eventName": "UpdateOrganizationConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4dec75cd-fd50-49c5-a400-ab79c6bec6f0",
  "requestParameters": {
    "autoEnable": false
  },
  "responseElements": {
    "message": "The request failed because you must be the Macie administrator for an organization to perform this operation"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateResourceProfile

#
Service
macie2

Description

Updates the sensitivity score for an S3 bucket.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "b42ecfeb-a474-4c7a-ba42-71cd9fff8214",
  "eventName": "UpdateResourceProfile",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "333f3563-aa4a-4620-af10-3788ff82a695",
  "requestParameters": {
    "resourceArn": "dw-probe"
  },
  "responseElements": {
    "message": "Invalid resource arn [dw-probe]"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateResourceProfileDetections

#
Service
macie2

Description

Updates the sensitivity scoring settings for an S3 bucket.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "eventCategory": "Management",
  "eventID": "9c6f897e-090f-412e-8963-4b88ffdfd031",
  "eventName": "UpdateResourceProfileDetections",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "682ec464-ea43-4d6a-b8a6-896a3e810e89",
  "requestParameters": {
    "resourceArn": "dw-probe"
  },
  "responseElements": {
    "message": "Invalid resource arn [dw-probe]"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRevealConfiguration

#
Service
macie2

Description

Updates the status and configuration settings for retrieving occurrences of sensitive data reported by findings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "21faac29-b11d-451e-9747-ee26b6c3f8ee",
  "eventName": "UpdateRevealConfiguration",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8223853b-df3c-4b59-bf1c-a64f5950e8f9",
  "requestParameters": {
    "configuration": {
      "status": "ENABLED"
    }
  },
  "responseElements": {
    "message": "To retrieve samples, you have to enable Macie for your account in the current AWS Region."
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateSensitivityInspectionTemplate

#
Service
macie2

Description

Updates the settings for the sensitivity inspection template for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "eventCategory": "Management",
  "eventID": "8910b092-1b03-4124-abc1-f1ee57bfa4fc",
  "eventName": "UpdateSensitivityInspectionTemplate",
  "eventSource": "macie2.amazonaws.com",
  "eventTime": "2026-06-29T19:24:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e4246cfc-6871-48aa-8b7a-f0df1c79bb11",
  "requestParameters": {
    "id": "dw-probe"
  },
  "responseElements": {
    "errorCode": "AccessDeniedException",
    "message": "Macie is not enabled."
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}