AWS Network Firewall

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Network Firewall rules that match the service but not a specific eventName.NN
AcceptNetworkFirewallTransitGatewayAttachmentAccepts a transit gateway attachment request for Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociateAvailabilityZonesAssociates the specified Availability Zones with a transit gateway-attached firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociateFirewallPolicyAssociates a FirewallPolicy to a Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociateSubnetsAssociates the specified subnets in the Amazon VPC to the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AttachRuleGroupsToProxyConfigurationAttaches ProxyRuleGroup resources to a ProxyConfiguration A Proxy Configuration defines the monitoring and protection behavior for a Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateFirewallCreates an Network Firewall Firewall and accompanying FirewallStatus for a VPC. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateFirewallPolicyCreates the firewall policy for the firewall according to the specifications. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateProxyCreates an Network Firewall Proxy Attaches a Proxy configuration to a NAT Gateway. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateProxyConfigurationCreates an Network Firewall ProxyConfiguration A Proxy Configuration defines the monitoring and protection behavior for a Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateProxyRuleGroupCreates an Network Firewall ProxyRuleGroup Collections of related proxy filtering rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateProxyRulesCreates Network Firewall ProxyRule resources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateRuleGroupCreates the specified stateless or stateful rule group, which includes the rules for network traffic inspection, a capacity setting, and tags. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateTLSInspectionConfigurationCreates an Network Firewall TLS inspection configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateVpcEndpointAssociationCreates a firewall endpoint for an Network Firewall firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteFirewallDeletes the specified Firewall and its FirewallStatus. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteFirewallPolicyDeletes the specified FirewallPolicy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteNetworkFirewallTransitGatewayAttachmentDeletes a transit gateway attachment from a Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteProxyDeletes the specified Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteProxyConfigurationDeletes the specified ProxyConfiguration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteProxyRuleGroupDeletes the specified ProxyRuleGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteProxyRulesDeletes the specified ProxyRule(s). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResourcePolicyDeletes a resource policy that you created in a PutResourcePolicy request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteRuleGroupDeletes the specified RuleGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteTLSInspectionConfigurationDeletes the specified TLSInspectionConfiguration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteVpcEndpointAssociationDeletes the specified VpcEndpointAssociation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeFirewallReturns the data objects for the specified firewall.YY
DescribeFirewallMetadataReturns the high-level information about a firewall, including the Availability Zones where the Firewall is currently in use. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeFirewallPolicyReturns the data objects for the specified firewall policy.YY
DescribeFlowOperationReturns key information about a specific flow operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeLoggingConfigurationReturns the logging configuration for the specified firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeProxyReturns the data objects for the specified proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeProxyConfigurationReturns the data objects for the specified proxy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeProxyRuleReturns the data objects for the specified proxy configuration for the specified proxy rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeProxyRuleGroupReturns the data objects for the specified proxy rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeResourcePolicyRetrieves a resource policy that you created in a PutResourcePolicy request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeRuleGroupReturns the data objects for the specified rule group.YY
DescribeRuleGroupMetadataHigh-level information about a rule group, returned by operations like create and describe. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeRuleGroupSummaryReturns detailed information for a stateful rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeTLSInspectionConfigurationReturns the data objects for the specified TLS inspection configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeVpcEndpointAssociationReturns the data object for the specified VPC endpoint association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DetachRuleGroupsFromProxyConfigurationDetaches ProxyRuleGroup resources from a ProxyConfiguration A Proxy Configuration defines the monitoring and protection behavior for a Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisassociateAvailabilityZonesRemoves the specified Availability Zone associations from a transit gateway-attached firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisassociateSubnetsRemoves the specified subnet associations from the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetAnalysisReportResultsThe results of a COMPLETED analysis report generated with StartAnalysisReport. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListAnalysisReportsReturns a list of all traffic analysis reports generated within the last 30 days. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListFirewallPoliciesRetrieves the metadata for the firewall policies that you have defined.YY
ListFirewallsRetrieves the metadata for the firewalls that you have defined.YY
ListFlowOperationResultsReturns the results of a specific flow operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListFlowOperationsReturns a list of all flow operations ran in a specific firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListProxiesRetrieves the metadata for the proxies that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListProxyConfigurationsRetrieves the metadata for the proxy configuration that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListProxyRuleGroupsRetrieves the metadata for the proxy rule groups that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListRuleGroupsRetrieves the metadata for the rule groups that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceRetrieves the tags associated with the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTLSInspectionConfigurationsRetrieves the metadata for the TLS inspection configurations that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListVpcEndpointAssociationsRetrieves the metadata for the VPC endpoint associations that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
PutResourcePolicyCreates or updates an IAM policy for your rule group, firewall policy, or firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RejectNetworkFirewallTransitGatewayAttachmentRejects a transit gateway attachment request for Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartAnalysisReportGenerates a traffic analysis report for the timeframe and traffic type you specify. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartFlowCaptureBegins capturing the flows in a firewall, according to the filters you define. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartFlowFlushBegins the flushing of traffic from the firewall, according to the filters you define. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceAdds the specified tags to the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves the tags with the specified keys from the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateAvailabilityZoneChangeProtectionModifies the AvailabilityZoneChangeProtection setting for a transit gateway-attached firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateFirewallAnalysisSettingsEnables specific types of firewall analysis on a specific firewall you define. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateFirewallDeleteProtectionModifies the flag, DeleteProtection, which indicates whether it is possible to delete the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateFirewallDescriptionModifies the description for the specified firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateFirewallEncryptionConfigurationA complex type that contains settings for encryption of your firewall resources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateFirewallPolicyUpdates the properties of the specified firewall policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateFirewallPolicyChangeProtectionModifies the flag, ChangeProtection, which indicates whether it is possible to change the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLoggingConfigurationSets the logging configuration for the specified firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProxyUpdates the properties of the specified proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProxyConfigurationUpdates the properties of the specified proxy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProxyRuleUpdates the properties of the specified proxy rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProxyRuleGroupPrioritiesUpdates proxy rule group priorities within a proxy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProxyRulePrioritiesUpdates proxy rule priorities within a proxy rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateRuleGroupUpdates the rule settings for the specified rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateSubnetChangeProtectionUpdateSubnetChangeProtection API operation for AWS Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTLSInspectionConfigurationUpdates the TLS inspection configuration settings for the specified TLS inspection configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateContainerAssociationCreates a Network Firewall container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteContainerAssociationDeletes a container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeContainerAssociationRetrieves the configuration and status of a container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListContainerAssociationsLists the container associations in your account and Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateContainerAssociationUpdates the monitoring configurations and description of a container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProxySettingsModifies the proxy listener configuration of a proxy mode firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: AWS Network Firewall (catch-all)

#
Service
network-firewall

Description

Catch-all entry for AWS Network Firewall rules that match the service but not a specific eventName.

AcceptNetworkFirewallTransitGatewayAttachment

#
Service
network-firewall

Description

Accepts a transit gateway attachment request for Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociateAvailabilityZones

#
Service
network-firewall

Description

Associates the specified Availability Zones with a transit gateway-attached firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociateFirewallPolicy

#
Service
network-firewall

Description

Associates a FirewallPolicy to a Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociateSubnets

#
Service
network-firewall

Description

Associates the specified subnets in the Amazon VPC to the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AttachRuleGroupsToProxyConfiguration

#
Service
network-firewall

Description

Attaches ProxyRuleGroup resources to a ProxyConfiguration A Proxy Configuration defines the monitoring and protection behavior for a Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateFirewall

#
Service
network-firewall

Description

Creates an Network Firewall Firewall and accompanying FirewallStatus for a VPC. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateFirewallPolicy

#
Service
network-firewall

Description

Creates the firewall policy for the firewall according to the specifications. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateProxy

#
Service
network-firewall

Description

Creates an Network Firewall Proxy Attaches a Proxy configuration to a NAT Gateway. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateProxyConfiguration

#
Service
network-firewall

Description

Creates an Network Firewall ProxyConfiguration A Proxy Configuration defines the monitoring and protection behavior for a Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateProxyRuleGroup

#
Service
network-firewall

Description

Creates an Network Firewall ProxyRuleGroup Collections of related proxy filtering rules. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateProxyRules

#
Service
network-firewall

Description

Creates Network Firewall ProxyRule resources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateRuleGroup

#
Service
network-firewall

Description

Creates the specified stateless or stateful rule group, which includes the rules for network traffic inspection, a capacity setting, and tags. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateTLSInspectionConfiguration

#
Service
network-firewall

Description

Creates an Network Firewall TLS inspection configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateVpcEndpointAssociation

#
Service
network-firewall

Description

Creates a firewall endpoint for an Network Firewall firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteFirewall

#
Service
network-firewall

Description

Deletes the specified Firewall and its FirewallStatus. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteFirewallPolicy

#
Service
network-firewall

Description

Deletes the specified FirewallPolicy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteNetworkFirewallTransitGatewayAttachment

#
Service
network-firewall

Description

Deletes a transit gateway attachment from a Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteProxy

#
Service
network-firewall

Description

Deletes the specified Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteProxyConfiguration

#
Service
network-firewall

Description

Deletes the specified ProxyConfiguration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteProxyRuleGroup

#
Service
network-firewall

Description

Deletes the specified ProxyRuleGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteProxyRules

#
Service
network-firewall

Description

Deletes the specified ProxyRule(s). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResourcePolicy

#
Service
network-firewall

Description

Deletes a resource policy that you created in a PutResourcePolicy request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteRuleGroup

#
Service
network-firewall

Description

Deletes the specified RuleGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteTLSInspectionConfiguration

#
Service
network-firewall

Description

Deletes the specified TLSInspectionConfiguration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteVpcEndpointAssociation

#
Service
network-firewall

Description

Deletes the specified VpcEndpointAssociation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeFirewall

#
Service
network-firewall

Description

Returns the data objects for the specified firewall.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T19:59:44Z",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "DescribeFirewall",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#network-firewall.describe-firewall",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "No object with the provided name or resource identifier was found",
  "requestParameters": {
    "firewallName": "dw-harn-network-firewall-bf42d1"
  },
  "responseElements": null,
  "requestID": "56778f54-da72-4ece-ba51-1f3db7e963d1",
  "eventID": "1046d83d-a5eb-4483-ad8e-fd9311d24ec2",
  "readOnly": true,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::NetworkFirewall::Firewall",
      "ARN": "arn:aws:network-firewall:us-west-1:123456789012:firewall/dw-harn-network-firewall-bf42d1"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "network-firewall.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DescribeFirewallMetadata

#
Service
network-firewall

Description

Returns the high-level information about a firewall, including the Availability Zones where the Firewall is currently in use. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeFirewallPolicy

#
Service
network-firewall

Description

Returns the data objects for the specified firewall policy.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T19:59:45Z",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "DescribeFirewallPolicy",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#network-firewall.describe-firewall-policy",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "No object with the provided name or resource identifier was found",
  "requestParameters": {
    "firewallPolicyName": "dw-harn-network-firewall-bf42d1"
  },
  "responseElements": null,
  "requestID": "b450de98-3f97-4fd6-b1bc-c02ec0892302",
  "eventID": "3f4ef390-da75-456d-b132-3e195d72c2f9",
  "readOnly": true,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::NetworkFirewall::FirewallPolicy",
      "ARN": "arn:aws:network-firewall:us-west-1:123456789012:firewall-policy/dw-harn-network-firewall-bf42d1"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "network-firewall.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DescribeFlowOperation

#
Service
network-firewall

Description

Returns key information about a specific flow operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeLoggingConfiguration

#
Service
network-firewall

Description

Returns the logging configuration for the specified firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeProxy

#
Service
network-firewall

Description

Returns the data objects for the specified proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeProxyConfiguration

#
Service
network-firewall

Description

Returns the data objects for the specified proxy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeProxyRule

#
Service
network-firewall

Description

Returns the data objects for the specified proxy configuration for the specified proxy rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeProxyRuleGroup

#
Service
network-firewall

Description

Returns the data objects for the specified proxy rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeResourcePolicy

#
Service
network-firewall

Description

Retrieves a resource policy that you created in a PutResourcePolicy request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeRuleGroup

#
Service
network-firewall

Description

Returns the data objects for the specified rule group.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T19:59:46Z",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "DescribeRuleGroup",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#network-firewall.describe-rule-group",
  "errorCode": "ResourceNotFoundException",
  "errorMessage": "No object with the provided name or resource identifier was found",
  "requestParameters": {
    "ruleGroupName": "dw-harn-network-firewall-bf42d1",
    "type": "STATELESS",
    "analyzeRuleGroup": false
  },
  "responseElements": null,
  "requestID": "9927d278-e6fe-40b1-8408-18be33c9bdac",
  "eventID": "c27f5357-e3b0-4d20-aca9-111f1f5aa349",
  "readOnly": true,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::NetworkFirewall::RuleGroup",
      "ARN": "arn:aws:network-firewall:us-west-1:123456789012:stateless-rulegroup/dw-harn-network-firewall-bf42d1"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "network-firewall.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DescribeRuleGroupMetadata

#
Service
network-firewall

Description

High-level information about a rule group, returned by operations like create and describe. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeRuleGroupSummary

#
Service
network-firewall

Description

Returns detailed information for a stateful rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeTLSInspectionConfiguration

#
Service
network-firewall

Description

Returns the data objects for the specified TLS inspection configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeVpcEndpointAssociation

#
Service
network-firewall

Description

Returns the data object for the specified VPC endpoint association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DetachRuleGroupsFromProxyConfiguration

#
Service
network-firewall

Description

Detaches ProxyRuleGroup resources from a ProxyConfiguration A Proxy Configuration defines the monitoring and protection behavior for a Proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisassociateAvailabilityZones

#
Service
network-firewall

Description

Removes the specified Availability Zone associations from a transit gateway-attached firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisassociateSubnets

#
Service
network-firewall

Description

Removes the specified subnet associations from the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetAnalysisReportResults

#
Service
network-firewall

Description

The results of a COMPLETED analysis report generated with StartAnalysisReport. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListAnalysisReports

#
Service
network-firewall

Description

Returns a list of all traffic analysis reports generated within the last 30 days. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListFirewallPolicies

#
Service
network-firewall

Description

Retrieves the metadata for the firewall policies that you have defined.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "IAMUser",
    "principalId": "AIDAEXAMPLE00000000",
    "arn": "arn:aws:iam::123456789012:user/dw-sample-collector",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "userName": "dw-sample-collector"
  },
  "eventTime": "2026-07-02T16:24:54Z",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListFirewallPolicies",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#network-firewall.list-firewall-policies",
  "requestParameters": null,
  "responseElements": null,
  "requestID": "4090e286-0261-462f-8901-e5031d73b555",
  "eventID": "a935a66d-dc4d-4aac-adcc-cb3adc9ac2cc",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "network-firewall.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ListFirewalls

#
Service
network-firewall

Description

Retrieves the metadata for the firewalls that you have defined.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "IAMUser",
    "principalId": "AIDAEXAMPLE00000000",
    "arn": "arn:aws:iam::123456789012:user/dw-sample-collector",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "userName": "dw-sample-collector"
  },
  "eventTime": "2026-07-02T16:24:53Z",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListFirewalls",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#network-firewall.list-firewalls",
  "requestParameters": null,
  "responseElements": null,
  "requestID": "3f29e7c3-da65-4ca0-9f0f-7e11741c337c",
  "eventID": "982272a6-b373-4848-bae4-de755499464f",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "network-firewall.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ListFlowOperationResults

#
Service
network-firewall

Description

Returns the results of a specific flow operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListFlowOperations

#
Service
network-firewall

Description

Returns a list of all flow operations ran in a specific firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListProxies

#
Service
network-firewall

Description

Retrieves the metadata for the proxies that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "68618d50-7b76-498f-a0f8-5aa8dcee7c85",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListProxies",
  "awsRegion": "eu-north-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1d222a8d-bd53-42e0-bfe3-c7fe5983b655",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/networkfirewall#1.59.3 m/C,E",
  "errorCode": "InvalidRequestException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-north-1.amazonaws.com"
  }
}

ListProxyConfigurations

#
Service
network-firewall

Description

Retrieves the metadata for the proxy configuration that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5269f5fa-3ff0-431c-be1e-cd1f423e8c70",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListProxyConfigurations",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "97470b4b-cbb5-4630-b9cc-c8b4d9dc726b",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/networkfirewall#1.59.3 m/C,E",
  "errorCode": "InvalidRequestException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ca-central-1.amazonaws.com"
  }
}

ListProxyRuleGroups

#
Service
network-firewall

Description

Retrieves the metadata for the proxy rule groups that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c096ff89-7b51-49d1-a3ee-8f5e451c0410",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListProxyRuleGroups",
  "awsRegion": "eu-north-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4b4f5dfb-76dc-4a27-941b-0574eef402f7",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/networkfirewall#1.59.3 m/C,E",
  "errorCode": "InvalidRequestException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-north-1.amazonaws.com"
  }
}

ListRuleGroups

#
Service
network-firewall

Description

Retrieves the metadata for the rule groups that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9d32b84e-fa80-4ae8-9fb3-9886cc62b2e0",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListRuleGroups",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "0aa5ca40-3838-4fc1-9358-cfb55d32a13d",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListTagsForResource

#
Service
network-firewall

Description

Retrieves the tags associated with the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTLSInspectionConfigurations

#
Service
network-firewall

Description

Retrieves the metadata for the TLS inspection configurations that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c210d645-8790-427a-ab06-f7be6721b869",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListTLSInspectionConfigurations",
  "awsRegion": "sa-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f89bbd88-6413-4e6f-b124-b8c16aeb36da",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/networkfirewall#1.59.3 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.sa-east-1.amazonaws.com"
  }
}

ListVpcEndpointAssociations

#
Service
network-firewall

Description

Retrieves the metadata for the VPC endpoint associations that you have defined. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a3ad141b-4c62-4c2d-80cb-fc9dd6cb25f7",
  "eventSource": "network-firewall.amazonaws.com",
  "eventName": "ListVpcEndpointAssociations",
  "awsRegion": "eu-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "85a9bdf4-77fb-43af-9003-7e4e7ebfc029",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/networkfirewall#1.59.3 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-central-1.amazonaws.com"
  }
}

PutResourcePolicy

#
Service
network-firewall

Description

Creates or updates an IAM policy for your rule group, firewall policy, or firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RejectNetworkFirewallTransitGatewayAttachment

#
Service
network-firewall

Description

Rejects a transit gateway attachment request for Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartAnalysisReport

#
Service
network-firewall

Description

Generates a traffic analysis report for the timeframe and traffic type you specify. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartFlowCapture

#
Service
network-firewall

Description

Begins capturing the flows in a firewall, according to the filters you define. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartFlowFlush

#
Service
network-firewall

Description

Begins the flushing of traffic from the firewall, according to the filters you define. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
network-firewall

Description

Adds the specified tags to the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
network-firewall

Description

Removes the tags with the specified keys from the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateAvailabilityZoneChangeProtection

#
Service
network-firewall

Description

Modifies the AvailabilityZoneChangeProtection setting for a transit gateway-attached firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateFirewallAnalysisSettings

#
Service
network-firewall

Description

Enables specific types of firewall analysis on a specific firewall you define. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateFirewallDeleteProtection

#
Service
network-firewall

Description

Modifies the flag, DeleteProtection, which indicates whether it is possible to delete the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateFirewallDescription

#
Service
network-firewall

Description

Modifies the description for the specified firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateFirewallEncryptionConfiguration

#
Service
network-firewall

Description

A complex type that contains settings for encryption of your firewall resources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateFirewallPolicy

#
Service
network-firewall

Description

Updates the properties of the specified firewall policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateFirewallPolicyChangeProtection

#
Service
network-firewall

Description

Modifies the flag, ChangeProtection, which indicates whether it is possible to change the firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLoggingConfiguration

#
Service
network-firewall

Description

Sets the logging configuration for the specified firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProxy

#
Service
network-firewall

Description

Updates the properties of the specified proxy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProxyConfiguration

#
Service
network-firewall

Description

Updates the properties of the specified proxy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProxyRule

#
Service
network-firewall

Description

Updates the properties of the specified proxy rule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProxyRuleGroupPriorities

#
Service
network-firewall

Description

Updates proxy rule group priorities within a proxy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProxyRulePriorities

#
Service
network-firewall

Description

Updates proxy rule priorities within a proxy rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateRuleGroup

#
Service
network-firewall

Description

Updates the rule settings for the specified rule group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateSubnetChangeProtection

#
Service
network-firewall

Description

UpdateSubnetChangeProtection API operation for AWS Network Firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTLSInspectionConfiguration

#
Service
network-firewall

Description

Updates the TLS inspection configuration settings for the specified TLS inspection configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateContainerAssociation

#
Service
network-firewall

Description

Creates a Network Firewall container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteContainerAssociation

#
Service
network-firewall

Description

Deletes a container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeContainerAssociation

#
Service
network-firewall

Description

Retrieves the configuration and status of a container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListContainerAssociations

#
Service
network-firewall

Description

Lists the container associations in your account and Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateContainerAssociation

#
Service
network-firewall

Description

Updates the monitoring configurations and description of a container association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProxySettings

#
Service
network-firewall

Description

Modifies the proxy listener configuration of a proxy mode firewall. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.