AWS Resource Explorer

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Resource Explorer rules that match the service but not a specific eventName.NN
AssociateDefaultViewSets the specified view as the default for the Amazon Web Services Region in which you call this operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
BatchGetViewRetrieves details about a list of views. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateIndexTurns on Amazon Web Services Resource Explorer in the Amazon Web Services Region in which you called this operation by creating an index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateResourceExplorerSetupCreates a Resource Explorer setup configuration across multiple Amazon Web Services Regions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateViewCreates a view that users can query by using the Search operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteIndexDeletes the specified index and turns off Amazon Web Services Resource Explorer in the specified Amazon Web Services Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResourceExplorerSetupDeletes a Resource Explorer setup configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteViewDeletes the specified view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisassociateDefaultViewAfter you call this operation, the affected Amazon Web Services Region no longer has a default view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetAccountLevelServiceConfigurationRetrieves the status of your account's Amazon Web Services service access, and validates the service linked role required to access the multi-account search feature. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetDefaultViewRetrieves the Amazon Resource Name (ARN) of the view that is the default for the Amazon Web Services Region in which you call this operation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetIndexRetrieves details about the Amazon Web Services Resource Explorer index in the Amazon Web Services Region in which you invoked the operation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetManagedViewRetrieves details of the specified Amazon Web Services-managed view. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetResourceExplorerSetupRetrieves the status and details of a Resource Explorer setup operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetServiceIndexRetrieves information about the Resource Explorer index in the current Amazon Web Services Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetServiceViewRetrieves details about a specific Resource Explorer service view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetViewRetrieves details of the specified view. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListIndexesRetrieves a list of all of the indexes in Amazon Web Services Regions that are currently collecting resource information for Amazon Web Services Resource Explorer. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListIndexesForMembersRetrieves a list of a member's indexes in all Amazon Web Services Regions that are currently collecting resource information for Amazon Web Services Resource Explorer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListManagedViewsLists the Amazon resource names (ARNs) of the Amazon Web Services-managed views available in the Amazon Web Services Region in which you call this operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListResourcesReturns a list of resources and their details that match the specified criteria. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListServiceIndexesLists all Resource Explorer indexes across the specified Amazon Web Services Regions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListServiceViewsLists all Resource Explorer service views available in the current Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListStreamingAccessForServicesReturns a list of Amazon Web Services services that have been granted streaming access to your Resource Explorer data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListSupportedResourceTypesRetrieves a list of all resource types currently supported by Amazon Web Services Resource Explorer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsForResourceLists the tags that are attached to the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListViewsLists the Amazon resource names (ARNs) of the views available in the Amazon Web Services Region in which you call this operation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SearchSearches for resources and displays details about all resources that match the specified criteria.YN
TagResourceAdds one or more tag key and value pairs to an Amazon Web Services Resource Explorer view or index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves one or more tag key and value pairs from an Amazon Web Services Resource Explorer view or index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateIndexTypeChanges the type of the index from one of the following types to the other. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateViewModifies some of the details of a view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateManagedViewCreateManagedView recorded by CloudTrail for AWS Resource Explorer. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN

any: AWS Resource Explorer (catch-all)

#
Service
resource-explorer-2

Description

Catch-all entry for AWS Resource Explorer rules that match the service but not a specific eventName.

AssociateDefaultView

#
Service
resource-explorer-2

Description

Sets the specified view as the default for the Amazon Web Services Region in which you call this operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

BatchGetView

#
Service
resource-explorer-2

Description

Retrieves details about a list of views. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateIndex

#
Service
resource-explorer-2

Description

Turns on Amazon Web Services Resource Explorer in the Amazon Web Services Region in which you called this operation by creating an index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateResourceExplorerSetup

#
Service
resource-explorer-2

Description

Creates a Resource Explorer setup configuration across multiple Amazon Web Services Regions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateView

#
Service
resource-explorer-2

Description

Creates a view that users can query by using the Search operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteIndex

#
Service
resource-explorer-2

Description

Deletes the specified index and turns off Amazon Web Services Resource Explorer in the specified Amazon Web Services Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResourceExplorerSetup

#
Service
resource-explorer-2

Description

Deletes a Resource Explorer setup configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteView

#
Service
resource-explorer-2

Description

Deletes the specified view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisassociateDefaultView

#
Service
resource-explorer-2

Description

After you call this operation, the affected Amazon Web Services Region no longer has a default view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetAccountLevelServiceConfiguration

#
Service
resource-explorer-2

Description

Retrieves the status of your account's Amazon Web Services service access, and validates the service linked role required to access the multi-account search feature. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7d0785c6-c6aa-4037-a48d-e9e1b7c3f182",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "GetAccountLevelServiceConfiguration",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ed0c9aa4-ae68-47bc-8084-c9c62e3eac5a",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "AccessDenied"
}

GetDefaultView

#
Service
resource-explorer-2

Description

Retrieves the Amazon Resource Name (ARN) of the view that is the default for the Amazon Web Services Region in which you call this operation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0c8ef603-01b9-46a6-a3b4-8ea3b59ea922",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "GetDefaultView",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "141e5eac-f833-4ff7-a1a5-f474ac2b395d",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard"
}

GetIndex

#
Service
resource-explorer-2

Description

Retrieves details about the Amazon Web Services Resource Explorer index in the Amazon Web Services Region in which you invoked the operation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5a027d9e-c4b6-4d57-8de0-651b8580fad0",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "GetIndex",
  "awsRegion": "ap-northeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "89c0a8bf-6946-4f5a-8082-14ade6d50fab",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

GetManagedView

#
Service
resource-explorer-2

Description

Retrieves details of the specified Amazon Web Services-managed view. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fadab509-91bf-496b-8d59-0f6c71eeee2c",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "GetManagedView",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "66f9a414-f88f-472d-84a4-6ac0b7c3416c",
  "userAgent": "ssm.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::ResourceExplorer2::ManagedView",
      "ARN": "arn:aws:resource-explorer-2:us-east-1:123456789012:managed-view/EXAMPLE"
    }
  ]
}

GetResourceExplorerSetup

#
Service
resource-explorer-2

Description

Retrieves the status and details of a Resource Explorer setup operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetServiceIndex

#
Service
resource-explorer-2

Description

Retrieves information about the Resource Explorer index in the current Amazon Web Services Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetServiceView

#
Service
resource-explorer-2

Description

Retrieves details about a specific Resource Explorer service view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetView

#
Service
resource-explorer-2

Description

Retrieves details of the specified view. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.09",
  "eventID": "83a94674-8ac8-4c99-a5ec-07c6652091e7",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "GetView",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3c6ad7e7-6bc8-4f73-9ea8-7fcc477df732",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::ResourceExplorer2::View",
      "ARN": "arn:aws:resource-explorer-2:us-east-2:123456789012:view/EXAMPLE"
    }
  ]
}

ListIndexes

#
Service
resource-explorer-2

Description

Retrieves a list of all of the indexes in Amazon Web Services Regions that are currently collecting resource information for Amazon Web Services Resource Explorer. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "47d7a419-0323-4dcd-83d3-c31a0edd2cc9",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "ListIndexes",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c9a1e79d-cd86-4523-b8ed-b3cdd90a5611",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
}

ListIndexesForMembers

#
Service
resource-explorer-2

Description

Retrieves a list of a member's indexes in all Amazon Web Services Regions that are currently collecting resource information for Amazon Web Services Resource Explorer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListManagedViews

#
Service
resource-explorer-2

Description

Lists the Amazon resource names (ARNs) of the Amazon Web Services-managed views available in the Amazon Web Services Region in which you call this operation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListResources

#
Service
resource-explorer-2

Description

Returns a list of resources and their details that match the specified criteria. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "569ba36f-999e-45f1-9662-7bf3e47ea027",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "ListResources",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a761b24a-0de0-4e74-9316-6943bedc1940",
  "userAgent": "application-signals.cloudwatch.amazonaws.com"
}

ListServiceIndexes

#
Service
resource-explorer-2

Description

Lists all Resource Explorer indexes across the specified Amazon Web Services Regions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListServiceViews

#
Service
resource-explorer-2

Description

Lists all Resource Explorer service views available in the current Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListStreamingAccessForServices

#
Service
resource-explorer-2

Description

Returns a list of Amazon Web Services services that have been granted streaming access to your Resource Explorer data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListSupportedResourceTypes

#
Service
resource-explorer-2

Description

Retrieves a list of all resource types currently supported by Amazon Web Services Resource Explorer. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTagsForResource

#
Service
resource-explorer-2

Description

Lists the tags that are attached to the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListViews

#
Service
resource-explorer-2

Description

Lists the Amazon resource names (ARNs) of the views available in the Amazon Web Services Region in which you call this operation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4e90f70c-3a38-4aba-948b-b21ecf0df137",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "ListViews",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "72ad639e-6ef2-4ff2-8b35-0e735f2f91b9",
  "userAgent": "config.amazonaws.com"
}

Search

#
Service
resource-explorer-2

Description

Searches for resources and displays details about all resources that match the specified criteria.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "UnauthorizedException",
  "eventCategory": "Management",
  "eventID": "27ea7a75-9e68-4082-89d5-4254bff7e0f6",
  "eventName": "Search",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventTime": "2024-08-18T12:56:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.09",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "36cb88b6-1d62-4857-80b3-eb08abc69db9",
  "requestParameters": {
    "QueryString": "***"
  },
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_94756beb-5ee9-4e5c-8e55-fff2c46f2e4c cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#resource-explorer-2.search",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

References #

TagResource

#
Service
resource-explorer-2

Description

Adds one or more tag key and value pairs to an Amazon Web Services Resource Explorer view or index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
resource-explorer-2

Description

Removes one or more tag key and value pairs from an Amazon Web Services Resource Explorer view or index. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateIndexType

#
Service
resource-explorer-2

Description

Changes the type of the index from one of the following types to the other. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateView

#
Service
resource-explorer-2

Description

Modifies some of the details of a view. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateManagedView

#
Service
resource-explorer-2

Description

CreateManagedView recorded by CloudTrail for AWS Resource Explorer. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a9d53a31-c8fb-4d60-b235-3e4fa6d14a3f",
  "eventSource": "resource-explorer-2.amazonaws.com",
  "eventName": "CreateManagedView",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "8b7478dc-d092-4e66-bcdb-3a7e29151dda",
  "userAgent": "ssm.amazonaws.com",
  "errorCode": "UnauthorizedException"
}