Route 53
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Route 53 rules that match the service but not a specific eventName. | N | N |
| Associate | Associates an Amazon VPC with a private Route 53 hosted zone so the VPC can resolve records in that zone. | N | Y |
| Activate | Activates a key-signing key (KSK) so that it can be used for signing by DNSSEC. | N | N |
| Change | Creates, changes, or deletes CIDR blocks within a collection. | Y | N |
| Change | Creates, changes, or deletes a resource record set, which contains authoritative DNS information for a specified domain name or subdomain name. | Y | N |
| Change | Adds, edits, or deletes tags for a health check or a hosted zone. | Y | N |
| Create | Creates a CIDR collection in the current Amazon Web Services account. | Y | N |
| Create | Creates a new health check. | Y | N |
| Create | Creates a new public or private hosted zone. | Y | N |
| Create | Creates a new key-signing key (KSK) associated with a hosted zone. | N | N |
| Create | Creates a configuration for DNS query logging. | Y | N |
| Create | Creates a delegation set (a group of four name servers) that can be reused by multiple hosted zones that were created by the same Amazon Web Services account. | Y | N |
| Create | Creates a traffic policy, which you use to create multiple DNS resource record sets for one domain name (such as example.com) or one subdomain name (such as www.example.com). | Y | N |
| Create | Creates resource record sets in a specified hosted zone based on the settings in a specified traffic policy version. | N | N |
| Create | Creates a new version of an existing traffic policy. | Y | N |
| Create | Authorizes the Amazon Web Services account that created a specified VPC to submit an AssociateVPCWithHostedZone request to associate the VPC with a specified hosted zone that was created by a different account. | N | N |
| Deactivate | Deactivates a key-signing key (KSK) so that it will not be used for signing by DNSSEC. | Y | N |
| Delete | Deletes a CIDR collection in the current Amazon Web Services account. | Y | N |
| Delete | Deletes a health check. | Y | N |
| Delete | Deletes a hosted zone. | Y | N |
| Delete | Deletes a key-signing key (KSK). | Y | N |
| Delete | Deletes a configuration for DNS query logging. | Y | N |
| Delete | Deletes a reusable delegation set. | Y | N |
| Delete | Deletes a traffic policy. | Y | N |
| Delete | Deletes a traffic policy instance and all of the resource record sets that Amazon Route 53 created when you created the instance. | N | N |
| Delete | Removes authorization to submit an AssociateVPCWithHostedZone request to associate a specified VPC with a hosted zone that was created by a different account. | N | N |
| Disable | Disables DNSSEC signing in a specific hosted zone. | N | N |
| Disassociate | Disassociates an Amazon Virtual Private Cloud (Amazon VPC) from an Amazon Route 53 private hosted zone. | N | N |
| Enable | Enables DNSSEC signing in a specific hosted zone. | N | N |
| Get | Gets the specified limit for the current account, for example, the maximum number of health checks that you can create using the account. | Y | N |
| Get | Returns the current status of a change batch request. | N | N |
| Get | Route 53 does not perform authorization for this API because it retrieves information that is already available to the public. | Y | N |
| Get | Returns information about DNSSEC for a specific hosted zone, including the key-signing keys (KSKs) in the hosted zone. | N | N |
| Get | Gets information about whether a specified geographic location is supported for Amazon Route 53 geolocation resource record sets. | Y | N |
| Get | Gets information about a specified health check. | N | N |
| Get | Retrieves the number of health checks that are associated with the current Amazon Web Services account. | Y | N |
| Get | Gets the reason that a specified health check failed most recently. | N | N |
| Get | Gets status of a specified health check. | N | N |
| Get | Gets information about a specified hosted zone including the four name servers assigned to the hosted zone. | N | N |
| Get | Retrieves the number of hosted zones that are associated with the current Amazon Web Services account. | Y | N |
| Get | Gets the specified limit for a specified hosted zone, for example, the maximum number of records that you can create in the hosted zone. | N | N |
| Get | Gets information about a specified configuration for DNS query logging. | N | N |
| Get | Retrieves information about a specified reusable delegation set, including the four name servers that are assigned to the delegation set. | N | N |
| Get | Gets the maximum number of hosted zones that you can associate with the specified reusable delegation set. | N | N |
| Get | Gets information about a specific traffic policy version. | N | N |
| Get | Gets information about a specified traffic policy instance. | N | N |
| Get | Gets the number of traffic policy instances that are associated with the current Amazon Web Services account. | Y | N |
| List | Returns a paginated list of location objects and their CIDR blocks. | N | N |
| List | Returns a paginated list of CIDR collections in the Amazon Web Services account (metadata only). | Y | N |
| List | Returns a paginated list of CIDR locations for the given collection (metadata only, does not include CIDR blocks). | N | N |
| List | Retrieves a list of supported geographic locations. | Y | N |
| List | Retrieve a list of the health checks that are associated with the current Amazon Web Services account. | Y | N |
| List | Retrieves a list of the public and private hosted zones that are associated with the current Amazon Web Services account. | Y | N |
| List | Retrieves a list of your hosted zones in lexicographic order. | Y | N |
| List | Lists all the private hosted zones that a specified VPC is associated with, regardless of which Amazon Web Services account or Amazon Web Services service owns the hosted zones. | Y | N |
| List | Lists the configurations for DNS query logging that are associated with the current Amazon Web Services account or the configuration that is associated with a specified hosted zone. | Y | N |
| List | Lists the resource record sets in a specified hosted zone. | Y | N |
| List | Retrieves a list of the reusable delegation sets that are associated with the current Amazon Web Services account. | Y | N |
| List | Lists tags for one health check or hosted zone. | N | N |
| List | Lists tags for up to 10 health checks or hosted zones. | N | N |
| List | Gets information about the latest version for every traffic policy that is associated with the current Amazon Web Services account. | Y | N |
| List | Gets information about the traffic policy instances that you created by using the current Amazon Web Services account. | Y | N |
| List | Gets information about the traffic policy instances that you created in a specified hosted zone. | N | N |
| List | Gets information about the traffic policy instances that you created by using a specify traffic policy version. | N | N |
| List | Gets information about all of the versions for a specified traffic policy. | N | N |
| List | Gets a list of the VPCs that were created by other accounts and that can be associated with a specified hosted zone because you've submitted one or more CreateVPCAssociationAuthorization requests. | N | N |
| Test | Gets the value that Amazon Route 53 returns in response to a DNS request for a specified record name and type. | Y | N |
| Update | Updates an existing health check. | Y | N |
| Update | Updates the comment for a specified hosted zone. | Y | N |
| Update | Updates the features configuration for a hosted zone. | Y | N |
| Update | Updates the comment for a specified traffic policy version. | Y | N |
| Update | After you submit a UpdateTrafficPolicyInstance request, there's a brief delay while Route 53 creates the resource record sets that are specified in the traffic policy definition. | N | N |
any: Route 53 (catch-all)
#Description
Catch-all entry for Route 53 rules that match the service but not a specific eventName.
AssociateVPCWithHostedZone
#Description
Associates an Amazon VPC with a private Route 53 hosted zone so the VPC can resolve records in that zone.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1557, T1583, T1583.001
ActivateKeySigningKey
#Description
Activates a key-signing key (KSK) so that it can be used for signing by DNSSEC.
ChangeCidrCollection
#Description
Creates, changes, or deletes CIDR blocks within a collection.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "0c28aebd-3fa6-4e17-8d19-4fd22a8f7f1a",
"eventName": "ChangeCidrCollection",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "99ec182e-bcaf-4e59-b213-75e1a1ba3fe6",
"requestParameters": {
"changes": [
{
"action": "PUT",
"cidrList": [
"10.100.0.0/24",
"10.100.1.0/24"
],
"locationName": "dwfix-block"
}
],
"collectionVersion": 1,
"id": "94cf8a98-91be-eae4-c71e-aac8047e2e05"
},
"responseElements": {
"id": "BAQICAHgTt0B3S5K5971BzLHtdwBsxj8YhFwDj_tV6O9ZRT8hdwG_HwgdnPc9SNsMXmOcUsFvAAAAxDCBwQYJKoZIhvcNAQcGoIGzMIGwAgEAMIGqBgkqhkiG9w0BBwEwHgYJYIZIAWUDBAEuMBEEDOvQKaLf6BEalLrmIAIBEIB92Nyn7IuzXU7G-evTz9GFC2u-UaFOZgaxfS88WFdcaH0pU6_FMFvQqRnpglRHxIrVhwEWbQNv0DfdBmRID49oTzrmOjDIW3kGCQXWch3GOLJTwJmQikTUPjycLdC-u5nBNLu1G_q2ddmEd77aXFO8-wrCBDwuyy459kCVsiA="
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ChangeResourceRecordSets
#Description
Creates, changes, or deletes a resource record set, which contains authoritative DNS information for a specified domain name or subdomain name.
Example CloudTrail Event #
{
"additionalEventData": {
"Note": "Do not use to reconstruct hosted zone"
},
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "9fecf317-8730-4975-baf2-32a4416fbe7d",
"eventName": "ChangeResourceRecordSets",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T20:04:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2e0c8d23-dfe8-45a8-a742-482c7d39375c",
"requestParameters": {
"changeBatch": {
"changes": [
{
"action": "CREATE",
"resourceRecordSet": {
"name": "a.dwfixsamplezone.com",
"resourceRecords": [
{
"value": "192.0.2.1"
}
],
"tTL": 300,
"type": "A"
}
}
]
},
"hostedZoneId": "Z09455601B09H9MZET78V"
},
"responseElements": {
"changeInfo": {
"id": "/change/C0294202QKM7ZC00P9TO",
"status": "PENDING",
"submittedAt": "Jun 29, 2026 8:04:35 PM"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateCidrCollection
#Description
Creates a CIDR collection in the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1abeb927-c3d9-4316-80dd-1a6537ff4775",
"eventName": "CreateCidrCollection",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "85690e68-1319-403b-9868-23dd9087b5ad",
"requestParameters": {
"callerReference": "dwfix-cidr-ref-510491b5",
"name": "dwfix-cidr-510491b5"
},
"responseElements": {
"collection": {
"arn": "arn:aws:route53:::cidrcollection/94cf8a98-91be-eae4-c71e-aac8047e2e05",
"id": "94cf8a98-91be-eae4-c71e-aac8047e2e05",
"name": "dwfix-cidr-510491b5",
"version": 1
},
"location": "https://route53.amazonaws.com/2013-04-01/cidrcollection/94cf8a98-91be-eae4-c71e-aac8047e2e05"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateHealthCheck
#Description
Creates a new health check.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a95c6614-e046-41e2-b55c-c9df55ca527c",
"eventName": "CreateHealthCheck",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T20:04:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1c879b62-da56-4698-9674-7d381219be1b",
"requestParameters": {
"callerReference": "dwfix-hc2",
"healthCheckConfig": {
"failureThreshold": 3,
"fullyQualifiedDomainName": "example.com",
"port": 80,
"requestInterval": 30,
"type": "HTTP"
}
},
"responseElements": {
"healthCheck": {
"callerReference": "dwfix-hc2",
"healthCheckConfig": {
"disabled": false,
"enableSNI": false,
"failureThreshold": 3,
"fullyQualifiedDomainName": "example.com",
"inverted": false,
"measureLatency": false,
"port": 80,
"requestInterval": 30,
"type": "HTTP"
},
"healthCheckVersion": 1,
"id": "b5b3cca7-a88d-4bd4-9193-b7d596f54ab6"
},
"location": "https://route53.amazonaws.com/2013-04-01/healthcheck/b5b3cca7-a88d-4bd4-9193-b7d596f54ab6"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateHostedZone
#Description
Creates a new public or private hosted zone.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"errorCode": "InvalidDomainName",
"errorMessage": "dwfix.example.com is reserved by AWS!",
"eventCategory": "Management",
"eventID": "530b36f1-5b27-4a9c-8500-265904689d55",
"eventName": "CreateHostedZone",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T20:00:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e3b09411-86d7-44c4-8014-0034eea4d882",
"requestParameters": {
"callerReference": "dwfix-r53",
"name": "dwfix.example.com"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,n,D,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateKeySigningKey
#Description
Creates a new key-signing key (KSK) associated with a hosted zone.
CreateQueryLoggingConfig
#Description
Creates a configuration for DNS query logging.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "68912dd4-cdd1-4c71-897b-e97f3dee9c17",
"eventName": "CreateQueryLoggingConfig",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7b676370-1559-46ba-8569-99526331919d",
"requestParameters": {
"cloudWatchLogsLogGroupArn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/route53/dwfix-510491b5",
"hostedZoneId": "Z03496553IHELE8BOZSET"
},
"responseElements": {
"location": "https://route53.amazonaws.com/2013-04-01/queryloggingconfig/53324ff7-075c-40af-a516-4067cb955bda",
"queryLoggingConfig": {
"cloudWatchLogsLogGroupArn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/route53/dwfix-510491b5",
"hostedZoneId": "Z03496553IHELE8BOZSET",
"id": "53324ff7-075c-40af-a516-4067cb955bda"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateReusableDelegationSet
#Description
Creates a delegation set (a group of four name servers) that can be reused by multiple hosted zones that were created by the same Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "fdeb8810-3ccb-4a51-a071-f766149e84bf",
"eventName": "CreateReusableDelegationSet",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "05c3e397-263f-46b6-bf93-d71ed419db11",
"requestParameters": {
"callerReference": "dwfix-ds-510491b5"
},
"responseElements": {
"delegationSet": {
"callerReference": "dwfix-ds-510491b5",
"id": "/delegationset/N088563221KIBAZRWJLW1",
"nameServers": [
"ns-1051.awsdns-03.org",
"ns-624.awsdns-14.net",
"ns-1578.awsdns-05.co.uk",
"ns-458.awsdns-57.com"
]
},
"location": "https://route53.amazonaws.com/2013-04-01/delegationset/N088563221KIBAZRWJLW1"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTrafficPolicy
#Description
Creates a traffic policy, which you use to create multiple DNS resource record sets for one domain name (such as example.com) or one subdomain name (such as www.example.com).
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "66822d05-cfe0-4ed6-b073-2a9d6ac2e0b7",
"eventName": "CreateTrafficPolicy",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2f10b822-a967-4b22-ac01-166bf785b4a1",
"requestParameters": {
"comment": "dwfix test traffic policy v1",
"document": {
"AWSPolicyFormatVersion": "2015-10-01",
"RecordType": "A",
"Endpoints": {
"ep-dwfix": {
"Type": "value",
"Value": "203.0.113.1"
}
},
"StartEndpoint": "ep-dwfix"
},
"name": "dwfix-tp-510491b5"
},
"responseElements": {
"location": "https://route53.amazonaws.com/2013-04-01/trafficpolicy/435c7699-6a50-4dfd-97d3-348fb5a357e8/1",
"trafficPolicy": {
"comment": "dwfix test traffic policy v1",
"document": {
"AWSPolicyFormatVersion": "2015-10-01",
"RecordType": "A",
"Endpoints": {
"ep-dwfix": {
"Type": "value",
"Value": "203.0.113.1"
}
},
"StartEndpoint": "ep-dwfix"
},
"id": "435c7699-6a50-4dfd-97d3-348fb5a357e8",
"name": "dwfix-tp-510491b5",
"type": "A",
"version": 1
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTrafficPolicyInstance
#Description
Creates resource record sets in a specified hosted zone based on the settings in a specified traffic policy version.
CreateTrafficPolicyVersion
#Description
Creates a new version of an existing traffic policy.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "65676c26-68ed-4ad4-bd0d-afd4cd44c9f6",
"eventName": "CreateTrafficPolicyVersion",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fc9ab6ae-d4b8-4245-9bea-be064ff8da5c",
"requestParameters": {
"comment": "dwfix test traffic policy v2",
"document": {
"AWSPolicyFormatVersion": "2015-10-01",
"RecordType": "A",
"Endpoints": {
"ep-dwfix": {
"Type": "value",
"Value": "203.0.113.1"
}
},
"StartEndpoint": "ep-dwfix"
},
"id": "435c7699-6a50-4dfd-97d3-348fb5a357e8"
},
"responseElements": {
"location": "https://route53.amazonaws.com/2013-04-01/trafficpolicy/435c7699-6a50-4dfd-97d3-348fb5a357e8/2",
"trafficPolicy": {
"comment": "dwfix test traffic policy v2",
"document": {
"AWSPolicyFormatVersion": "2015-10-01",
"RecordType": "A",
"Endpoints": {
"ep-dwfix": {
"Type": "value",
"Value": "203.0.113.1"
}
},
"StartEndpoint": "ep-dwfix"
},
"id": "435c7699-6a50-4dfd-97d3-348fb5a357e8",
"name": "dwfix-tp-510491b5",
"type": "A",
"version": 2
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeactivateKeySigningKey
#Description
Deactivates a key-signing key (KSK) so that it will not be used for signing by DNSSEC.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"errorCode": "KeySigningKeyInUse",
"errorMessage": "Key Signing Key with name 'dwfixksk510491b5' is the only available ACTIVE key for the hosted zone.",
"eventCategory": "Management",
"eventID": "2a2d3c56-11de-4d03-9ea8-256f188eea93",
"eventName": "DeactivateKeySigningKey",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0f09b66e-5314-45ff-836a-7a2f3143400c",
"requestParameters": {
"hostedZoneId": "Z03496553IHELE8BOZSET",
"name": "dwfixksk510491b5"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCidrCollection
#Description
Deletes a CIDR collection in the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "87afd067-2903-4da3-84db-1ce041a2fb6a",
"eventName": "DeleteCidrCollection",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a3f68e84-abfc-4d0b-a937-888dc8a934ac",
"requestParameters": {
"id": "94cf8a98-91be-eae4-c71e-aac8047e2e05"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteHealthCheck
#Description
Deletes a health check.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "294b1515-10db-410b-ae87-9f340fbb9758",
"eventName": "DeleteHealthCheck",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T20:04:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a8d6e5f5-2d84-4645-9d80-18e8e11aadd0",
"requestParameters": {
"healthCheckId": "b5b3cca7-a88d-4bd4-9193-b7d596f54ab6"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteHostedZone
#Description
Deletes a hosted zone.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "e1fb6299-595b-4ec4-8f09-f10563ab7c84",
"eventName": "DeleteHostedZone",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T20:04:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b0c9900d-f500-4e6e-b02c-82f5ec0febd4",
"requestParameters": {
"id": "Z09455601B09H9MZET78V"
},
"responseElements": {
"changeInfo": {
"id": "/change/C031041630KYN82DFWLT4",
"status": "PENDING",
"submittedAt": "Jun 29, 2026 8:04:36 PM"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteKeySigningKey
#Description
Deletes a key-signing key (KSK).
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"errorCode": "InvalidKeySigningKeyStatus",
"errorMessage": "Key Signing Key with name dwfixksk510491b5 cannot be deleted because current status is not INACTIVE. You can use DeactivateKeySigningKey to deactivate the Key Signing Key before you delete it.",
"eventCategory": "Management",
"eventID": "643f2c2d-2c43-49b4-b028-d2f3516306ee",
"eventName": "DeleteKeySigningKey",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "97c1f0d4-68c6-4ae0-9f9e-561d5882346c",
"requestParameters": {
"hostedZoneId": "Z03496553IHELE8BOZSET",
"name": "dwfixksk510491b5"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteQueryLoggingConfig
#Description
Deletes a configuration for DNS query logging.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "80f918ac-cb57-475f-b3d7-d9a9bbbeb050",
"eventName": "DeleteQueryLoggingConfig",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e3003f86-c762-4722-8e9c-dac826506667",
"requestParameters": {
"id": "53324ff7-075c-40af-a516-4067cb955bda"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteReusableDelegationSet
#Description
Deletes a reusable delegation set.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b277536b-2b45-4578-a90b-b0506cd15b0f",
"eventName": "DeleteReusableDelegationSet",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dfd0537f-d87f-44cc-9cd2-d5d3b0c8e60a",
"requestParameters": {
"id": "N088563221KIBAZRWJLW1"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTrafficPolicy
#Description
Deletes a traffic policy.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "14f1c893-8a20-4a3e-b989-018e9c2eb724",
"eventName": "DeleteTrafficPolicy",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "445a62b5-135d-4267-b321-8307947a650c",
"requestParameters": {
"id": "435c7699-6a50-4dfd-97d3-348fb5a357e8",
"version": 2
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTrafficPolicyInstance
#Description
Deletes a traffic policy instance and all of the resource record sets that Amazon Route 53 created when you created the instance.
DisableHostedZoneDNSSEC
#Description
Disables DNSSEC signing in a specific hosted zone.
DisassociateVPCFromHostedZone
#Description
Disassociates an Amazon Virtual Private Cloud (Amazon VPC) from an Amazon Route 53 private hosted zone.
EnableHostedZoneDNSSEC
#Description
Enables DNSSEC signing in a specific hosted zone.
GetAccountLimit
#Description
Gets the specified limit for the current account, for example, the maximum number of health checks that you can create using the account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "75dbc321-c088-42ec-a3d5-31cc92c99126",
"eventName": "GetAccountLimit",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T18:45:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0262bc9b-80ed-431f-97be-074d9a1174f2",
"requestParameters": {
"type": "MAX_HEALTH_CHECKS_BY_OWNER"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetChange
#Description
Returns the current status of a change batch request.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4261635d-d357-47ef-8d7e-bc5a8bd21473",
"eventSource": "route53.amazonaws.com",
"eventName": "GetChange",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "c60cb3d2-546f-454c-8607-e68682d7853d",
"userAgent": "aws-cli/2.34.24 md/awscrt#0.31.2 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.4 md/pyimpl#CPython exec-env/AmazonQ-For-CLI-Version-2.14.2-acp-client-kiro-tui m/Z,b,E,r,s cfg/retry-mode#standard md/installer#source sid/56cf6496accb md/prompt#off md/command#route53.get-change",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetCheckerIpRanges
#Description
Route 53 does not perform authorization for this API because it retrieves information that is already available to the public.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "b8190e35-4337-4b0c-b587-bdcf50c867961",
"eventName": "GetCheckerIpRanges",
"eventSource": "route53.amazonaws.com",
"eventTime": "2019-11-04T00:04:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "de3127b2-5009-4432-9853-12e59edec6b9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "95.22.6.8",
"userAgent": "Boto3/1.10.8 Python/3.7.5rc1 Linux/5.2.0-kali3-amd64 Botocore/1.13.8",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
GetDNSSEC
#Description
Returns information about DNSSEC for a specific hosted zone, including the key-signing keys (KSKs) in the hosted zone.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "7df5712b-cf0b-49b5-85d9-abcb1b629748",
"eventSource": "route53.amazonaws.com",
"eventName": "GetDNSSEC",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "15769961-12fa-4869-b244-13cf00da0f3d",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/route53#1.46.2 m/E",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetGeoLocation
#Description
Gets information about whether a specified geographic location is supported for Amazon Route 53 geolocation resource record sets.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "eba6d0ba-4cbf-4528-8f1e-b4452bfebec9",
"eventName": "GetGeoLocation",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T18:32:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "47be4b6d-d577-44e3-af78-9bfd10da5445",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetHealthCheck
#Description
Gets information about a specified health check.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a4ec87a1-4077-4d0d-80c3-4f2fc5b7e043",
"eventSource": "route53.amazonaws.com",
"eventName": "GetHealthCheck",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "fefa166a-c351-4c02-aa52-983ab25ba92d",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/5.100.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.36.3 ua/2.1 os/linux lang/go#1.23.10 md/GOOS#linux md/GOARCH#amd64 api/route53#1.52.0 m/g",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetHealthCheckCount
#Description
Retrieves the number of health checks that are associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "d8de67cc-7804-49c8-b49e-c9d4c40d3804",
"eventName": "GetHealthCheckCount",
"eventSource": "route53.amazonaws.com",
"eventTime": "2019-07-25T09:40:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "9e3c98e4-1362-4053-a2b8-1d06c95982af",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetHealthCheckLastFailureReason
#Description
Gets the reason that a specified health check failed most recently.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d83f68d3-edfb-47dd-8467-793c855550cb",
"eventSource": "route53.amazonaws.com",
"eventName": "GetHealthCheckLastFailureReason",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "ceb3b33b-cd67-43c7-bdb3-684dc10a4aea",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetHealthCheckStatus
#Description
Gets status of a specified health check.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "89001be8-dd93-46f6-8a5e-1ca80362852e",
"eventSource": "route53.amazonaws.com",
"eventName": "GetHealthCheckStatus",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "412fd5c6-ba61-48e0-b602-a0a76c7def25",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetHostedZone
#Description
Gets information about a specified hosted zone including the four name servers assigned to the hosted zone.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e376133f-4774-4184-b52b-0464f1f05dc4",
"eventSource": "route53.amazonaws.com",
"eventName": "GetHostedZone",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "ca16b576-2242-476b-afaf-01962a74472e",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/route53#1.46.2 m/E",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetHostedZoneCount
#Description
Retrieves the number of hosted zones that are associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "0832ba3b-8a2f-4176-89c1-8272cdaab028",
"eventName": "GetHostedZoneCount",
"eventSource": "route53.amazonaws.com",
"eventTime": "2018-05-17T20:40:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "9925ea0a-5a12-11e8-a11e-77155546fd06",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "252.250.127.237",
"userAgent": "AWSPowerShell/251.194.70.74 .NET_Runtime/4.0 .NET_Framework/4.0 OS/Microsoft_Windows_NT_10.0.17369.0 WindowsPowerShell/5.0 ClientSync",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetHostedZoneLimit
#Description
Gets the specified limit for a specified hosted zone, for example, the maximum number of records that you can create in the hosted zone.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "5bdec17a-787b-411a-b0f7-e94adb51940a",
"eventSource": "route53.amazonaws.com",
"eventName": "GetHostedZoneLimit",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "f899c140-852d-4c4d-9e4b-cd1a9a759d0c",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetQueryLoggingConfig
#Description
Gets information about a specified configuration for DNS query logging.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "9e287c4d-30f0-4bc1-83b6-7bf7d30ccee2",
"eventSource": "route53.amazonaws.com",
"eventName": "GetQueryLoggingConfig",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "9b141736-3fa1-4900-8cf6-74e56fe393eb",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetReusableDelegationSet
#Description
Retrieves information about a specified reusable delegation set, including the four name servers that are assigned to the delegation set.
GetReusableDelegationSetLimit
#Description
Gets the maximum number of hosted zones that you can associate with the specified reusable delegation set.
GetTrafficPolicy
#Description
Gets information about a specific traffic policy version.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f512078c-0174-49de-a281-f4a1924b047a",
"eventSource": "route53.amazonaws.com",
"eventName": "GetTrafficPolicy",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "dea05051-7fc2-45bd-bbf9-9348a9fe03fa",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetTrafficPolicyInstance
#Description
Gets information about a specified traffic policy instance.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f8df37e6-928c-4eae-a687-692a86052f18",
"eventSource": "route53.amazonaws.com",
"eventName": "GetTrafficPolicyInstance",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "3feedfa2-1f41-43fe-9c02-59914cba33b7",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
GetTrafficPolicyInstanceCount
#Description
Gets the number of traffic policy instances that are associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "ad0c32b9-4f9a-4e6a-85d1-988c638a5031",
"eventName": "GetTrafficPolicyInstanceCount",
"eventSource": "route53.amazonaws.com",
"eventTime": "2019-07-25T09:40:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c00ad573-9455-44db-841d-0868a99220a9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListCidrBlocks
#Description
Returns a paginated list of location objects and their CIDR blocks.
ListCidrCollections
#Description
Returns a paginated list of CIDR collections in the Amazon Web Services account (metadata only).
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "26815141-febc-4e2e-b2f3-d530699c531d",
"eventName": "ListCidrCollections",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T18:32:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0a888fbc-6a91-4b6e-b1e0-aa4c167c55a8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListCidrLocations
#Description
Returns a paginated list of CIDR locations for the given collection (metadata only, does not include CIDR blocks).
ListGeoLocations
#Description
Retrieves a list of supported geographic locations.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "0ed74f55-09a2-4585-bd54-c50d42a3e107",
"eventName": "ListGeoLocations",
"eventSource": "route53.amazonaws.com",
"eventTime": "2018-10-17T20:02:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a44a8c8f-d247-11e8-8212-2f9ec16aee0a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListHealthChecks
#Description
Retrieve a list of the health checks that are associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "8d8f742f-f6df-43d9-bac9-050de83da568",
"eventName": "ListHealthChecks",
"eventSource": "route53.amazonaws.com",
"eventTime": "2018-10-17T20:02:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a44b4fbe-d247-11e8-be0b-480cdc2a654d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListHostedZones
#Description
Retrieves a list of the public and private hosted zones that are associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b29fbfda-cd70-40c0-86d8-529d8f653638",
"eventName": "ListHostedZones",
"eventSource": "route53.amazonaws.com",
"eventTime": "2023-07-10T11:43:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "f3b75538-d1d3-463a-b978-f76a331a6727",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSCUXC3DDDP",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"type": "IAMUser",
"userName": "benjamin"
}
}
References #
ListHostedZonesByName
#Description
Retrieves a list of your hosted zones in lexicographic order.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "86041e63-32ea-4d4f-9bd3-481d78cdde23",
"eventName": "ListHostedZonesByName",
"eventSource": "route53.amazonaws.com",
"eventTime": "2017-03-07T20:03:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "108c57c7-0371-11e7-a258-f3d7785dc1f0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "253.5.152.254",
"userAgent": "aws-cli/1.9.20 Python/2.7.6 Linux/3.13.0-83-generic botocore/1.3.20",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListHostedZonesByVPC
#Description
Lists all the private hosted zones that a specified VPC is associated with, regardless of which Amazon Web Services account or Amazon Web Services service owns the hosted zones.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "4aba8c90-d02c-4e29-85be-70729ff51359",
"eventName": "ListHostedZonesByVPC",
"eventSource": "route53.amazonaws.com",
"eventTime": "2021-04-13T13:34:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "760111141337",
"requestID": "554ca479-822c-497f-bd46-bdca3ecefd26",
"requestParameters": {
"vPCId": "vpc-0660ad9c723de2cfc",
"vPCRegion": "us-west-2"
},
"responseElements": null,
"sourceIPAddress": "95.9.125.40",
"userAgent": "Boto3/1.14.6 Python/3.9.4 Darwin/20.3.0 Botocore/1.17.6",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLIXX7QSZR",
"accountId": "760111141337",
"arn": "arn:aws:iam::760111141337:user/cloudmapper",
"principalId": "AIDAYTOGP2RLK32EB7QZV",
"type": "IAMUser",
"userName": "cloudmapper"
}
}
References #
ListQueryLoggingConfigs
#Description
Lists the configurations for DNS query logging that are associated with the current Amazon Web Services account or the configuration that is associated with a specified hosted zone.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "94220cc-5f7d-4bf8-b012-0ff8aea2f415",
"eventName": "ListQueryLoggingConfigs",
"eventSource": "route53.amazonaws.com",
"eventTime": "2018-10-17T20:02:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a47e9509-d247-11e8-be0b-480cdc2a654d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListResourceRecordSets
#Description
Lists the resource record sets in a specified hosted zone.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "518409f7-6b1b-4cc9-b5e0-2e11b3cf4def",
"eventName": "ListResourceRecordSets",
"eventSource": "route53.amazonaws.com",
"eventTime": "2021-04-13T13:18:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "760111141337",
"requestID": "dc4ba108-7743-426a-a604-383afc755fe4",
"requestParameters": {
"hostedZoneId": "Z0400730XY82TJ22VNSJ"
},
"responseElements": null,
"sourceIPAddress": "95.9.125.40",
"userAgent": "Boto3/1.14.6 Python/3.9.4 Darwin/20.3.0 Botocore/1.17.6",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLIXX7QSZR",
"accountId": "760111141337",
"arn": "arn:aws:iam::760111141337:user/cloudmapper",
"principalId": "AIDAYTOGP2RLK32EB7QZV",
"type": "IAMUser",
"userName": "cloudmapper"
}
}
References #
ListReusableDelegationSets
#Description
Retrieves a list of the reusable delegation sets that are associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "27a08c9a-b5a3-4431-86a0-7e3ee96d0b39",
"eventName": "ListReusableDelegationSets",
"eventSource": "route53.amazonaws.com",
"eventTime": "2017-04-07T21:01:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "5df7e2c9-1bd5-11e7-a505-8b820e6a6033",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "121.226.254.251",
"userAgent": "aws-cli/1.11.70 Python/2.7.10 Darwin/16.4.0 botocore/1.5.33",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListTrafficPolicies
#Description
Gets information about the latest version for every traffic policy that is associated with the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "9c807912f-c7b0-498c-a409-7b62ccd94fc5",
"eventName": "ListTrafficPolicies",
"eventSource": "route53.amazonaws.com",
"eventTime": "2020-08-06T15:57:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "576bd730-11f4-4cfb-a0bb-26b5e946d24f",
"requestParameters": {
"maxItems": "1"
},
"responseElements": null,
"sourceIPAddress": "252.1.22.60",
"userAgent": "console.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAZZEZ7STHKNW2G6FE",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2020-08-06T15:57:23Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "Root",
"userName": "flaws"
}
}
References #
ListTrafficPolicyInstances
#Description
Gets information about the traffic policy instances that you created by using the current Amazon Web Services account.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventID": "b09e2528-61ac-48f8-a02f-e13709a4b210",
"eventName": "ListTrafficPolicyInstances",
"eventSource": "route53.amazonaws.com",
"eventTime": "2018-10-17T20:02:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a4910ad5-d247-11e8-8212-2f9ec16aee0a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListTrafficPolicyInstancesByHostedZone
#Description
Gets information about the traffic policy instances that you created in a specified hosted zone.
ListTrafficPolicyInstancesByPolicy
#Description
Gets information about the traffic policy instances that you created by using a specify traffic policy version.
ListTrafficPolicyVersions
#Description
Gets information about all of the versions for a specified traffic policy.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "11b5aa63-579d-46bc-b902-072daaebe763",
"eventSource": "route53.amazonaws.com",
"eventName": "ListTrafficPolicyVersions",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"apiVersion": "2013-04-01",
"readOnly": true,
"managementEvent": true,
"requestID": "eab37d39-114d-4645-8720-0d7dd6b01ae9",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com"
}
}
TestDNSAnswer
#Description
Gets the value that Amazon Route 53 returns in response to a DNS request for a specified record name and type.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "55aab941-b674-422d-a767-74749b698bc3",
"eventName": "TestDNSAnswer",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e52a5662-9dd8-4016-b863-0140579aac2b",
"requestParameters": {
"hostedZoneId": "Z03496553IHELE8BOZSET",
"recordName": "dwfix-sample.dwfix-510491b5.test.",
"recordType": "TXT"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateHealthCheck
#Description
Updates an existing health check.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "775b676f-5d60-48b6-be64-748614931d6f",
"eventName": "UpdateHealthCheck",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T20:04:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f15da870-1384-4769-b696-75b75f1f95ab",
"requestParameters": {
"failureThreshold": 2,
"healthCheckId": "b5b3cca7-a88d-4bd4-9193-b7d596f54ab6"
},
"responseElements": {
"healthCheck": {
"callerReference": "dwfix-hc2",
"healthCheckConfig": {
"disabled": false,
"enableSNI": false,
"failureThreshold": 2,
"fullyQualifiedDomainName": "example.com",
"inverted": false,
"measureLatency": false,
"port": 80,
"requestInterval": 30,
"type": "HTTP"
},
"healthCheckVersion": 2,
"id": "b5b3cca7-a88d-4bd4-9193-b7d596f54ab6"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,n,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateHostedZoneComment
#Description
Updates the comment for a specified hosted zone.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "0cfedf5e-ba13-4f10-84fd-e45498302802",
"eventName": "UpdateHostedZoneComment",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6096f1ff-8bc7-47e4-8fca-6b3a421155b0",
"requestParameters": {
"comment": "dwfix updated comment",
"id": "Z03496553IHELE8BOZSET"
},
"responseElements": {
"hostedZone": {
"callerReference": "dwfix-hz-510491b5",
"config": {
"comment": "dwfix updated comment",
"privateZone": false
},
"id": "/hostedzone/Z03496553IHELE8BOZSET",
"name": "dwfix-510491b5.test.",
"resourceRecordSetCount": 2
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateHostedZoneFeatures
#Description
Updates the features configuration for a hosted zone.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"errorCode": "InvalidInput",
"errorMessage": "Accelerated recovery is already disabled for this hosted zone",
"eventCategory": "Management",
"eventID": "1f8e3f1a-3d2e-47f3-a332-17c7e6783d66",
"eventName": "UpdateHostedZoneFeatures",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5a1c0a31-887f-4f80-b8c6-81e7b4527249",
"requestParameters": {
"enableAcceleratedRecovery": false,
"hostedZoneId": "Z03496553IHELE8BOZSET"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTrafficPolicyComment
#Description
Updates the comment for a specified traffic policy version.
Example CloudTrail Event #
{
"apiVersion": "2013-04-01",
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "c6e07c21-258d-4957-a4be-aefa287e5e39",
"eventName": "UpdateTrafficPolicyComment",
"eventSource": "route53.amazonaws.com",
"eventTime": "2026-06-29T21:02:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d9f8960d-4038-4abe-8d59-279a9d02206b",
"requestParameters": {
"comment": "dwfix updated v1 comment",
"id": "435c7699-6a50-4dfd-97d3-348fb5a357e8",
"version": 1
},
"responseElements": {
"trafficPolicy": {
"comment": "dwfix updated v1 comment",
"document": {
"AWSPolicyFormatVersion": "2015-10-01",
"RecordType": "A",
"Endpoints": {
"ep-dwfix": {
"Type": "value",
"Value": "203.0.113.1"
}
},
"StartEndpoint": "ep-dwfix"
},
"id": "435c7699-6a50-4dfd-97d3-348fb5a357e8",
"name": "dwfix-tp-510491b5",
"type": "A",
"version": 1
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "route53.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTrafficPolicyInstance
#Description
After you submit a UpdateTrafficPolicyInstance request, there's a brief delay while Route 53 creates the resource record sets that are specified in the traffic policy definition.