Macie
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Macie rules that match the service but not a specific eventName. | N | N |
| Create | Creates a findings filter rule in Amazon Macie that automatically archives or suppresses findings matching specified criteria. | Y | Y |
| Delete | Removes an account from the set of member accounts managed by the Amazon Macie administrator account. | Y | N |
| Disable | Disables Amazon Macie for the current account and deletes the Macie service-linked role. | Y | Y |
| Disable | Revokes the designation of an account as the Amazon Macie delegated administrator for an AWS Organizations organization. | Y | N |
| Disassociate | Disassociates the current Macie member account from its administrator account, ending the membership relationship. | Y | N |
| Disassociate | Disassociates a member account from the Amazon Macie administrator account, revoking the administrator's access to findings for that member. | Y | N |
| Update | Updates the status or configuration of an Amazon Macie S3 data classification job. | Y | Y |
| Update | Updates the criteria, action, or name of an existing Amazon Macie findings filter. | Y | Y |
| Update | Updates the configuration or status of the Amazon Macie session for the current account, such as enabling or suspending Macie. | Y | Y |
| Update | Updates the Amazon Macie status for a member account, enabling or suspending Macie for that account from the administrator account. | Y | Y |
| Accept | Accepts an Amazon Macie membership invitation that was received from a specific account. | N | N |
| Batch | Retrieves information about one or more custom data identifiers. | Y | N |
| Batch | Changes the status of automated sensitive data discovery for one or more accounts. | N | N |
| Create | Creates and defines the settings for an allow list. | Y | N |
| Create | Creates and defines the settings for a classification job. | N | N |
| Create | Creates and defines the criteria and other settings for a custom data identifier. | Y | N |
| Create | Sends an Amazon Macie membership invitation to one or more accounts. | N | N |
| Create | Associates an account with an Amazon Macie administrator account. | N | N |
| Create | Creates sample findings. | Y | N |
| Decline | Declines Amazon Macie membership invitations that were received from specific accounts. | N | N |
| Delete | Deletes an allow list. | Y | N |
| Delete | Soft deletes a custom data identifier. | Y | N |
| Delete | Deletes a findings filter. | Y | N |
| Delete | Deletes Amazon Macie membership invitations that were received from specific accounts. | Y | N |
| Describe | Retrieves (queries) statistical data and other information about one or more S3 buckets that Amazon Macie monitors and analyzes for an account. | Y | N |
| Describe | Retrieves the status and settings for a classification job. | Y | N |
| Describe | Retrieves the Amazon Macie configuration settings for an organization in Organizations. | Y | N |
| Disassociate | Disassociates a member account from its Amazon Macie administrator account. | Y | N |
| Enable | Enables Amazon Macie and specifies the configuration settings for a Macie account. | Y | N |
| Enable | Designates an account as the delegated Amazon Macie administrator account for an organization in Organizations. | N | N |
| Get | Retrieves information about the Amazon Macie administrator account for an account. | Y | N |
| Get | Retrieves the settings and status of an allow list. | Y | N |
| Get | Retrieves the configuration settings and status of automated sensitive data discovery for an organization or standalone account. | Y | N |
| Get | Retrieves (queries) aggregated statistical data about all the S3 buckets that Amazon Macie monitors and analyzes for an account. | Y | N |
| Get | Retrieves the configuration settings for storing data classification results. | Y | N |
| Get | Retrieves the classification scope settings for an account. | Y | N |
| Get | Retrieves the criteria and other settings for a custom data identifier. | Y | N |
| Get | Retrieves the details of one or more findings. | Y | N |
| Get | Retrieves the criteria and other settings for a findings filter. | Y | N |
| Get | Retrieves the configuration settings for publishing findings to Security Hub. | Y | N |
| Get | Retrieves (queries) aggregated statistical data about findings. | Y | N |
| Get | Retrieves the count of Amazon Macie membership invitations that were received by an account. | Y | N |
| Get | Retrieves the status and configuration settings for an Amazon Macie account. | Y | N |
| Get | (Deprecated) Retrieves information about the Amazon Macie administrator account for an account. | Y | N |
| Get | Retrieves information about an account that's associated with an Amazon Macie administrator account. | Y | N |
| Get | Retrieves (queries) sensitive data discovery statistics and the sensitivity score for an S3 bucket. | Y | N |
| Get | Retrieves the status and configuration settings for retrieving occurrences of sensitive data reported by findings. | Y | N |
| Get | Retrieves occurrences of sensitive data reported by a finding. | Y | N |
| Get | Checks whether occurrences of sensitive data can be retrieved for a finding. | Y | N |
| Get | Retrieves the settings for the sensitivity inspection template for an account. | Y | N |
| Get | Retrieves (queries) quotas and aggregated usage data for one or more accounts. | Y | N |
| Get | Retrieves (queries) aggregated usage data for an account. | Y | N |
| List | Retrieves a subset of information about all the allow lists for an account. | Y | N |
| List | Retrieves the status of automated sensitive data discovery for one or more accounts. | Y | N |
| List | Retrieves a subset of information about one or more classification jobs. | Y | N |
| List | Retrieves a subset of information about the classification scope for an account. | Y | N |
| List | Retrieves a subset of information about the custom data identifiers for an account. | Y | N |
| List | Retrieves a subset of information about one or more findings. | Y | N |
| List | Retrieves a subset of information about all the findings filters for an account. | Y | N |
| List | Retrieves information about Amazon Macie membership invitations that were received by an account. | Y | N |
| List | Retrieves information about all the managed data identifiers that Amazon Macie currently provides. | Y | N |
| List | Retrieves information about the accounts that are associated with an Amazon Macie administrator account. | Y | N |
| List | Retrieves information about the delegated Amazon Macie administrator account for an organization in Organizations. | Y | N |
| List | Retrieves information about objects that Amazon Macie selected from an S3 bucket for automated sensitive data discovery. | Y | N |
| List | Retrieves information about the types and amount of sensitive data that Amazon Macie found in an S3 bucket. | Y | N |
| List | Retrieves a subset of information about the sensitivity inspection template for an account. | Y | N |
| List | Retrieves the tags (keys and values) that are associated with an Amazon Macie resource. | Y | N |
| Put | Adds or updates the configuration settings for storing data classification results. | N | N |
| Put | Updates the configuration settings for publishing findings to Security Hub. | Y | N |
| Search | Retrieves (queries) statistical data and other information about Amazon Web Services resources that Amazon Macie monitors and analyzes for an account. | Y | N |
| Tag | Adds or updates one or more tags (keys and values) that are associated with an Amazon Macie resource. | Y | N |
| Test | Tests criteria for a custom data identifier. | Y | N |
| Untag | Removes one or more tags (keys and values) from an Amazon Macie resource. | Y | N |
| Update | Updates the settings for an allow list. | Y | N |
| Update | Changes the configuration settings and status of automated sensitive data discovery for an organization or standalone account. | Y | N |
| Update | Updates the classification scope settings for an account. | Y | N |
| Update | Updates the Amazon Macie configuration settings for an organization in Organizations. | Y | N |
| Update | Updates the sensitivity score for an S3 bucket. | Y | N |
| Update | Updates the sensitivity scoring settings for an S3 bucket. | Y | N |
| Update | Updates the status and configuration settings for retrieving occurrences of sensitive data reported by findings. | Y | N |
| Update | Updates the settings for the sensitivity inspection template for an account. | Y | N |
any: Macie (catch-all)
#Description
Catch-all entry for Macie rules that match the service but not a specific eventName.
CreateFindingsFilter
#Description
Creates a findings filter rule in Amazon Macie that automatically archives or suppresses findings matching specified criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "10b7f426-7ff7-4325-af8a-d4f44dbc6f1b",
"eventName": "CreateFindingsFilter",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f02622a9-3de2-460c-909e-bceaab36f154",
"requestParameters": {
"action": "NOOP",
"clientToken": "1cb01d12-c160-4ace-a96b-211916f7875e",
"description": "dwfix test findings filter",
"findingCriteria": {
"criterion": {
"severity.description": {
"eq": [
"High"
]
}
}
},
"name": "dwfix-ff-206c92d2",
"tags": {
"dwfix": "true"
}
},
"responseElements": {
"arn": "arn:aws:macie2:us-west-1:123456789012:findings-filter/712877ee-87ff-427d-bc8c-7d57272d2991",
"id": "712877ee-87ff-427d-bc8c-7d57272d2991"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches DisableMacie, UpdateClassificationJob, UpdateFindingsFilter, UpdateMacieSession, UpdateMemberSession
DeleteMember
#Description
Removes an account from the set of member accounts managed by the Amazon Macie administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "5d82d707-e8d6-42c4-b1d1-454c93bbb4a0",
"eventName": "DeleteMember",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7a33901f-a0a7-4b94-bbc8-b3aa8e76cac6",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"message": "Macie is not enabled"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableMacie
#Description
Disables Amazon Macie for the current account and deletes the Macie service-linked role.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "f2905533-b944-4cb8-ae5a-4e0183855251",
"eventName": "DisableMacie",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:45:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eec92787-d760-4127-9c63-e43851879aa2",
"requestParameters": null,
"responseElements": {
"message": "Macie is not enabled"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateFindingsFilter, UpdateClassificationJob, UpdateFindingsFilter, UpdateMacieSession, UpdateMemberSession
DisableOrganizationAdminAccount
#Description
Revokes the designation of an account as the Amazon Macie delegated administrator for an AWS Organizations organization.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "68aa8ec9-9584-4e19-8070-282077218fc0",
"eventName": "DisableOrganizationAdminAccount",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "61a2c832-0fc8-49f7-9329-9c2b562c4600",
"requestParameters": {
"adminAccountId": "dw-probe"
},
"responseElements": {
"message": "1 validation error detected: Value 'dw-probe' at 'adminAccountId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9]{12}"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateFromMasterAccount
#Description
Disassociates the current Macie member account from its administrator account, ending the membership relationship.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "bada3b1b-a6ab-41fd-be3a-19d411175746",
"eventName": "DisassociateFromMasterAccount",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:45:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f30f9252-b93f-4fe8-8d62-03477615472c",
"requestParameters": null,
"responseElements": {
"message": "Macie is not enabled"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateMember
#Description
Disassociates a member account from the Amazon Macie administrator account, revoking the administrator's access to findings for that member.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "5a19c734-f46e-4ad1-8439-a18845edc212",
"eventName": "DisassociateMember",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0d11bc99-6801-40e1-b818-a91b9b5ebe4c",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"message": "1 validation error detected: Value 'dw-probe' at 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9]{12}"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateClassificationJob
#Description
Updates the status or configuration of an Amazon Macie S3 data classification job.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "aeac6276-cada-4b64-90f7-3cadf7e28029",
"eventName": "UpdateClassificationJob",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "57bc8630-4bd7-4ac7-a1a8-bbe38e38c6fd",
"requestParameters": {
"jobId": "dw-probe",
"jobStatus": "RUNNING"
},
"responseElements": {
"errorCode": "AccessDeniedException",
"message": "Macie is not enabled."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateFindingsFilter, DisableMacie, UpdateFindingsFilter, UpdateMacieSession, UpdateMemberSession
UpdateFindingsFilter
#Description
Updates the criteria, action, or name of an existing Amazon Macie findings filter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "d1f6cd2b-af02-45e8-94bd-a25e391aad4f",
"eventName": "UpdateFindingsFilter",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2ba5b26b-c34f-4965-88dd-39e5a7769258",
"requestParameters": {
"clientToken": "a04c8ccf-f966-4d46-94af-870971f8e58d",
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateFindingsFilter, DisableMacie, UpdateClassificationJob, UpdateMacieSession, UpdateMemberSession
UpdateMacieSession
#Description
Updates the configuration or status of the Amazon Macie session for the current account, such as enabling or suspending Macie.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9da96cc0-4b94-485a-9b92-65429dde8740",
"eventName": "UpdateMacieSession",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e20babd4-81f1-4819-be0e-817ea8b54584",
"requestParameters": {
"findingPublishingFrequency": "ONE_HOUR"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateFindingsFilter, DisableMacie, UpdateClassificationJob, UpdateFindingsFilter, UpdateMemberSession
UpdateMemberSession
#Description
Updates the Amazon Macie status for a member account, enabling or suspending Macie for that account from the administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "1195742c-f990-4a70-8e59-dac88704db5d",
"eventName": "UpdateMemberSession",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c6003d6d-2902-4b2c-8930-06f0264242ef",
"requestParameters": {
"id": "dw-probe",
"status": "PAUSED"
},
"responseElements": {
"message": "1 validation error detected: Value 'dw-probe' at 'accountId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9]{12}"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateFindingsFilter, DisableMacie, UpdateClassificationJob, UpdateFindingsFilter, UpdateMacieSession
AcceptInvitation
#Description
Accepts an Amazon Macie membership invitation that was received from a specific account.
BatchGetCustomDataIdentifiers
#Description
Retrieves information about one or more custom data identifiers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "196494f0-aba8-4a40-a6cb-ec2bcd2f6eb7",
"eventName": "BatchGetCustomDataIdentifiers",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c82d7215-1285-4ff0-8619-dbc7da842e05",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchUpdateAutomatedDiscoveryAccounts
#Description
Changes the status of automated sensitive data discovery for one or more accounts.
CreateAllowList
#Description
Creates and defines the settings for an allow list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "54845f10-2e74-4f6e-9a67-8665f0fe84da",
"eventName": "CreateAllowList",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4493b08d-16d0-4ba0-b858-2f48aac48e5c",
"requestParameters": {
"clientToken": "f82636ff-1a93-4f69-ac4b-0a4cf8f31349",
"criteria": {
"regex": "***"
},
"description": "dwfix test allow list — safe to delete",
"name": "dwfix-al-707bcee2",
"tags": {
"dwfix": "true"
}
},
"responseElements": {
"arn": "arn:aws:macie2:us-west-1:123456789012:allow-list/3xufg2bfclxgufwnqjlg55",
"id": "3xufg2bfclxgufwnqjlg55"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateClassificationJob
#Description
Creates and defines the settings for a classification job.
CreateCustomDataIdentifier
#Description
Creates and defines the criteria and other settings for a custom data identifier.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "adeef724-aa99-4fdb-82d5-480b67995d3b",
"eventName": "CreateCustomDataIdentifier",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5b7b6354-27c8-4f4a-b3f5-0eda01f3aed1",
"requestParameters": {
"clientToken": "3060fc1d-6f8b-44ca-b735-1c3bff97dfec",
"description": "dwfix test custom data identifier — safe to delete",
"keywords": [
"SSN",
"social security"
],
"name": "dwfix-cdi-159ba078",
"regex": "***",
"tags": {
"Purpose": "sample-collection",
"dwfix": "true"
}
},
"responseElements": {
"customDataIdentifierId": "87db561c-4124-42dc-bf53-1e36c5141358"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateInvitations
#Description
Sends an Amazon Macie membership invitation to one or more accounts.
CreateMember
#Description
Associates an account with an Amazon Macie administrator account.
CreateSampleFindings
#Description
Creates sample findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "60b924a3-188c-407b-bd46-bed7ccadb3ed",
"eventName": "CreateSampleFindings",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "62b003bc-ecc7-4552-81d0-b188d6d3a658",
"requestParameters": {
"findingTypes": [
"Policy:IAMUser/S3BucketPublic"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeclineInvitations
#Description
Declines Amazon Macie membership invitations that were received from specific accounts.
DeleteAllowList
#Description
Deletes an allow list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "ff98fd9f-5fa9-4321-b892-990db7ba6d7a",
"eventName": "DeleteAllowList",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "60a3feae-68d1-4947-823d-d464fa3a0e01",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"message": "2 validation errors detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-z0-9]{22}; Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 22"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCustomDataIdentifier
#Description
Soft deletes a custom data identifier.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "9305176c-f1db-4bac-ac4d-2d3ee4f4b762",
"eventName": "DeleteCustomDataIdentifier",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d2ac0b6a-ff9c-49cb-aa51-ced4d6a61098",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"message": "2 validation errors detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 36; Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}$"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteFindingsFilter
#Description
Deletes a findings filter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "eb04b51e-ad8e-4b05-ab7a-6b890e7a0e49",
"eventName": "DeleteFindingsFilter",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "579ea4b4-dbe4-4648-8b0b-d447de91562d",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"message": "1 validation error detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 32"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInvitations
#Description
Deletes Amazon Macie membership invitations that were received from specific accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "03c1de93-9e28-4d4b-83f7-f4604f9b1cc2",
"eventName": "DeleteInvitations",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "280f79f2-f5e9-454f-b88e-25c035014ade",
"requestParameters": {
"accountIds": [
"dw-probe"
]
},
"responseElements": {
"message": "1 validation error detected: Value '[dw-probe]' at 'accountIds' failed to satisfy constraint: Member must satisfy constraint: [Member must satisfy regular expression pattern: [0-9]{12}]"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeBuckets
#Description
Retrieves (queries) statistical data and other information about one or more S3 buckets that Amazon Macie monitors and analyzes for an account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "0323bb93-3705-42b4-97d3-6ab9d39876",
"eventName": "DescribeBuckets",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "e027ba8a-e50a-4d99-a6ef-028e8a8e550f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeClassificationJob
#Description
Retrieves the status and settings for a classification job.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "82dc55ab-0281-4345-ac39-ad5765b3d513",
"eventName": "DescribeClassificationJob",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "99c3e7ed-082a-41b3-bad9-b97ba9db8820",
"requestParameters": {
"jobId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeOrganizationConfiguration
#Description
Retrieves the Amazon Macie configuration settings for an organization in Organizations.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "c0dc2150-1989-41f5-ab21-58b4eeaa4706",
"eventName": "DescribeOrganizationConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "f0e195d8-a14a-4506-a45a-f9548757c2b2",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DisassociateFromAdministratorAccount
#Description
Disassociates a member account from its Amazon Macie administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "ce4ed07f-6618-4d40-b8c7-46f3da0fe05d",
"eventName": "DisassociateFromAdministratorAccount",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:45:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c9c0015e-1a6f-45c0-8186-b0f6269c1864",
"requestParameters": null,
"responseElements": {
"message": "Macie is not enabled"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableMacie
#Description
Enables Amazon Macie and specifies the configuration settings for a Macie account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "35932af5-b5d0-4fe7-957e-364f91b5a3bd",
"eventName": "EnableMacie",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "729d1f07-c3e9-4036-b500-a4105490f2c9",
"requestParameters": {
"clientToken": "d1d3b0c0-6cce-4530-80a8-22fd191c213d",
"findingPublishingFrequency": "SIX_HOURS",
"status": "ENABLED"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableOrganizationAdminAccount
#Description
Designates an account as the delegated Amazon Macie administrator account for an organization in Organizations.
GetAdministratorAccount
#Description
Retrieves information about the Amazon Macie administrator account for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "9208d7b2-079c-4255-ae7a-f4c6434c5ce2",
"eventName": "GetAdministratorAccount",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "93f1e931-90e6-4135-8182-0f10ac679e84",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAllowList
#Description
Retrieves the settings and status of an allow list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "6fae7a9a-d0cd-4a88-85f1-7f686ed06862",
"eventName": "GetAllowList",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9355e441-ac72-42b5-a766-e0f3bb42837c",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAutomatedDiscoveryConfiguration
#Description
Retrieves the configuration settings and status of automated sensitive data discovery for an organization or standalone account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "f0a51e96-d446-4aff-8420-7b8aa46b8423",
"eventName": "GetAutomatedDiscoveryConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9c801552-3c98-4595-ab44-f0f40493e062",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBucketStatistics
#Description
Retrieves (queries) aggregated statistical data about all the S3 buckets that Amazon Macie monitors and analyzes for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "672b1f9c-3493-4f0a-87a9-6a407d92d601",
"eventName": "GetBucketStatistics",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d7581538-1a2e-4736-9243-5ecf5161a524",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetClassificationExportConfiguration
#Description
Retrieves the configuration settings for storing data classification results.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"eventCategory": "Management",
"eventID": "a48660ca-ef31-4d13-ba5d-414f35f2da6d",
"eventName": "GetClassificationExportConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "264d68ef-3251-42cd-8957-b7184f9cf965",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetClassificationScope
#Description
Retrieves the classification scope settings for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "c5691eef-7f3a-438a-a1df-b4d52d8655df",
"eventName": "GetClassificationScope",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ca3978d1-9b1f-4606-a4e1-63c0697cff8e",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCustomDataIdentifier
#Description
Retrieves the criteria and other settings for a custom data identifier.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "f809b7f8-a084-449c-ba2a-a3a04cae26c3",
"eventName": "GetCustomDataIdentifier",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a29f95f6-6665-420e-a0db-246d1bfb29cf",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindings
#Description
Retrieves the details of one or more findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "6c5e19f5-90bb-40da-b34b-2d041ab9d55e",
"eventName": "GetFindings",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "731db781-9a72-46ca-a5f6-97e9835c7276",
"requestParameters": {
"findingIds": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindingsFilter
#Description
Retrieves the criteria and other settings for a findings filter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "537d8f22-86a7-417f-a5cd-dbdef20caff9",
"eventName": "GetFindingsFilter",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6535f288-69e2-4090-bf25-11a51912484f",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindingsPublicationConfiguration
#Description
Retrieves the configuration settings for publishing findings to Security Hub.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "3248f655-5abc-43a1-8534-dd0412eafd42",
"eventName": "GetFindingsPublicationConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "93791cac-e27a-4e94-b158-e210ff6506a2",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindingStatistics
#Description
Retrieves (queries) aggregated statistical data about findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "4745509d-3952-4c70-bda4-72ac34d0e7ec",
"eventName": "GetFindingStatistics",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f4129f08-46d4-4c72-a5ce-77577a56de03",
"requestParameters": {
"groupBy": "resourcesAffected.s3Bucket.name"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInvitationsCount
#Description
Retrieves the count of Amazon Macie membership invitations that were received by an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "37dd345f-0343-48fb-9179-df32335ed3b7",
"eventName": "GetInvitationsCount",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cd01c707-82fb-49ca-952e-3921dac213c6",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMacieSession
#Description
Retrieves the status and configuration settings for an Amazon Macie account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "5117c084-5019-487c-8292-d7695b72de25",
"eventName": "GetMacieSession",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "603d0768-2adc-4bef-b9ac-88f114be96d0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMasterAccount
#Description
(Deprecated) Retrieves information about the Amazon Macie administrator account for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "c5b0cbe8-253d-4f9f-bcb6-4901302be33b",
"eventName": "GetMasterAccount",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c90032a3-0bc2-4d50-b2e6-70b885ef5acd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMember
#Description
Retrieves information about an account that's associated with an Amazon Macie administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "89e1e7d0-7244-40b1-9966-352ecfdcd97c",
"eventName": "GetMember",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e050a92a-5e6c-42fe-8049-a9779d414e34",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetResourceProfile
#Description
Retrieves (queries) sensitive data discovery statistics and the sensitivity score for an S3 bucket.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "090a3ce7-3b71-44d1-924c-6148a62bb3d4",
"eventName": "GetResourceProfile",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "20410d16-a88a-4b46-b66b-99d34a1fafd4",
"requestParameters": {
"resourceArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRevealConfiguration
#Description
Retrieves the status and configuration settings for retrieving occurrences of sensitive data reported by findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "c9f3c8b5-afd9-4646-b3aa-aeb74f7508ba",
"eventName": "GetRevealConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e7395294-dc97-4109-94e7-0d9a7c6b173f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSensitiveDataOccurrences
#Description
Retrieves occurrences of sensitive data reported by a finding.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "6d051e56-545b-4f09-a111-dbe883b50774",
"eventName": "GetSensitiveDataOccurrences",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f746a1cc-43e9-492b-9dbd-37c531175fed",
"requestParameters": {
"findingId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSensitiveDataOccurrencesAvailability
#Description
Checks whether occurrences of sensitive data can be retrieved for a finding.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "9b5667f7-e446-49f6-8aa9-0048e48daee2",
"eventName": "GetSensitiveDataOccurrencesAvailability",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8ef5fb39-a701-4bf4-9376-29b32c23774f",
"requestParameters": {
"findingId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSensitivityInspectionTemplate
#Description
Retrieves the settings for the sensitivity inspection template for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "870fbe61-a307-46db-be6d-65ae4a7d2eed",
"eventName": "GetSensitivityInspectionTemplate",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "99dc55de-0a60-4d02-a21c-795954c769d1",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetUsageStatistics
#Description
Retrieves (queries) quotas and aggregated usage data for one or more accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "UnauthorizedException",
"eventCategory": "Management",
"eventID": "79353786-ca3c-402b-9399-ce35bdf5460c",
"eventName": "GetUsageStatistics",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c0c7c729-030a-4348-8cc1-0d6aa4106ad2",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetUsageTotals
#Description
Retrieves (queries) aggregated usage data for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "UnauthorizedException",
"eventCategory": "Management",
"eventID": "8c1ae29a-9ac1-4e66-91e2-d7c2d92d14f9",
"eventName": "GetUsageTotals",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cec3b2b2-cf61-4ab1-a79d-52a2069b2575",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAllowLists
#Description
Retrieves a subset of information about all the allow lists for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "24c57704-1c26-4f4c-8220-7d3e0dd782c8",
"eventName": "ListAllowLists",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "72725d9c-9bec-471d-9703-b5f0c833afaa",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAutomatedDiscoveryAccounts
#Description
Retrieves the status of automated sensitive data discovery for one or more accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "36f81915-86b8-4caf-b3fe-2485af139dce",
"eventName": "ListAutomatedDiscoveryAccounts",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "488e9bcf-359b-40b7-91d5-87f01fcd479e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListClassificationJobs
#Description
Retrieves a subset of information about one or more classification jobs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "ea786ce0-0896-45f7-8243-857353802766",
"eventName": "ListClassificationJobs",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "a3823c1b-8bee-4d19-9ad0-2d5f280414c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListClassificationScopes
#Description
Retrieves a subset of information about the classification scope for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "8eafc7ec-2d11-469e-936e-8f4f9a90bbe3",
"eventName": "ListClassificationScopes",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "772e3e88-1459-4ce2-b84c-a2e3186d7fb5",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListCustomDataIdentifiers
#Description
Retrieves a subset of information about the custom data identifiers for an account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "6f3ae159-6cfb-4b76-a169-13cbf8e41df2",
"eventName": "ListCustomDataIdentifiers",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "1d00d7ba-dfee-4ea1-a559-bc6e4c0d25d1",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListFindings
#Description
Retrieves a subset of information about one or more findings.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "813901cc8-6013-44f9-a13d-a144376b2236",
"eventName": "ListFindings",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "011bd27f-382d-4521-8ce3-5a0d303ce462",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListFindingsFilters
#Description
Retrieves a subset of information about all the findings filters for an account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "0647cc3d-acd2-4212-8593-59ec61e445542",
"eventName": "ListFindingsFilters",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "4cb3c43e-e052-4f93-96f3-0f9a5b271043",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListInvitations
#Description
Retrieves information about Amazon Macie membership invitations that were received by an account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "270f705f-a0c6-464a-9894-b0f15d6285f6",
"eventName": "ListInvitations",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "dc7cfca5-1950-42ca-9722-7a4e73c722943",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListManagedDataIdentifiers
#Description
Retrieves information about all the managed data identifiers that Amazon Macie currently provides.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "07cb6ecb-3b00-40a2-98c7-1391cd8fad64",
"eventName": "ListManagedDataIdentifiers",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0d786c86-97cc-4ece-8d53-d4a03b39357b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListMembers
#Description
Retrieves information about the accounts that are associated with an Amazon Macie administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "89c0bc0b-7fb1-425e-bb53-abec0af2cbfe",
"eventName": "ListMembers",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "ba0f06a8-5b89-49f0-856a-2e6dcc4c42d3",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListOrganizationAdminAccounts
#Description
Retrieves information about the delegated Amazon Macie administrator account for an organization in Organizations.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "f26f65bf-662a-458d-ad5b-1383fbb2ab99",
"eventName": "ListOrganizationAdminAccounts",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2020-06-10T05:30:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "a277b5b2-e83b-4d00-b87e-c3e352fe6045",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListResourceProfileArtifacts
#Description
Retrieves information about objects that Amazon Macie selected from an S3 bucket for automated sensitive data discovery.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "c867ce76-b16c-4a30-97a7-0edbf5963d14",
"eventName": "ListResourceProfileArtifacts",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2c69935c-82d8-4455-943e-ff3f5b678106",
"requestParameters": {
"resourceArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListResourceProfileDetections
#Description
Retrieves information about the types and amount of sensitive data that Amazon Macie found in an S3 bucket.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "407b0daa-8039-4838-82ee-2cc4ac7416e0",
"eventName": "ListResourceProfileDetections",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:45:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "40391b4f-3272-44c1-9b7c-081fd6b04f61",
"requestParameters": {
"resourceArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListSensitivityInspectionTemplates
#Description
Retrieves a subset of information about the sensitivity inspection template for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "214c732a-d77b-4ca8-b156-cbaace61096b",
"eventName": "ListSensitivityInspectionTemplates",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "83b8e7c1-9ceb-4dcc-81ea-f41fa7435652",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutClassificationExportConfiguration
#Description
Adds or updates the configuration settings for storing data classification results.
PutFindingsPublicationConfiguration
#Description
Updates the configuration settings for publishing findings to Security Hub.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2194517a-70a7-4120-b518-f7e45ef711d3",
"eventName": "PutFindingsPublicationConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "137d6ee8-c7c4-445d-ac68-053619e3165d",
"requestParameters": {
"clientToken": "43f99386-f7c3-4fdc-ae38-4cf4570cdc3b",
"securityHubConfiguration": {
"publishClassificationFindings": false,
"publishPolicyFindings": false
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SearchResources
#Description
Retrieves (queries) statistical data and other information about Amazon Web Services resources that Amazon Macie monitors and analyzes for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "cae60404-9614-4412-90aa-3b3af8fa9897",
"eventName": "SearchResources",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T18:32:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ccac722e-d3a6-4701-8a20-9cfed8a33f28",
"requestParameters": null,
"responseElements": {
"message": "Macie is not enabled."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TagResource
#Description
Adds or updates one or more tags (keys and values) that are associated with an Amazon Macie resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "72a21fa0-7f25-459e-a2d3-bcf5cf0c54a3",
"eventName": "TagResource",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1ac0936b-a58f-49e2-8778-a0e366a406ef",
"requestParameters": {
"resourceArn": "arn:aws:macie2:us-west-1:123456789012:findings-filter/712877ee-87ff-427d-bc8c-7d57272d2991",
"tags": {
"Environment": "test",
"SampleCollector": "dwfix"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TestCustomDataIdentifier
#Description
Tests criteria for a custom data identifier.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "37105ffe-3246-485d-9b8a-1b82482c32c8",
"eventName": "TestCustomDataIdentifier",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T21:46:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b3ad9705-4b4c-403a-8a8d-c7c9abe91d4a",
"requestParameters": {
"keywords": [
"SSN"
],
"regex": "***",
"sampleText": "***"
},
"responseElements": {
"Access-Control-Expose-Headers": "x-amzn-errortype,x-amzn-requestid,x-amzn-errormessage,x-amzn-trace-id,x-amz-apigw-id,date",
"matchCount": 1
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagResource
#Description
Removes one or more tags (keys and values) from an Amazon Macie resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "c2ed2114-607d-4f83-a1aa-9df50b7eda39",
"eventName": "UntagResource",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "97854756-e0d0-4869-94e4-275e6ee2aa93",
"requestParameters": {
"resourceArn": "dw-probe",
"tagKeys": "dw-probe"
},
"responseElements": {
"message": "Invalid input resource arn: bad syntax"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAllowList
#Description
Updates the settings for an allow list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "aa2811f0-7a22-442b-b30d-055d0ad075d5",
"eventName": "UpdateAllowList",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2fca7af2-c220-4383-ad4c-b9db3393b222",
"requestParameters": {
"criteria": {},
"id": "dw-probe",
"name": "ddddd"
},
"responseElements": {
"message": "2 validation errors detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-z0-9]{22}; Value 'dw-probe' at 'id' failed to satisfy constraint: Member must have length greater than or equal to 22"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAutomatedDiscoveryConfiguration
#Description
Changes the configuration settings and status of automated sensitive data discovery for an organization or standalone account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "5614fdff-df93-4c13-be5d-bbc3988639d1",
"eventName": "UpdateAutomatedDiscoveryConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6771f97a-3923-4f38-8538-8872e2db10b0",
"requestParameters": {
"status": "ENABLED"
},
"responseElements": {
"message": "Account Id: [123456789012] has not been onboarded"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateClassificationScope
#Description
Updates the classification scope settings for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "16baade5-ea56-4457-8e17-46add479a07f",
"eventName": "UpdateClassificationScope",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "99d7c115-2d89-4784-9fae-0b44540b2dca",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"message": "1 validation error detected: Value 'dw-probe' at 'id' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-z]*"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateOrganizationConfiguration
#Description
Updates the Amazon Macie configuration settings for an organization in Organizations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "7869a614-4f5c-4aec-90ad-c6957eecb456",
"eventName": "UpdateOrganizationConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4dec75cd-fd50-49c5-a400-ab79c6bec6f0",
"requestParameters": {
"autoEnable": false
},
"responseElements": {
"message": "The request failed because you must be the Macie administrator for an organization to perform this operation"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateResourceProfile
#Description
Updates the sensitivity score for an S3 bucket.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "b42ecfeb-a474-4c7a-ba42-71cd9fff8214",
"eventName": "UpdateResourceProfile",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "333f3563-aa4a-4620-af10-3788ff82a695",
"requestParameters": {
"resourceArn": "dw-probe"
},
"responseElements": {
"message": "Invalid resource arn [dw-probe]"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateResourceProfileDetections
#Description
Updates the sensitivity scoring settings for an S3 bucket.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "9c6f897e-090f-412e-8963-4b88ffdfd031",
"eventName": "UpdateResourceProfileDetections",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "682ec464-ea43-4d6a-b8a6-896a3e810e89",
"requestParameters": {
"resourceArn": "dw-probe"
},
"responseElements": {
"message": "Invalid resource arn [dw-probe]"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateRevealConfiguration
#Description
Updates the status and configuration settings for retrieving occurrences of sensitive data reported by findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "21faac29-b11d-451e-9747-ee26b6c3f8ee",
"eventName": "UpdateRevealConfiguration",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8223853b-df3c-4b59-bf1c-a64f5950e8f9",
"requestParameters": {
"configuration": {
"status": "ENABLED"
}
},
"responseElements": {
"message": "To retrieve samples, you have to enable Macie for your account in the current AWS Region."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateSensitivityInspectionTemplate
#Description
Updates the settings for the sensitivity inspection template for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "8910b092-1b03-4124-abc1-f1ee57bfa4fc",
"eventName": "UpdateSensitivityInspectionTemplate",
"eventSource": "macie2.amazonaws.com",
"eventTime": "2026-06-29T19:24:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e4246cfc-6871-48aa-8b7a-f0df1c79bb11",
"requestParameters": {
"id": "dw-probe"
},
"responseElements": {
"errorCode": "AccessDeniedException",
"message": "Macie is not enabled."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}