OpenSearch Ingestion

eventNameDescriptionSampleRule
anyCatch-all entry for OpenSearch Ingestion rules that match the service but not a specific eventName.NN
CreatePipelineCreates an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreatePipelineEndpointCreates a VPC endpoint for an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeletePipelineDeletes an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeletePipelineEndpointDeletes a VPC endpoint for an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResourcePolicyDeletes a resource-based policy from an OpenSearch Ingestion resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetPipelineRetrieves information about an OpenSearch Ingestion pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetPipelineBlueprintRetrieves information about a specific blueprint for OpenSearch Ingestion. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetPipelineChangeProgressReturns progress information for the current change happening on an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetResourcePolicyRetrieves the resource-based policy attached to an OpenSearch Ingestion resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListPipelineBlueprintsRetrieves a list of all available blueprints for Data Prepper. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelineEndpointConnectionsLists the pipeline endpoints connected to pipelines in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListPipelineEndpointsLists all pipeline endpoints in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelinesLists all OpenSearch Ingestion pipelines in the current Amazon Web Services account and Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsForResourceLists all resource tags associated with an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutResourcePolicyAttaches a resource-based policy to an OpenSearch Ingestion resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RevokePipelineEndpointConnectionsRevokes pipeline endpoints from specified endpoint IDs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartPipelineStarts an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StopPipelineStops an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceTags an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves one or more tags from an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdatePipelineUpdates an OpenSearch Ingestion pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ValidatePipelineChecks whether an OpenSearch Ingestion pipeline configuration is valid prior to creation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN

any: OpenSearch Ingestion (catch-all)

#
Service
osis

Description

Catch-all entry for OpenSearch Ingestion rules that match the service but not a specific eventName.

CreatePipeline

#
Service
osis

Description

Creates an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreatePipelineEndpoint

#
Service
osis

Description

Creates a VPC endpoint for an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeletePipeline

#
Service
osis

Description

Deletes an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeletePipelineEndpoint

#
Service
osis

Description

Deletes a VPC endpoint for an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResourcePolicy

#
Service
osis

Description

Deletes a resource-based policy from an OpenSearch Ingestion resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetPipeline

#
Service
osis

Description

Retrieves information about an OpenSearch Ingestion pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6f61d4b7-dd67-4ca0-a964-20bd9d3e328d",
  "eventSource": "osis.amazonaws.com",
  "eventName": "GetPipeline",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3fdc97a4-cc4e-4d00-9de0-920474052223",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0"
}

GetPipelineBlueprint

#
Service
osis

Description

Retrieves information about a specific blueprint for OpenSearch Ingestion. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetPipelineChangeProgress

#
Service
osis

Description

Returns progress information for the current change happening on an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetResourcePolicy

#
Service
osis

Description

Retrieves the resource-based policy attached to an OpenSearch Ingestion resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListPipelineBlueprints

#
Service
osis

Description

Retrieves a list of all available blueprints for Data Prepper. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d43c5da7-a194-4dc8-830d-c0bcf36292d2",
  "eventSource": "osis.amazonaws.com",
  "eventName": "ListPipelineBlueprints",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c813ef8d-46e3-47d8-a08b-e034beddf86b",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
}

ListPipelineEndpointConnections

#
Service
osis

Description

Lists the pipeline endpoints connected to pipelines in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListPipelineEndpoints

#
Service
osis

Description

Lists all pipeline endpoints in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ed127c98-4878-4286-843a-bab0e5ba8501",
  "eventSource": "osis.amazonaws.com",
  "eventName": "ListPipelineEndpoints",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "fc71bf03-ec30-4ddc-aecc-6da23f727aea",
  "userAgent": "AWS Internal",
  "errorCode": "AccessDenied"
}

ListPipelines

#
Service
osis

Description

Lists all OpenSearch Ingestion pipelines in the current Amazon Web Services account and Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTagsForResource

#
Service
osis

Description

Lists all resource tags associated with an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutResourcePolicy

#
Service
osis

Description

Attaches a resource-based policy to an OpenSearch Ingestion resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RevokePipelineEndpointConnections

#
Service
osis

Description

Revokes pipeline endpoints from specified endpoint IDs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartPipeline

#
Service
osis

Description

Starts an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StopPipeline

#
Service
osis

Description

Stops an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
osis

Description

Tags an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
osis

Description

Removes one or more tags from an OpenSearch Ingestion pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdatePipeline

#
Service
osis

Description

Updates an OpenSearch Ingestion pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d63f7f8c-e3b3-48ca-be32-0e929723d996",
  "eventSource": "osis.amazonaws.com",
  "eventName": "UpdatePipeline",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "bcf5d9c4-25c0-4384-99c8-f362ad294e49",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/osis#1.22.7 m/g",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::OSIS::Pipeline",
      "ARN": "arn:aws:osis:eu-west-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

ValidatePipeline

#
Service
osis

Description

Checks whether an OpenSearch Ingestion pipeline configuration is valid prior to creation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6d20f7b4-e8b5-43ea-8ee9-45faf99c6196",
  "eventSource": "osis.amazonaws.com",
  "eventName": "ValidatePipeline",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "81d787ad-4c8a-47f0-9589-894138d2e8f4",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
}