CloudWatch Observability Access Manager

eventNameDescriptionSampleRule
anyCatch-all entry for CloudWatch Observability Access Manager rules that match the service but not a specific eventName.NN
CreateLinkCreates a link between a source account and a sink that you have created in a monitoring account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateSinkUse this to create a sink in the current account, so that it can be used as a monitoring account in CloudWatch cross-account observability. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteLinkDeletes a link between a monitoring account sink and a source account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSinkDeletes a sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetLinkReturns complete information about one link. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetSinkReturns complete information about one monitoring account sink. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetSinkPolicyReturns the current sink policy attached to this sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListAttachedLinksReturns a list of source account links that are linked to this monitoring account sink. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListLinksUse this operation in a source account to return a list of links to monitoring account sinks that this source account has. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListSinksUse this operation in a monitoring account to return the list of sinks created in that account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceDisplays the tags associated with a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutSinkPolicyCreates or updates the resource policy that grants permissions to source accounts to link to the monitoring account sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceAssigns one or more tags (key-value pairs) to the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves one or more tags from the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateLinkUse this operation to change what types of data are shared from a source account to its linked monitoring account sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: CloudWatch Observability Access Manager (catch-all)

#
Service
oam

Description

Catch-all entry for CloudWatch Observability Access Manager rules that match the service but not a specific eventName.

CreateLink

#
Service
oam

CreateSink

#
Service
oam

Description

Use this to create a sink in the current account, so that it can be used as a monitoring account in CloudWatch cross-account observability. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteLink

#
Service
oam

DeleteSink

#
Service
oam

Description

Deletes a sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetLink

#
Service
oam

GetSink

#
Service
oam

Description

Returns complete information about one monitoring account sink. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b5e0004c-1373-4da4-a0c0-10c37c5b187d",
  "eventSource": "oam.amazonaws.com",
  "eventName": "GetSink",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b9df757b-cba9-4f07-80a9-6296481af88d",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/oam#1.23.14 m/E",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::Oam::Sink",
      "ARN": "arn:aws:oam:ca-central-1:123456789012:sink/EXAMPLE"
    }
  ]
}

GetSinkPolicy

#
Service
oam

Description

Returns the current sink policy attached to this sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListAttachedLinks

#
Service
oam

ListLinks

#
Service
oam

ListSinks

#
Service
oam

Description

Use this operation in a monitoring account to return the list of sinks created in that account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "33cb15ff-914c-4a11-a232-c06ecfc1d4b3",
  "eventSource": "oam.amazonaws.com",
  "eventName": "ListSinks",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "97f6d918-2ba6-467a-bf5c-7960b29f2d5b",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/oam#1.23.14 m/C,E"
}

ListTagsForResource

#
Service
oam

Description

Displays the tags associated with a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutSinkPolicy

#
Service
oam

Description

Creates or updates the resource policy that grants permissions to source accounts to link to the monitoring account sink. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
oam

Description

Assigns one or more tags (key-value pairs) to the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
oam

Description

Removes one or more tags from the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateLink

#
Service
oam