SageMaker Service

eventNameDescriptionSampleRule
anyCatch-all entry for SageMaker Service rules that match the service but not a specific eventName.NN
AddAssociationCreates an association between the source and the destination. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
AddTagsAdds or overwrites one or more tags for the specified SageMaker resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
AssociateTrialComponentAssociates a trial component with a trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
AttachClusterNodeVolumeAttaches your Amazon Elastic Block Store (Amazon EBS) volume to a node in your EKS orchestrated HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchAddClusterNodesAdds nodes to a HyperPod cluster by incrementing the target count for one or more instance groups. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchDeleteClusterNodesDeletes specific nodes within a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchDescribeModelPackageThis action batch describes a list of versioned model packages Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchRebootClusterNodesReboots specific nodes within a SageMaker HyperPod cluster using a soft recovery mechanism. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchReplaceClusterNodesReplaces specific nodes within a SageMaker HyperPod cluster with new hardware. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateActionCreates an action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateAIBenchmarkJobCreates a benchmark job that runs performance benchmarks against inference infrastructure using a predefined AI workload configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateAIRecommendationJobCreates a recommendation job that generates intelligent optimization recommendations for generative AI inference deployments. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateAIWorkloadConfigCreates a reusable AI workload configuration that defines datasets, data sources, and benchmark tool settings for consistent performance testing of generative AI inference deployments on Amazon SageMaker AI. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateAlgorithmCreate a machine learning algorithm that you can use in SageMaker and list in the Amazon Web Services Marketplace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateAppCreates a running app for the specified UserProfile. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateAppImageConfigCreates a configuration for running a SageMaker AI image as a KernelGateway app. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateArtifactCreates an artifact. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateAutoMLJobCreates an Autopilot job also referred to as Autopilot experiment or AutoML job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NY
CreateAutoMLJobV2Creates an Autopilot job also referred to as Autopilot experiment or AutoML job V2. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateClusterCreates an Amazon SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateClusterSchedulerConfigCreate cluster policy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateCodeRepositoryCreates a Git repository as a resource in your SageMaker AI account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateCompilationJobStarts a model compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateComputeQuotaCreate compute allocation definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateContextCreates a context. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateDataQualityJobDefinitionCreates a definition for a job that monitors data quality and drift. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateDeviceFleetCreates a device fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateDomainCreates a Domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateEdgeDeploymentPlanCreates an edge deployment plan, consisting of multiple stages. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateEdgeDeploymentStageCreates a new stage in an existing edge deployment plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateEdgePackagingJobStarts a SageMaker Edge Manager model packaging job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateEndpointCreates an endpoint using the endpoint configuration specified in the request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateEndpointConfigCreates an endpoint configuration that SageMaker hosting services uses to deploy models. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateExperimentCreates a SageMaker experiment. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateFeatureGroupCreate a new FeatureGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateFlowDefinitionCreates a flow definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateHubCreate a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateHubContentPresignedUrlsCreates presigned URLs for accessing hub content artifacts. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateHubContentReferenceCreate a hub content reference in order to add a model in the JumpStart public hub to a private hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateHumanTaskUiDefines the settings you will use for the human review workflow user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateHyperParameterTuningJobStarts a hyperparameter tuning job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateImageCreates a custom SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateImageVersionCreates a version of the SageMaker AI image specified by ImageName. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateInferenceComponentCreates an inference component, which is a SageMaker AI hosting object that you can use to deploy a model to an endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateInferenceExperimentCreates an inference experiment using the configurations specified in the request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateInferenceRecommendationsJobStarts a recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateJobCreates a model customization job in Amazon SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateLabelingJobCreates a job that uses workers to label the data objects in your input dataset. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateMlflowAppCreates an MLflow Tracking Server using a general purpose Amazon S3 bucket as the artifact store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateMlflowTrackingServerCreates an MLflow Tracking Server using a general purpose Amazon S3 bucket as the artifact store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelCreates a model in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelBiasJobDefinitionCreates the definition for a model bias job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelCardCreates an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelCardExportJobCreates an Amazon SageMaker Model Card export job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelExplainabilityJobDefinitionCreates the definition for a model explainability job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelPackageCreates a model package that you can use to create SageMaker models or list on Amazon Web Services Marketplace, or a versioned model that is part of a model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelPackageGroupCreates a model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateModelQualityJobDefinitionCreates a definition for a job that monitors model quality and drift. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateMonitoringScheduleCreates a schedule that regularly starts Amazon SageMaker AI Processing Jobs to monitor the data captured for an Amazon SageMaker AI Endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateNotebookInstanceCreates an SageMaker AI notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NY
CreateNotebookInstanceLifecycleConfigCreates a lifecycle configuration that you can associate with a notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NY
CreateOptimizationJobCreates a job that optimizes a model for inference performance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreatePartnerAppCreates an Amazon SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreatePartnerAppPresignedUrlCreates a presigned URL to access an Amazon SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreatePipelineCreates a pipeline using a JSON pipeline definition. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NY
CreatePresignedDomainUrlCreates a URL for a specified UserProfile in a Domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreatePresignedMlflowAppUrlReturns a presigned URL that you can use to connect to the MLflow UI attached to your MLflow App. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreatePresignedMlflowTrackingServerUrlReturns a presigned URL that you can use to connect to the MLflow UI attached to your tracking server. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreatePresignedNotebookInstanceUrlReturns a URL that you can use to connect to the Jupyter server from a notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateProcessingJobCreates a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NY
CreateProjectCreates a machine learning (ML) project that can contain one or more templates that set up an ML pipeline from training to deploying an approved model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateSpaceCreates a private space or a space used for real time collaboration in a domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateStudioLifecycleConfigCreates a new Amazon SageMaker AI Studio Lifecycle Configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateTrainingJobStarts a model training job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NY
CreateTrainingPlanCreates a new training plan in SageMaker to reserve compute capacity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateTransformJobStarts a transform job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateTrialCreates an SageMaker trial. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateTrialComponentCreates a trial component, which is a stage of a machine learning trial. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
CreateUserProfileCreates a user profile. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateWorkforceUse this operation to create a workforce. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateWorkteamCreates a new work team for labeling your data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteActionDeletes an action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteAIBenchmarkJobDeletes the specified AI benchmark job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteAIRecommendationJobDeletes the specified AI recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteAIWorkloadConfigDeletes the specified AI workload configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteAlgorithmRemoves the specified algorithm from your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteAppUsed to stop and delete an app. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DeleteAppImageConfigDeletes an AppImageConfig. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteArtifactDeletes an artifact. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteAssociationDeletes an association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteClusterDelete a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteClusterSchedulerConfigDeletes the cluster policy of the cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteCodeRepositoryDeletes the specified Git repository from your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteCompilationJobDeletes the specified compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteComputeQuotaDeletes the compute allocation from the cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteContextDeletes an context. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteDataQualityJobDefinitionDeletes a data quality monitoring job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteDeviceFleetDeletes a fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteDomainUsed to delete a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteEdgeDeploymentPlanDeletes an edge deployment plan if (and only if) all the stages in the plan are inactive or there are no stages in the plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteEdgeDeploymentStageDelete a stage in an edge deployment plan if (and only if) the stage is inactive. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteEndpointDeletes an endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteEndpointConfigDeletes an endpoint configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteExperimentDeletes an SageMaker experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteFeatureGroupDelete the FeatureGroup and any data that was written to the OnlineStore of the FeatureGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteFlowDefinitionDeletes the specified flow definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteHubDelete a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteHubContentDelete the contents of a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteHubContentReferenceDelete a hub content reference in order to remove a model from a private hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteHumanTaskUiUse this operation to delete a human task user interface (worker task template). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteHyperParameterTuningJobDeletes a hyperparameter tuning job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteImageDeletes a SageMaker AI image and all versions of the image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteImageVersionDeletes a version of a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteInferenceComponentDeletes an inference component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteInferenceExperimentDeletes an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteJobDeletes a job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteMlflowAppDeletes an MLflow App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteMlflowTrackingServerDeletes an MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelDeletes a model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelBiasJobDefinitionDeletes an Amazon SageMaker AI model bias job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelCardDeletes an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelExplainabilityJobDefinitionDeletes an Amazon SageMaker AI model explainability job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelPackageDeletes a model package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelPackageGroupDeletes the specified model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelPackageGroupPolicyDeletes a model group resource policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteModelQualityJobDefinitionDeletes the secified model quality monitoring job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteMonitoringScheduleDeletes a monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteNotebookInstanceDeletes an SageMaker AI notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteNotebookInstanceLifecycleConfigDeletes a notebook instance lifecycle configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteOptimizationJobDeletes an optimization job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeletePartnerAppDeletes a SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeletePipelineDeletes a pipeline if there are no running instances of the pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DeleteProcessingJobDeletes a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteProjectDelete the specified project. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteSpaceUsed to delete a space. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DeleteStudioLifecycleConfigDeletes the Amazon SageMaker AI Studio Lifecycle Configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteTagsDeletes the specified tags from an SageMaker resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteTrainingJobDeletes a training job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteTrialDeletes the specified trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteTrialComponentDeletes the specified trial component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteUserProfileDeletes a user profile. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteWorkforceUse this operation to delete a workforce. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteWorkteamDeletes an existing work team. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeregisterDevicesDeregisters the specified devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeActionDescribes an action. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeAIBenchmarkJobReturns details of an AI benchmark job, including its status, configuration, target endpoint, and timing information. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeAIRecommendationJobReturns details of an AI recommendation job, including its status, model source, performance targets, optimization recommendations, and deployment configurations. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeAIWorkloadConfigReturns details of an AI workload configuration, including the dataset configuration, benchmark tool settings, tags, and creation time. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeAlgorithmReturns a description of the specified algorithm that is in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeAppDescribes the app. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeAppImageConfigDescribes an AppImageConfig. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeArtifactDescribes an artifact. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeAutoMLJobReturns information about an AutoML job created by calling CreateAutoMLJob. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeAutoMLJobV2Returns information about an AutoML job created by calling CreateAutoMLJobV2 or CreateAutoMLJob. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeClusterRetrieves information of a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeClusterEventRetrieves detailed information about a specific event for a given HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeClusterNodeRetrieves information of a node (also called a instance interchangeably) of a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeClusterSchedulerConfigDescription of the cluster policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeCodeRepositoryGets details about the specified Git repository. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeCompilationJobReturns information about a model compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeComputeQuotaDescription of the compute allocation definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeContextDescribes a context. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeDataQualityJobDefinitionGets the details of a data quality monitoring job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeDeviceDescribes the device. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeDeviceFleetA description of the fleet the device belongs to. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeDomainThe description of the domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeEdgeDeploymentPlanDescribes an edge deployment plan with deployment status per stage. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeEdgePackagingJobA description of edge packaging jobs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeEndpointReturns the description of an endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeEndpointConfigReturns the description of an endpoint configuration created using the CreateEndpointConfig API. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeExperimentProvides a list of an experiment's properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeFeatureGroupUse this operation to describe a FeatureGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeFeatureMetadataShows the metadata for a feature within a feature group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeFlowDefinitionReturns information about the specified flow definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeHubDescribes a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeHubContentDescribe the content of a hub. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeHumanTaskUiReturns information about the requested human task user interface (worker task template). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeHyperParameterTuningJobReturns a description of a hyperparameter tuning job, depending on the fields selected. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeImageDescribes a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeImageVersionDescribes a version of a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeInferenceComponentReturns information about an inference component. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeInferenceExperimentReturns details about an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeInferenceRecommendationsJobProvides the results of the Inference Recommender job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeJobReturns detailed information about a job, including its current status, secondary status, configuration, and timestamps. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeJobSchemaVersionReturns the JSON schema for a specified job category and schema version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeLabelingJobGets information about a labeling job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeLineageGroupProvides a list of properties for the requested lineage group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeMlflowAppReturns information about an MLflow App. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeMlflowTrackingServerReturns information about an MLflow Tracking Server. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeModelDescribes a model that you created using the CreateModel API. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeModelBiasJobDefinitionReturns a description of a model bias job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeModelCardDescribes the content, creation time, and security configuration of an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeModelCardExportJobDescribes an Amazon SageMaker Model Card export job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeModelExplainabilityJobDefinitionReturns a description of a model explainability job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeModelPackageReturns a description of the specified model package, which is used to create SageMaker models or list them on Amazon Web Services Marketplace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeModelPackageGroupGets a description for the specified model group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeModelQualityJobDefinitionReturns a description of a model quality job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeMonitoringScheduleDescribes the schedule for a monitoring job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeNotebookInstanceReturns information about a notebook instance. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeNotebookInstanceLifecycleConfigReturns a description of a notebook instance lifecycle configuration. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeOptimizationJobProvides the properties of the specified optimization job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribePartnerAppGets information about a SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribePipelineDescribes the details of a pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribePipelineDefinitionForExecutionDescribes the details of an execution's pipeline definition. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribePipelineExecutionDescribes the details of a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeProcessingJobReturns a description of a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeProjectDescribes the details of a project. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeReservedCapacityRetrieves details about a reserved capacity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeSpaceDescribes the space. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeStudioLifecycleConfigDescribes the Amazon SageMaker AI Studio Lifecycle Configuration. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeSubscribedWorkteamGets information about a work team provided by a vendor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeTrainingJobReturns information about a training job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeTrainingPlanRetrieves detailed information about a specific training plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeTrainingPlanExtensionHistoryRetrieves the extension history for a specified training plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeTransformJobReturns information about a transform job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeTrialProvides a list of a trial's properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeTrialComponentProvides a list of a trials component's properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeUserProfileDescribes a user profile. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeWorkforceLists private workforce information, including workforce name, Amazon Resource Name (ARN), and, if applicable, allowed IP address ranges (CIDRs). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeWorkteamGets information about a specific work team. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DetachClusterNodeVolumeDetaches your Amazon Elastic Block Store (Amazon EBS) volume from a node in your EKS orchestrated SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DisableSagemakerServicecatalogPortfolioDisables using Service Catalog in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DisassociateTrialComponentDisassociates a trial component from a trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
EnableSagemakerServicecatalogPortfolioEnables using Service Catalog in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ExtendTrainingPlanExtends an existing training plan by purchasing an extension offering. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetDeviceFleetReportDescribes a fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetLineageGroupPolicyThe resource policy for the lineage group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetModelPackageGroupPolicyGets a resource policy that manages access for a model group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetSagemakerServicecatalogPortfolioStatusGets the status of Service Catalog in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetScalingConfigurationRecommendationStarts an Amazon SageMaker Inference Recommender autoscaling recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetSearchSuggestionsAn auto-complete API for the search functionality in the SageMaker console. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ImportHubContentImport hub content. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListActionsLists the actions in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListAIBenchmarkJobsReturns a list of AI benchmark jobs in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListAIRecommendationJobsReturns a list of AI recommendation jobs in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListAIWorkloadConfigsReturns a list of AI workload configurations in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListAlgorithmsLists the machine learning algorithms that have been created. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListAliasesLists the aliases of a specified image or image version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListAppImageConfigsLists the AppImageConfigs in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListAppsLists apps. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListArtifactsLists the artifacts in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListAssociationsLists the associations in your account and their properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListAutoMLJobsRequest a list of jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCandidatesForAutoMLJobList the candidates created for the job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListClusterEventsRetrieves a list of event summaries for a specified HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListClusterNodesRetrieves the list of instances (also called nodes interchangeably) in a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListClustersRetrieves the list of SageMaker HyperPod clusters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListClusterSchedulerConfigsList the cluster policy configurations. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListCodeRepositoriesGets a list of the Git repositories in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCompilationJobsLists model compilation jobs that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListComputeQuotasList the resource allocation definitions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListContextsLists the contexts in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListDataQualityJobDefinitionsLists the data quality job definitions in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListDeviceFleetsReturns a list of devices in the fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListDevicesA list of devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListDomainsLists the domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListEdgeDeploymentPlansLists all edge deployment plans. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListEdgePackagingJobsReturns a list of edge packaging jobs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListEndpointConfigsLists endpoint configurations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListEndpointsLists endpoints. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListExperimentsLists all the experiments in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListFeatureGroupsList FeatureGroups based on given filter and order. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListFlowDefinitionsReturns information about the flow definitions in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListHubContentsList the contents of a hub. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListHubContentVersionsList hub content versions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListHubsList all existing hubs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListHumanTaskUisReturns information about the human task user interfaces in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListHyperParameterTuningJobsGets a list of HyperParameterTuningJobSummary objects that describe the hyperparameter tuning jobs launched in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListImagesLists the images in your account and their properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListImageVersionsLists the versions of a specified image and their properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListInferenceComponentsLists the inference components in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListInferenceExperimentsReturns the list of all inference experiments. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListInferenceRecommendationsJobsLists recommendation jobs that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListInferenceRecommendationsJobStepsReturns a list of the subtasks for an Inference Recommender job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListJobsLists jobs in a specified category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListJobSchemaVersionsLists available configuration schema versions for a specified job category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListLabelingJobsGets a list of labeling jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListLabelingJobsForWorkteamGets a list of labeling jobs assigned to a specified work team. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListLineageGroupsA list of lineage groups shared with your Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListMlflowAppsLists all MLflow Apps Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListMlflowTrackingServersLists all MLflow Tracking Servers. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelBiasJobDefinitionsLists model bias jobs definitions that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelCardExportJobsList the export jobs for the Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListModelCardsList existing model cards. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelCardVersionsList existing versions of an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListModelExplainabilityJobDefinitionsLists model explainability job definitions that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelMetadataLists the domain, framework, task, and model name of standard machine learning models found in common model zoos. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListModelPackageGroupsGets a list of the model groups in your Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelPackagesLists the model packages that have been created. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelQualityJobDefinitionsGets a list of model quality monitoring job definitions in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListModelsLists models created with the CreateModel API. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListMonitoringAlertHistoryGets a list of past alerts in a model monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListMonitoringAlertsGets the alerts for a single monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListMonitoringExecutionsReturns list of all monitoring job executions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListMonitoringSchedulesReturns list of all monitoring schedules. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListNotebookInstanceLifecycleConfigsLists notebook instance lifestyle configurations created with the CreateNotebookInstanceLifecycleConfig API. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListNotebookInstancesReturns a list of the SageMaker AI notebook instances in the requester's account in an Amazon Web Services Region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListOptimizationJobsLists the optimization jobs in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPartnerAppsLists all of the SageMaker Partner AI Apps in an account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelineExecutionsGets a list of the pipeline executions. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelineExecutionStepsGets a list of PipeLineExecutionStep objects. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelineParametersForExecutionGets a list of parameters for a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelinesGets a list of pipelines. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPipelineVersionsGets a list of all versions of the pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListProcessingJobsLists processing jobs that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListProjectsGets a list of the projects in an Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListResourceCatalogsLists Amazon SageMaker Catalogs based on given filters and orders. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListSpacesLists spaces. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListStageDevicesLists devices allocated to the stage, containing detailed device information and deployment status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListStudioLifecycleConfigsLists the Amazon SageMaker AI Studio Lifecycle Configurations in your Amazon Web Services Account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListSubscribedWorkteamsGets a list of the work teams that you are subscribed to in the Amazon Web Services Marketplace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListTagsReturns the tags for the specified SageMaker resource. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTrainingJobsLists training jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTrainingJobsForHyperParameterTuningJobGets a list of TrainingJobSummary objects that describe the training jobs that a hyperparameter tuning job launched. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListTrainingPlansRetrieves a list of training plans for the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTransformJobsLists transform jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTrialComponentsLists the trial components in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTrialsLists the trials in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListUltraServersByReservedCapacityLists all UltraServers that are part of a specified reserved capacity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListUserProfilesLists user profiles. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListWorkforcesUse this operation to list all private and vendor workforces in an Amazon Web Services Region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListWorkteamsGets a list of private work teams that you have defined in a region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
PutModelPackageGroupPolicyAdds a resouce policy to control access to a model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
QueryLineageUse this action to inspect your lineage and discover relationships between entities. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
RegisterDevicesRegister devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
RenderUiTemplateRenders the UI template so that you can preview the worker's experience. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
RetryPipelineExecutionRetry the execution of the pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
SearchFinds SageMaker resources that match a search query. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SearchTrainingPlanOfferingsSearches for available training plan offerings based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
SendPipelineExecutionStepFailureNotifies the pipeline that the execution of a callback step failed, along with a message describing why. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
SendPipelineExecutionStepSuccessNotifies the pipeline that the execution of a callback step succeeded and provides a list of the step's output parameters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartClusterHealthCheckStart deep health checks for a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartEdgeDeploymentStageStarts a stage in an edge deployment plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartInferenceExperimentStarts an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartMlflowTrackingServerProgrammatically start an MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartMonitoringScheduleStarts a previously stopped monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartNotebookInstanceLaunches an ML compute instance with the latest version of the libraries and attaches your ML storage volume. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartPipelineExecutionStarts a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
StartSessionInitiates a remote connection session between a local integrated development environments (IDEs) and a remote SageMaker space. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopAIBenchmarkJobStops a running AI benchmark job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopAIRecommendationJobStops a running AI recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopAutoMLJobA method for forcing a running job to shut down. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopCompilationJobStops a model compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopEdgeDeploymentStageStops a stage in an edge deployment plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopEdgePackagingJobRequest to stop an edge packaging job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopHyperParameterTuningJobStops a running hyperparameter tuning job and all running training jobs that the tuning job launched. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopInferenceExperimentStops an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopInferenceRecommendationsJobStops an Inference Recommender job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopJobStops a running job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopLabelingJobStops a running labeling job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopMlflowTrackingServerProgrammatically stop an MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopMonitoringScheduleStops a previously started monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopNotebookInstanceTerminates the ML compute instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopOptimizationJobEnds a running inference optimization job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopPipelineExecutionStops a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
StopProcessingJobStops a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StopTrainingJobStops a training job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
StopTransformJobStops a batch transform job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateActionUpdates an action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateAppImageConfigUpdates the properties of an AppImageConfig. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateArtifactUpdates an artifact. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateClusterUpdates a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateClusterSchedulerConfigUpdate the cluster policy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateClusterSoftwareUpdates the platform software of a SageMaker HyperPod cluster for security patching. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateCodeRepositoryUpdates the specified Git repository with the specified values. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateComputeQuotaUpdate the compute allocation definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateContextUpdates a context. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateDeviceFleetUpdates a fleet of devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateDevicesUpdates one or more devices in a fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateDomainUpdates the default settings for new user profiles in the domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
UpdateEndpointDeploys the EndpointConfig specified in the request to a new fleet of instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateEndpointWeightsAndCapacitiesUpdates variant weight of one or more variants associated with an existing endpoint, or capacity of one variant associated with an existing endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateExperimentAdds, updates, or removes the description of an experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateFeatureGroupUpdates the feature group by either adding features or updating the online store configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateFeatureMetadataUpdates the description and parameters of the feature group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateHubUpdate a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateHubContentUpdates SageMaker hub content (either a Model or Notebook resource). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateHubContentReferenceUpdates the contents of a SageMaker hub for a ModelReference resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateImageUpdates the properties of a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateImageVersionUpdates the properties of a SageMaker AI image version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateInferenceComponentUpdates an inference component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateInferenceComponentRuntimeConfigRuntime settings for a model that is deployed with an inference component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateInferenceExperimentUpdates an inference experiment that you created. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateMlflowAppUpdates an MLflow App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateMlflowTrackingServerUpdates properties of an existing MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateModelCardUpdate an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateModelPackageUpdates a versioned model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateMonitoringAlertUpdate the parameters of a model monitor alert. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateMonitoringScheduleUpdates a previously created schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateNotebookInstanceUpdates a notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateNotebookInstanceLifecycleConfigUpdates a notebook instance lifecycle configuration created with the CreateNotebookInstanceLifecycleConfig API. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NY
UpdatePartnerAppUpdates all of the SageMaker Partner AI Apps in an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdatePipelineUpdates a pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdatePipelineExecutionUpdates a pipeline execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdatePipelineVersionUpdates a pipeline version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateProjectUpdates a machine learning (ML) project that is created from a template that sets up an ML pipeline from training to deploying an approved model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateSpaceUpdates the settings of a space. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
UpdateTrainingJobUpdate a model training job to request a new Debugger profiling configuration or to change warm pool retention length. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateTrialUpdates the display name of a trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateTrialComponentUpdates one or more properties of a trial component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateUserProfileUpdates a user profile. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateWorkforceUse this operation to update your workforce. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateWorkteamUpdates an existing work team with new member definitions or description. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListSharedModelEventsListSharedModelEvents recorded by CloudTrail for Amazon SageMaker Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN

any: SageMaker Service (catch-all)

#
Service
sagemaker

Description

Catch-all entry for SageMaker Service rules that match the service but not a specific eventName.

AddAssociation

#
Service
sagemaker

Description

Creates an association between the source and the destination. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2e32f2f0-d2ff-4b58-8192-c7cb3a45ae83",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "AddAssociation",
  "awsRegion": "eu-west-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "0548fbc4-8722-42b7-8d73-ed9985e8fa59",
  "userAgent": "sagemaker.amazonaws.com"
}

AddTags

#
Service
sagemaker

Description

Adds or overwrites one or more tags for the specified SageMaker resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

AssociateTrialComponent

#
Service
sagemaker

Description

Associates a trial component with a trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

AttachClusterNodeVolume

#
Service
sagemaker

Description

Attaches your Amazon Elastic Block Store (Amazon EBS) volume to a node in your EKS orchestrated HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchAddClusterNodes

#
Service
sagemaker

Description

Adds nodes to a HyperPod cluster by incrementing the target count for one or more instance groups. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchDeleteClusterNodes

#
Service
sagemaker

Description

Deletes specific nodes within a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchDescribeModelPackage

#
Service
sagemaker

Description

This action batch describes a list of versioned model packages Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchRebootClusterNodes

#
Service
sagemaker

Description

Reboots specific nodes within a SageMaker HyperPod cluster using a soft recovery mechanism. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchReplaceClusterNodes

#
Service
sagemaker

Description

Replaces specific nodes within a SageMaker HyperPod cluster with new hardware. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateAction

#
Service
sagemaker

Description

Creates an action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateAIBenchmarkJob

#
Service
sagemaker

Description

Creates a benchmark job that runs performance benchmarks against inference infrastructure using a predefined AI workload configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateAIRecommendationJob

#
Service
sagemaker

Description

Creates a recommendation job that generates intelligent optimization recommendations for generative AI inference deployments. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateAIWorkloadConfig

#
Service
sagemaker

Description

Creates a reusable AI workload configuration that defines datasets, data sources, and benchmark tool settings for consistent performance testing of generative AI inference deployments on Amazon SageMaker AI. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateAlgorithm

#
Service
sagemaker

Description

Create a machine learning algorithm that you can use in SageMaker and list in the Amazon Web Services Marketplace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateApp

#
Service
sagemaker

Description

Creates a running app for the specified UserProfile. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "331a4e32-1eb4-4174-af64-6cccb0b9fbeb",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateApp",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "739ef306-0a81-4775-bc08-39c307212329",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

CreateAppImageConfig

#
Service
sagemaker

Description

Creates a configuration for running a SageMaker AI image as a KernelGateway app. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateArtifact

#
Service
sagemaker

Description

Creates an artifact. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c39dcc31-a3ed-4fc6-9263-b462b7802cf7",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateArtifact",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "a7f2fe63-828f-4668-abfd-7993375323a5",
  "userAgent": "sagemaker.amazonaws.com"
}

CreateAutoMLJob

#
Service
sagemaker

Description

Creates an Autopilot job also referred to as Autopilot experiment or AutoML job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Execution Role Passed by Unusual Principal source high: Identifies the first time an IAM principal passes a given execution role (roleArn) to an Amazon SageMaker resource, via CreateNotebookInstance, CreateTrainingJob, CreateProcessingJob, CreateAutoMLJob, or CreatePipeline. These actions require iam:PassRole and attach an IAM role that the created resource then runs as. An adversary holding both SageMaker create permissions and a broad iam:PassRole grant can pass a more privileged role to a resource they control and execute code as that role, escalating privileges. The rule keys on the combination of the calling principal and the passed roleArn, so it surfaces a principal using an execution role it has not used before in the last 7 days; a role whose account differs from the caller's, or that is more privileged than the caller, is especially suspicious.T1078, T1078.004↳ also matches CreateNotebookInstance, CreatePipeline, CreateProcessingJob, CreateTrainingJob

CreateAutoMLJobV2

#
Service
sagemaker

Description

Creates an Autopilot job also referred to as Autopilot experiment or AutoML job V2. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateCluster

#
Service
sagemaker

Description

Creates an Amazon SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateClusterSchedulerConfig

#
Service
sagemaker

Description

Create cluster policy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateCodeRepository

#
Service
sagemaker

Description

Creates a Git repository as a resource in your SageMaker AI account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateCompilationJob

#
Service
sagemaker

Description

Starts a model compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateComputeQuota

#
Service
sagemaker

Description

Create compute allocation definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateContext

#
Service
sagemaker

Description

Creates a context. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateDataQualityJobDefinition

#
Service
sagemaker

Description

Creates a definition for a job that monitors data quality and drift. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateDeviceFleet

#
Service
sagemaker

Description

Creates a device fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateDomain

#
Service
sagemaker

Description

Creates a Domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateEdgeDeploymentPlan

#
Service
sagemaker

Description

Creates an edge deployment plan, consisting of multiple stages. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateEdgeDeploymentStage

#
Service
sagemaker

Description

Creates a new stage in an existing edge deployment plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateEdgePackagingJob

#
Service
sagemaker

Description

Starts a SageMaker Edge Manager model packaging job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateEndpoint

#
Service
sagemaker

Description

Creates an endpoint using the endpoint configuration specified in the request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateEndpointConfig

#
Service
sagemaker

Description

Creates an endpoint configuration that SageMaker hosting services uses to deploy models. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateExperiment

#
Service
sagemaker

Description

Creates a SageMaker experiment. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f97eb831-57df-4053-8b4c-a785dff1b7ea",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateExperiment",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "1fffcc5e-2bba-4db6-aafe-e8ad41dc48c7",
  "userAgent": "sagemaker.amazonaws.com"
}

CreateFeatureGroup

#
Service
sagemaker

Description

Create a new FeatureGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateFlowDefinition

#
Service
sagemaker

Description

Creates a flow definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateHub

#
Service
sagemaker

Description

Create a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateHubContentPresignedUrls

#
Service
sagemaker

Description

Creates presigned URLs for accessing hub content artifacts. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateHubContentReference

#
Service
sagemaker

Description

Create a hub content reference in order to add a model in the JumpStart public hub to a private hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateHumanTaskUi

#
Service
sagemaker

Description

Defines the settings you will use for the human review workflow user interface. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateHyperParameterTuningJob

#
Service
sagemaker

Description

Starts a hyperparameter tuning job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateImage

#
Service
sagemaker

Description

Creates a custom SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateImageVersion

#
Service
sagemaker

Description

Creates a version of the SageMaker AI image specified by ImageName. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateInferenceComponent

#
Service
sagemaker

Description

Creates an inference component, which is a SageMaker AI hosting object that you can use to deploy a model to an endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateInferenceExperiment

#
Service
sagemaker

Description

Creates an inference experiment using the configurations specified in the request. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateInferenceRecommendationsJob

#
Service
sagemaker

Description

Starts a recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateJob

#
Service
sagemaker

Description

Creates a model customization job in Amazon SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateLabelingJob

#
Service
sagemaker

Description

Creates a job that uses workers to label the data objects in your input dataset. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateMlflowApp

#
Service
sagemaker

Description

Creates an MLflow Tracking Server using a general purpose Amazon S3 bucket as the artifact store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateMlflowTrackingServer

#
Service
sagemaker

Description

Creates an MLflow Tracking Server using a general purpose Amazon S3 bucket as the artifact store. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModel

#
Service
sagemaker

Description

Creates a model in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelBiasJobDefinition

#
Service
sagemaker

Description

Creates the definition for a model bias job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelCard

#
Service
sagemaker

Description

Creates an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelCardExportJob

#
Service
sagemaker

Description

Creates an Amazon SageMaker Model Card export job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelExplainabilityJobDefinition

#
Service
sagemaker

Description

Creates the definition for a model explainability job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelPackage

#
Service
sagemaker

Description

Creates a model package that you can use to create SageMaker models or list on Amazon Web Services Marketplace, or a versioned model that is part of a model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelPackageGroup

#
Service
sagemaker

Description

Creates a model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateModelQualityJobDefinition

#
Service
sagemaker

Description

Creates a definition for a job that monitors model quality and drift. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateMonitoringSchedule

#
Service
sagemaker

Description

Creates a schedule that regularly starts Amazon SageMaker AI Processing Jobs to monitor the data captured for an Amazon SageMaker AI Endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateNotebookInstance

#
Service
sagemaker

Description

Creates an SageMaker AI notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Execution Role Passed by Unusual Principal source high: Identifies the first time an IAM principal passes a given execution role (roleArn) to an Amazon SageMaker resource, via CreateNotebookInstance, CreateTrainingJob, CreateProcessingJob, CreateAutoMLJob, or CreatePipeline. These actions require iam:PassRole and attach an IAM role that the created resource then runs as. An adversary holding both SageMaker create permissions and a broad iam:PassRole grant can pass a more privileged role to a resource they control and execute code as that role, escalating privileges. The rule keys on the combination of the calling principal and the passed roleArn, so it surfaces a principal using an execution role it has not used before in the last 7 days; a role whose account differs from the caller's, or that is more privileged than the caller, is especially suspicious.T1078, T1078.004↳ also matches CreateAutoMLJob, CreatePipeline, CreateProcessingJob, CreateTrainingJob

CreateNotebookInstanceLifecycleConfig

#
Service
sagemaker

Description

Creates a lifecycle configuration that you can associate with a notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content source high: Identifies an Amazon SageMaker notebook lifecycle configuration whose OnStart or OnCreate script, after base64 decoding, contains patterns associated with malicious activity such as reverse shells, EC2 instance metadata (IMDS) credential access, or download-and-execute commands. A lifecycle configuration runs as root on the notebook instance, so a script with these patterns is a strong indicator of an attempt to backdoor the notebook, steal the execution role's credentials, or establish persistent code execution. This rule decodes the script in the request and matches high-signal indicators; it is a higher-fidelity companion to the rule that alerts on any lifecycle configuration change.T1059, T1059.004, T1546↳ also matches UpdateNotebookInstanceLifecycleConfig

CreateOptimizationJob

#
Service
sagemaker

Description

Creates a job that optimizes a model for inference performance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreatePartnerApp

#
Service
sagemaker

Description

Creates an Amazon SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreatePartnerAppPresignedUrl

#
Service
sagemaker

Description

Creates a presigned URL to access an Amazon SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreatePipeline

#
Service
sagemaker

Description

Creates a pipeline using a JSON pipeline definition. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "15410bec-195a-44be-aaf9-a61e44208538",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreatePipeline",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "a9adcb28-2de0-49d9-a8b6-7e3bd549ca1c",
  "userAgent": "Boto3/1.43.52 md/Botocore#1.43.52 ua/2.1 os/linux#5.10.255-259-299.1043.amzn2.aarch64 md/arch#aarch64 lang/python#3.12.13 md/pyimpl#CPython exec-env/AWS_Lambda_python3.12 m/b,D,Z,g cfg/retry-mode#legacy Botocore/1.43.52 lib/AWS-SageMaker-Python-SDK#2.257.2 PT/no-op/3.31.1 PTEnv/AWS_Lambda_python3.12",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Execution Role Passed by Unusual Principal source high: Identifies the first time an IAM principal passes a given execution role (roleArn) to an Amazon SageMaker resource, via CreateNotebookInstance, CreateTrainingJob, CreateProcessingJob, CreateAutoMLJob, or CreatePipeline. These actions require iam:PassRole and attach an IAM role that the created resource then runs as. An adversary holding both SageMaker create permissions and a broad iam:PassRole grant can pass a more privileged role to a resource they control and execute code as that role, escalating privileges. The rule keys on the combination of the calling principal and the passed roleArn, so it surfaces a principal using an execution role it has not used before in the last 7 days; a role whose account differs from the caller's, or that is more privileged than the caller, is especially suspicious.T1078, T1078.004↳ also matches CreateAutoMLJob, CreateNotebookInstance, CreateProcessingJob, CreateTrainingJob

CreatePresignedDomainUrl

#
Service
sagemaker

Description

Creates a URL for a specified UserProfile in a Domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "79712c97-c73e-4d06-8565-05075a30e85a",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreatePresignedDomainUrl",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "344d3081-5122-42e2-bb3c-d643313a72e6",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

CreatePresignedMlflowAppUrl

#
Service
sagemaker

Description

Returns a presigned URL that you can use to connect to the MLflow UI attached to your MLflow App. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "94769739-70e2-49d7-bafe-d5c7177f6bd2",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreatePresignedMlflowAppUrl",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "06433377-d632-47bb-8a17-1070f774fc0e",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::MlflowApp",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:mlflow-app/EXAMPLE"
    }
  ]
}

CreatePresignedMlflowTrackingServerUrl

#
Service
sagemaker

Description

Returns a presigned URL that you can use to connect to the MLflow UI attached to your tracking server. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "868d887f-7494-4035-8b42-e05ddff58786",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreatePresignedMlflowTrackingServerUrl",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "ad50b2ae-4b42-4447-a191-cecba2183ed5",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

CreatePresignedNotebookInstanceUrl

#
Service
sagemaker

Description

Returns a URL that you can use to connect to the Jupyter server from a notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateProcessingJob

#
Service
sagemaker

Description

Creates a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Execution Role Passed by Unusual Principal source high: Identifies the first time an IAM principal passes a given execution role (roleArn) to an Amazon SageMaker resource, via CreateNotebookInstance, CreateTrainingJob, CreateProcessingJob, CreateAutoMLJob, or CreatePipeline. These actions require iam:PassRole and attach an IAM role that the created resource then runs as. An adversary holding both SageMaker create permissions and a broad iam:PassRole grant can pass a more privileged role to a resource they control and execute code as that role, escalating privileges. The rule keys on the combination of the calling principal and the passed roleArn, so it surfaces a principal using an execution role it has not used before in the last 7 days; a role whose account differs from the caller's, or that is more privileged than the caller, is especially suspicious.T1078, T1078.004↳ also matches CreateAutoMLJob, CreateNotebookInstance, CreatePipeline, CreateTrainingJob

CreateProject

#
Service
sagemaker

Description

Creates a machine learning (ML) project that can contain one or more templates that set up an ML pipeline from training to deploying an approved model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateSpace

#
Service
sagemaker

Description

Creates a private space or a space used for real time collaboration in a domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4b2743ff-161d-4177-9390-928596c566b7",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateSpace",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "54516aa7-3564-4ab5-a70e-0f05afb78b37",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

CreateStudioLifecycleConfig

#
Service
sagemaker

Description

Creates a new Amazon SageMaker AI Studio Lifecycle Configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateTrainingJob

#
Service
sagemaker

Description

Starts a model training job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "caa16145-445a-40c7-a24d-6a364af9bbab",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateTrainingJob",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "580d35e8-5cc6-49b1-8842-b90702d78aae",
  "userAgent": "pipelines.sagemaker.amazonaws.com"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Execution Role Passed by Unusual Principal source high: Identifies the first time an IAM principal passes a given execution role (roleArn) to an Amazon SageMaker resource, via CreateNotebookInstance, CreateTrainingJob, CreateProcessingJob, CreateAutoMLJob, or CreatePipeline. These actions require iam:PassRole and attach an IAM role that the created resource then runs as. An adversary holding both SageMaker create permissions and a broad iam:PassRole grant can pass a more privileged role to a resource they control and execute code as that role, escalating privileges. The rule keys on the combination of the calling principal and the passed roleArn, so it surfaces a principal using an execution role it has not used before in the last 7 days; a role whose account differs from the caller's, or that is more privileged than the caller, is especially suspicious.T1078, T1078.004↳ also matches CreateAutoMLJob, CreateNotebookInstance, CreatePipeline, CreateProcessingJob

CreateTrainingPlan

#
Service
sagemaker

Description

Creates a new training plan in SageMaker to reserve compute capacity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateTransformJob

#
Service
sagemaker

Description

Starts a transform job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateTrial

#
Service
sagemaker

Description

Creates an SageMaker trial. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "cc8a7669-4e44-470a-8939-7d13d6b17fc3",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateTrial",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "1609ae90-6310-45d3-8b92-254c3f7fa068",
  "userAgent": "sagemaker.amazonaws.com"
}

CreateTrialComponent

#
Service
sagemaker

Description

Creates a trial component, which is a stage of a machine learning trial. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2e739bc6-59f5-488b-8a07-3bebf63395f9",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "CreateTrialComponent",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "07583283-dfb8-4d2e-aa69-859af24225ae",
  "userAgent": "sagemaker.amazonaws.com"
}

CreateUserProfile

#
Service
sagemaker

Description

Creates a user profile. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateWorkforce

#
Service
sagemaker

Description

Use this operation to create a workforce. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateWorkteam

#
Service
sagemaker

Description

Creates a new work team for labeling your data. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteAction

#
Service
sagemaker

Description

Deletes an action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteAIBenchmarkJob

#
Service
sagemaker

Description

Deletes the specified AI benchmark job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteAIRecommendationJob

#
Service
sagemaker

Description

Deletes the specified AI recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteAIWorkloadConfig

#
Service
sagemaker

Description

Deletes the specified AI workload configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteAlgorithm

#
Service
sagemaker

Description

Removes the specified algorithm from your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteApp

#
Service
sagemaker

Description

Used to stop and delete an app. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3ac60ced-0c3f-4754-82a8-b8db5f98a944",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DeleteApp",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "92aef453-ab6b-4336-b588-4af73dddbd46",
  "userAgent": "global.workflows.looseleaf.im.amazonaws.com"
}

DeleteAppImageConfig

#
Service
sagemaker

Description

Deletes an AppImageConfig. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteArtifact

#
Service
sagemaker

Description

Deletes an artifact. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteAssociation

#
Service
sagemaker

Description

Deletes an association. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteCluster

#
Service
sagemaker

Description

Delete a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteClusterSchedulerConfig

#
Service
sagemaker

Description

Deletes the cluster policy of the cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteCodeRepository

#
Service
sagemaker

Description

Deletes the specified Git repository from your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteCompilationJob

#
Service
sagemaker

Description

Deletes the specified compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteComputeQuota

#
Service
sagemaker

Description

Deletes the compute allocation from the cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteContext

#
Service
sagemaker

Description

Deletes an context. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteDataQualityJobDefinition

#
Service
sagemaker

Description

Deletes a data quality monitoring job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteDeviceFleet

#
Service
sagemaker

Description

Deletes a fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteDomain

#
Service
sagemaker

Description

Used to delete a domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteEdgeDeploymentPlan

#
Service
sagemaker

Description

Deletes an edge deployment plan if (and only if) all the stages in the plan are inactive or there are no stages in the plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteEdgeDeploymentStage

#
Service
sagemaker

Description

Delete a stage in an edge deployment plan if (and only if) the stage is inactive. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteEndpoint

#
Service
sagemaker

Description

Deletes an endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteEndpointConfig

#
Service
sagemaker

Description

Deletes an endpoint configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteExperiment

#
Service
sagemaker

Description

Deletes an SageMaker experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteFeatureGroup

#
Service
sagemaker

Description

Delete the FeatureGroup and any data that was written to the OnlineStore of the FeatureGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteFlowDefinition

#
Service
sagemaker

Description

Deletes the specified flow definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteHub

#
Service
sagemaker

Description

Delete a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteHubContent

#
Service
sagemaker

Description

Delete the contents of a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteHubContentReference

#
Service
sagemaker

Description

Delete a hub content reference in order to remove a model from a private hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteHumanTaskUi

#
Service
sagemaker

Description

Use this operation to delete a human task user interface (worker task template). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteHyperParameterTuningJob

#
Service
sagemaker

Description

Deletes a hyperparameter tuning job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteImage

#
Service
sagemaker

Description

Deletes a SageMaker AI image and all versions of the image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteImageVersion

#
Service
sagemaker

Description

Deletes a version of a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteInferenceComponent

#
Service
sagemaker

Description

Deletes an inference component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteInferenceExperiment

#
Service
sagemaker

Description

Deletes an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteJob

#
Service
sagemaker

Description

Deletes a job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteMlflowApp

#
Service
sagemaker

Description

Deletes an MLflow App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteMlflowTrackingServer

#
Service
sagemaker

Description

Deletes an MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModel

#
Service
sagemaker

Description

Deletes a model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelBiasJobDefinition

#
Service
sagemaker

Description

Deletes an Amazon SageMaker AI model bias job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelCard

#
Service
sagemaker

Description

Deletes an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelExplainabilityJobDefinition

#
Service
sagemaker

Description

Deletes an Amazon SageMaker AI model explainability job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelPackage

#
Service
sagemaker

Description

Deletes a model package. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelPackageGroup

#
Service
sagemaker

Description

Deletes the specified model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelPackageGroupPolicy

#
Service
sagemaker

Description

Deletes a model group resource policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteModelQualityJobDefinition

#
Service
sagemaker

Description

Deletes the secified model quality monitoring job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteMonitoringSchedule

#
Service
sagemaker

Description

Deletes a monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteNotebookInstance

#
Service
sagemaker

Description

Deletes an SageMaker AI notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteNotebookInstanceLifecycleConfig

#
Service
sagemaker

Description

Deletes a notebook instance lifecycle configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteOptimizationJob

#
Service
sagemaker

Description

Deletes an optimization job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeletePartnerApp

#
Service
sagemaker

Description

Deletes a SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeletePipeline

#
Service
sagemaker

Description

Deletes a pipeline if there are no running instances of the pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fcfaf44d-bbe1-4508-b006-3d2e1f69f848",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DeletePipeline",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "7831c0ca-59a2-45bc-ba43-9e726a466896",
  "userAgent": "Boto3/1.43.52 md/Botocore#1.43.52 ua/2.1 os/linux#5.10.255-259-299.1043.amzn2.aarch64 md/arch#aarch64 lang/python#3.12.13 md/pyimpl#CPython exec-env/AWS_Lambda_python3.12 m/Z,g,b,D cfg/retry-mode#legacy Botocore/1.43.52 PT/no-op/3.31.1 PTEnv/AWS_Lambda_python3.12",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

DeleteProcessingJob

#
Service
sagemaker

Description

Deletes a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteProject

#
Service
sagemaker

Description

Delete the specified project. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteSpace

#
Service
sagemaker

Description

Used to delete a space. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a249c06f-f35c-4e8a-8aa7-0ae20959f62d",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DeleteSpace",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "32e2c008-6e2d-4a9c-a1e4-7fecb889cbae",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DeleteStudioLifecycleConfig

#
Service
sagemaker

Description

Deletes the Amazon SageMaker AI Studio Lifecycle Configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteTags

#
Service
sagemaker

Description

Deletes the specified tags from an SageMaker resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteTrainingJob

#
Service
sagemaker

Description

Deletes a training job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteTrial

#
Service
sagemaker

Description

Deletes the specified trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteTrialComponent

#
Service
sagemaker

Description

Deletes the specified trial component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteUserProfile

#
Service
sagemaker

Description

Deletes a user profile. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteWorkforce

#
Service
sagemaker

Description

Use this operation to delete a workforce. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteWorkteam

#
Service
sagemaker

Description

Deletes an existing work team. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeregisterDevices

#
Service
sagemaker

Description

Deregisters the specified devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeAction

#
Service
sagemaker

Description

Describes an action. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6f967494-a116-4518-845f-6f1716fb8658",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeAction",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b4698f8e-ae96-4baf-ae92-86ea2d74ef17",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Action",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:action/EXAMPLE"
    }
  ]
}

DescribeAIBenchmarkJob

#
Service
sagemaker

Description

Returns details of an AI benchmark job, including its status, configuration, target endpoint, and timing information. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeAIRecommendationJob

#
Service
sagemaker

Description

Returns details of an AI recommendation job, including its status, model source, performance targets, optimization recommendations, and deployment configurations. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeAIWorkloadConfig

#
Service
sagemaker

Description

Returns details of an AI workload configuration, including the dataset configuration, benchmark tool settings, tags, and creation time. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeAlgorithm

#
Service
sagemaker

Description

Returns a description of the specified algorithm that is in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeApp

#
Service
sagemaker

Description

Describes the app. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3dcd5356-529a-47d9-8a97-dcf96e64485a",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeApp",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "653c21ba-c124-47f4-868b-49988c75f34c",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeAppImageConfig

#
Service
sagemaker

Description

Describes an AppImageConfig. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeArtifact

#
Service
sagemaker

Description

Describes an artifact. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeAutoMLJob

#
Service
sagemaker

Description

Returns information about an AutoML job created by calling CreateAutoMLJob. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1c73215b-2bec-4ab0-b1a8-07f8fa4ab3ec",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeAutoMLJob",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b9b19719-a42c-4338-a109-c536c1d97f19",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "ValidationException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeAutoMLJobV2

#
Service
sagemaker

Description

Returns information about an AutoML job created by calling CreateAutoMLJobV2 or CreateAutoMLJob. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f2b075a5-80bf-4f48-8bba-e5dfa155b71d",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeAutoMLJobV2",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f7f37a2d-8406-43d6-aed6-3b487c526429",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeCluster

#
Service
sagemaker

Description

Retrieves information of a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeClusterEvent

#
Service
sagemaker

Description

Retrieves detailed information about a specific event for a given HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeClusterNode

#
Service
sagemaker

Description

Retrieves information of a node (also called a instance interchangeably) of a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeClusterSchedulerConfig

#
Service
sagemaker

Description

Description of the cluster policy. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeCodeRepository

#
Service
sagemaker

Description

Gets details about the specified Git repository. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5479420c-e72a-40f3-a887-2c2a48adb53a",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeCodeRepository",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "81a03658-7ce0-4932-bfa9-c6e35619319b",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeCompilationJob

#
Service
sagemaker

Description

Returns information about a model compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeComputeQuota

#
Service
sagemaker

Description

Description of the compute allocation definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeContext

#
Service
sagemaker

Description

Describes a context. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b3af021b-7fb7-4648-9f39-5d3e1116d214",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeContext",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "da8aeb42-dee6-4b83-970c-830fe1fb3f67",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Context",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:context/EXAMPLE"
    }
  ]
}

DescribeDataQualityJobDefinition

#
Service
sagemaker

Description

Gets the details of a data quality monitoring job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeDevice

#
Service
sagemaker

Description

Describes the device. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeDeviceFleet

#
Service
sagemaker

Description

A description of the fleet the device belongs to. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeDomain

#
Service
sagemaker

Description

The description of the domain. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeEdgeDeploymentPlan

#
Service
sagemaker

Description

Describes an edge deployment plan with deployment status per stage. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeEdgePackagingJob

#
Service
sagemaker

Description

A description of edge packaging jobs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeEndpoint

#
Service
sagemaker

Description

Returns the description of an endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeEndpointConfig

#
Service
sagemaker

Description

Returns the description of an endpoint configuration created using the CreateEndpointConfig API. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "168cd37e-5102-47cd-8758-f5a85b3c42e2",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeEndpointConfig",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "92d8078b-b8e4-4cd3-8fcf-8a8337f7d3b3",
  "userAgent": "config.amazonaws.com"
}

DescribeExperiment

#
Service
sagemaker

Description

Provides a list of an experiment's properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0e9e3c84-686e-4a0a-bf4a-d5313d7762dd",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeExperiment",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d226883c-5ab4-4514-bb59-104088af7d24",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeFeatureGroup

#
Service
sagemaker

Description

Use this operation to describe a FeatureGroup. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeFeatureMetadata

#
Service
sagemaker

Description

Shows the metadata for a feature within a feature group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeFlowDefinition

#
Service
sagemaker

Description

Returns information about the specified flow definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeHub

#
Service
sagemaker

Description

Describes a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeHubContent

#
Service
sagemaker

Description

Describe the content of a hub. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d5ab5685-49da-4246-aaeb-a513fb36b3eb",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeHubContent",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "63e57465-f1b9-48c0-a166-f4b25d20a389",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeHumanTaskUi

#
Service
sagemaker

Description

Returns information about the requested human task user interface (worker task template). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeHyperParameterTuningJob

#
Service
sagemaker

Description

Returns a description of a hyperparameter tuning job, depending on the fields selected. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeImage

#
Service
sagemaker

Description

Describes a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeImageVersion

#
Service
sagemaker

Description

Describes a version of a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeInferenceComponent

#
Service
sagemaker

Description

Returns information about an inference component. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "18a6820a-e2f4-44c1-b12b-d7bb5d3ee5d5",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeInferenceComponent",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "0405b9b9-4ad6-4332-8b17-0d99a42d52ad",
  "userAgent": "config.amazonaws.com"
}

DescribeInferenceExperiment

#
Service
sagemaker

Description

Returns details about an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeInferenceRecommendationsJob

#
Service
sagemaker

Description

Provides the results of the Inference Recommender job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeJob

#
Service
sagemaker

Description

Returns detailed information about a job, including its current status, secondary status, configuration, and timestamps. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeJobSchemaVersion

#
Service
sagemaker

Description

Returns the JSON schema for a specified job category and schema version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeLabelingJob

#
Service
sagemaker

Description

Gets information about a labeling job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeLineageGroup

#
Service
sagemaker

Description

Provides a list of properties for the requested lineage group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "26488360-c6f1-4873-b813-feb570b22b0d",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeLineageGroup",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4260ec63-9b45-4a9e-a287-6c5222e83e0d",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

DescribeMlflowApp

#
Service
sagemaker

Description

Returns information about an MLflow App. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1a995f33-d0af-4665-86ed-b8eed17dac1a",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeMlflowApp",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "78907546-aec0-4fe7-8a10-65ae8965c847",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeMlflowTrackingServer

#
Service
sagemaker

Description

Returns information about an MLflow Tracking Server. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8fc1c883-8caf-487b-8d0c-5c073e191cfe",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeMlflowTrackingServer",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bdf0c562-cf02-40fb-ac48-1b6174d2106f",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeModel

#
Service
sagemaker

Description

Describes a model that you created using the CreateModel API. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ae4b4e77-2164-4fbd-b375-affe9149be1f",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeModel",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "9062d331-aead-4a12-af38-819d68b28220",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeModelBiasJobDefinition

#
Service
sagemaker

Description

Returns a description of a model bias job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeModelCard

#
Service
sagemaker

Description

Describes the content, creation time, and security configuration of an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeModelCardExportJob

#
Service
sagemaker

Description

Describes an Amazon SageMaker Model Card export job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeModelExplainabilityJobDefinition

#
Service
sagemaker

Description

Returns a description of a model explainability job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeModelPackage

#
Service
sagemaker

Description

Returns a description of the specified model package, which is used to create SageMaker models or list them on Amazon Web Services Marketplace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeModelPackageGroup

#
Service
sagemaker

Description

Gets a description for the specified model group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2d11a95a-2950-4a14-9ec7-dde241da7248",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeModelPackageGroup",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c022d83d-b098-4d3e-9946-a1b178be277b",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::ModelPackageGroup",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:model-package-group/EXAMPLE"
    }
  ]
}

DescribeModelQualityJobDefinition

#
Service
sagemaker

Description

Returns a description of a model quality job definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeMonitoringSchedule

#
Service
sagemaker

Description

Describes the schedule for a monitoring job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeNotebookInstance

#
Service
sagemaker

Description

Returns information about a notebook instance. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "790edf88-21c1-4796-bd65-d3f2080a0859",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeNotebookInstance",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ce159829-3d98-4d8e-ab23-9f4fbb778159",
  "userAgent": "config.amazonaws.com"
}

DescribeNotebookInstanceLifecycleConfig

#
Service
sagemaker

Description

Returns a description of a notebook instance lifecycle configuration. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6a879cd9-20da-4f52-b1c4-1e14c0468aca",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeNotebookInstanceLifecycleConfig",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "0e934107-7584-4502-bbfe-1b59c46d0985",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeOptimizationJob

#
Service
sagemaker

Description

Provides the properties of the specified optimization job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribePartnerApp

#
Service
sagemaker

Description

Gets information about a SageMaker Partner AI App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribePipeline

#
Service
sagemaker

Description

Describes the details of a pipeline. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9b40dcd5-6793-4847-9f40-4a60cac7a77e",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribePipeline",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "41a497ed-9bfe-468d-a191-56b3fd2ca88f",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.176-223.369.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:eu-west-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

DescribePipelineDefinitionForExecution

#
Service
sagemaker

Description

Describes the details of an execution's pipeline definition. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9fd1fd9a-3a91-4d0e-8783-0dd962e23cbc",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribePipelineDefinitionForExecution",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "eb1e9401-802c-4264-9a22-c8562871e0fd",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:eu-west-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

DescribePipelineExecution

#
Service
sagemaker

Description

Describes the details of a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fc520a4a-d620-4ad2-a6a9-be219d13d0bd",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribePipelineExecution",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a384d3f4-801b-4dd4-9286-2b484ff7a834",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ca-central-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:ca-central-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

DescribeProcessingJob

#
Service
sagemaker

Description

Returns a description of a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeProject

#
Service
sagemaker

Description

Describes the details of a project. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "efcf02f8-0a95-4032-a7bb-abfe57b24117",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeProject",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ad821c04-8faf-4d1e-a3e2-2a8d4cec7326",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeReservedCapacity

#
Service
sagemaker

Description

Retrieves details about a reserved capacity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeSpace

#
Service
sagemaker

Description

Describes the space. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4c39e786-9ddd-422c-814c-36c9de58b242",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeSpace",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d59517e4-701d-4917-be9f-042c5f357fb5",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

DescribeStudioLifecycleConfig

#
Service
sagemaker

Description

Describes the Amazon SageMaker AI Studio Lifecycle Configuration. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "81b615e7-6b2c-4b40-90ca-a2433e56bc61",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeStudioLifecycleConfig",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "fcc61779-e1ef-4d89-af99-52b4af6ceda8",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.253.1 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

DescribeSubscribedWorkteam

#
Service
sagemaker

Description

Gets information about a work team provided by a vendor. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeTrainingJob

#
Service
sagemaker

Description

Returns information about a training job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2fddcaf6-6a5e-4e91-a14c-9421d03eb3d7",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeTrainingJob",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "6de2a376-8e31-4380-805b-ce13737b6945",
  "userAgent": "pipelines.sagemaker.amazonaws.com"
}

DescribeTrainingPlan

#
Service
sagemaker

Description

Retrieves detailed information about a specific training plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeTrainingPlanExtensionHistory

#
Service
sagemaker

Description

Retrieves the extension history for a specified training plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeTransformJob

#
Service
sagemaker

Description

Returns information about a transform job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeTrial

#
Service
sagemaker

Description

Provides a list of a trial's properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeTrialComponent

#
Service
sagemaker

Description

Provides a list of a trials component's properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeUserProfile

#
Service
sagemaker

Description

Describes a user profile. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c93eb304-674a-4993-b3fc-716f818bb138",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "DescribeUserProfile",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "9715a7dc-58a6-4ea9-92ee-e23638fee975",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

DescribeWorkforce

#
Service
sagemaker

Description

Lists private workforce information, including workforce name, Amazon Resource Name (ARN), and, if applicable, allowed IP address ranges (CIDRs). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeWorkteam

#
Service
sagemaker

Description

Gets information about a specific work team. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DetachClusterNodeVolume

#
Service
sagemaker

Description

Detaches your Amazon Elastic Block Store (Amazon EBS) volume from a node in your EKS orchestrated SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DisableSagemakerServicecatalogPortfolio

#
Service
sagemaker

Description

Disables using Service Catalog in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DisassociateTrialComponent

#
Service
sagemaker

Description

Disassociates a trial component from a trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

EnableSagemakerServicecatalogPortfolio

#
Service
sagemaker

Description

Enables using Service Catalog in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ExtendTrainingPlan

#
Service
sagemaker

Description

Extends an existing training plan by purchasing an extension offering. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetDeviceFleetReport

#
Service
sagemaker

Description

Describes a fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetLineageGroupPolicy

#
Service
sagemaker

Description

The resource policy for the lineage group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetModelPackageGroupPolicy

#
Service
sagemaker

Description

Gets a resource policy that manages access for a model group. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b21aeb0b-35f2-46da-b4b1-6cc3dd17fec3",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "GetModelPackageGroupPolicy",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "e896deff-1016-4f88-a855-4ccbf2a4cef6",
  "userAgent": "config.amazonaws.com",
  "errorCode": "ValidationException"
}

GetSagemakerServicecatalogPortfolioStatus

#
Service
sagemaker

Description

Gets the status of Service Catalog in SageMaker. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetScalingConfigurationRecommendation

#
Service
sagemaker

Description

Starts an Amazon SageMaker Inference Recommender autoscaling recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetSearchSuggestions

#
Service
sagemaker

Description

An auto-complete API for the search functionality in the SageMaker console. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ImportHubContent

#
Service
sagemaker

Description

Import hub content. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListActions

#
Service
sagemaker

Description

Lists the actions in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c1dca51b-3af8-438c-8ae2-56b71e620b85",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListActions",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "10010b5f-d3ba-4c50-97ca-6383183c6edc",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListAIBenchmarkJobs

#
Service
sagemaker

Description

Returns a list of AI benchmark jobs in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListAIRecommendationJobs

#
Service
sagemaker

Description

Returns a list of AI recommendation jobs in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListAIWorkloadConfigs

#
Service
sagemaker

Description

Returns a list of AI workload configurations in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListAlgorithms

#
Service
sagemaker

Description

Lists the machine learning algorithms that have been created. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bfd98f55-f21e-4cb5-8c2f-0914f1cecc9e",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListAlgorithms",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a53e519c-13a1-4119-985b-1439bcff8a15",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListAliases

#
Service
sagemaker

Description

Lists the aliases of a specified image or image version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListAppImageConfigs

#
Service
sagemaker

Description

Lists the AppImageConfigs in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c0be9ac4-88b9-49e1-8647-90b91d1dd280",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListAppImageConfigs",
  "awsRegion": "ap-southeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "533fe0b9-2331-415f-aaa4-231a7ac19cfd",
  "userAgent": "config.amazonaws.com"
}

ListApps

#
Service
sagemaker

Description

Lists apps. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListArtifacts

#
Service
sagemaker

Description

Lists the artifacts in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e7b27baf-5a90-4f0b-9f54-9102b046cbbc",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListArtifacts",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b13023ab-d727-40ab-8a47-da0af8242bae",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListAssociations

#
Service
sagemaker

Description

Lists the associations in your account and their properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListAutoMLJobs

#
Service
sagemaker

Description

Request a list of jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6bccde77-4658-4df8-8d4b-d413a6753a4e",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListAutoMLJobs",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c9bf6504-3bc5-4bf2-af80-911ca13409e0",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListCandidatesForAutoMLJob

#
Service
sagemaker

Description

List the candidates created for the job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7d7073d6-c946-4735-84db-4a14c4768055",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListCandidatesForAutoMLJob",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "64402704-fe7a-4f10-9594-75a2b45318c6",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListClusterEvents

#
Service
sagemaker

Description

Retrieves a list of event summaries for a specified HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListClusterNodes

#
Service
sagemaker

Description

Retrieves the list of instances (also called nodes interchangeably) in a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListClusters

#
Service
sagemaker

Description

Retrieves the list of SageMaker HyperPod clusters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListClusterSchedulerConfigs

#
Service
sagemaker

Description

List the cluster policy configurations. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListCodeRepositories

#
Service
sagemaker

Description

Gets a list of the Git repositories in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "782ef0b7-d8a9-484c-beb1-c3ff09bfc68a",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListCodeRepositories",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "102c62f9-4f49-4fe6-b1d9-dc9e2e5c88a4",
  "userAgent": "config.amazonaws.com"
}

ListCompilationJobs

#
Service
sagemaker

Description

Lists model compilation jobs that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f2343ea8-aae0-4c4a-b83d-4cf01eb62f43",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListCompilationJobs",
  "awsRegion": "ap-northeast-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1ca89002-ce85-4047-8097-0dd283f7347f",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-northeast-3.amazonaws.com"
  }
}

ListComputeQuotas

#
Service
sagemaker

Description

List the resource allocation definitions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListContexts

#
Service
sagemaker

Description

Lists the contexts in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "53ac5fe0-41af-4017-9e64-5e50ad8afd03",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListContexts",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3459c16e-95dc-443c-997d-8192e5aacb5a",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListDataQualityJobDefinitions

#
Service
sagemaker

Description

Lists the data quality job definitions in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ef5997d4-5521-43fa-8a9e-99ebcc1cedb3",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListDataQualityJobDefinitions",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "55695e5a-1747-4afb-b25f-970291b46a4a",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

ListDeviceFleets

#
Service
sagemaker

Description

Returns a list of devices in the fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListDevices

#
Service
sagemaker

Description

A list of devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListDomains

#
Service
sagemaker

Description

Lists the domains. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListEdgeDeploymentPlans

#
Service
sagemaker

Description

Lists all edge deployment plans. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListEdgePackagingJobs

#
Service
sagemaker

Description

Returns a list of edge packaging jobs. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListEndpointConfigs

#
Service
sagemaker

Description

Lists endpoint configurations. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d51312a9-e81a-4b15-b456-4e78be39a346",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListEndpointConfigs",
  "awsRegion": "eu-north-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "42d74487-a721-4bb5-baf4-05874a7c2a67",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-north-1.amazonaws.com"
  }
}

ListEndpoints

#
Service
sagemaker

Description

Lists endpoints. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c5c097ae-6e59-4638-b2bd-3b4ac15fa034",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListEndpoints",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "fe1a91c3-24b7-4d57-a9b2-0f242ac56aa8",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ca-central-1.amazonaws.com"
  }
}

ListExperiments

#
Service
sagemaker

Description

Lists all the experiments in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListFeatureGroups

#
Service
sagemaker

Description

List FeatureGroups based on given filter and order. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bd1bdb89-a841-4bda-869a-630aee21234b",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListFeatureGroups",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "80321500-5e93-42b8-89a1-be30c8c385bc",
  "userAgent": "config.amazonaws.com"
}

ListFlowDefinitions

#
Service
sagemaker

Description

Returns information about the flow definitions in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d3cf8b7e-4d0d-4008-b8c1-92facb9c6996",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListFlowDefinitions",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b6cee4e2-eed9-4dbc-9e4a-33706cc90e0a",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListHubContents

#
Service
sagemaker

Description

List the contents of a hub. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "81c4a1aa-f33f-4a53-a907-2abb3cb062fc",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListHubContents",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "80948495-90b8-486e-8984-cdb175b606b3",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListHubContentVersions

#
Service
sagemaker

Description

List hub content versions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListHubs

#
Service
sagemaker

Description

List all existing hubs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6dbdb5e9-16da-46cb-becb-be24eef357a3",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListHubs",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ffad1be5-a8bc-453c-9ae9-5dfc56bdbff5",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListHumanTaskUis

#
Service
sagemaker

Description

Returns information about the human task user interfaces in your account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListHyperParameterTuningJobs

#
Service
sagemaker

Description

Gets a list of HyperParameterTuningJobSummary objects that describe the hyperparameter tuning jobs launched in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "04f62317-18b3-4799-bceb-3ff63975e54f",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListHyperParameterTuningJobs",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b8d31312-969b-4e14-b991-73c399cb9550",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

ListImages

#
Service
sagemaker

Description

Lists the images in your account and their properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListImageVersions

#
Service
sagemaker

Description

Lists the versions of a specified image and their properties. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListInferenceComponents

#
Service
sagemaker

Description

Lists the inference components in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "dc1f672a-3e41-4722-97a5-a6472c107dcd",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListInferenceComponents",
  "awsRegion": "eu-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3a8449b0-62a8-4f37-8dd2-351d09509e7b",
  "userAgent": "config.amazonaws.com"
}

ListInferenceExperiments

#
Service
sagemaker

Description

Returns the list of all inference experiments. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e8b6c6cc-c5e8-4dfd-9537-45e50a3c8bf1",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListInferenceExperiments",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "281aab61-3b1a-40db-bdfe-787ad84c1e6e",
  "userAgent": "config.amazonaws.com"
}

ListInferenceRecommendationsJobs

#
Service
sagemaker

Description

Lists recommendation jobs that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2d17516f-880c-4ea8-a506-e7d21728dd8c",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListInferenceRecommendationsJobs",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "400c4628-cef2-44a5-bce3-80cdfeeb3960",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-west-1.amazonaws.com"
  }
}

ListInferenceRecommendationsJobSteps

#
Service
sagemaker

Description

Returns a list of the subtasks for an Inference Recommender job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListJobs

#
Service
sagemaker

Description

Lists jobs in a specified category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListJobSchemaVersions

#
Service
sagemaker

Description

Lists available configuration schema versions for a specified job category. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListLabelingJobs

#
Service
sagemaker

Description

Gets a list of labeling jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b3f2c7ed-783e-4bf7-a704-ed92f0e597f8",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListLabelingJobs",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "3eab8842-877e-4db7-ab6e-740ce19e4902",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListLabelingJobsForWorkteam

#
Service
sagemaker

Description

Gets a list of labeling jobs assigned to a specified work team. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListLineageGroups

#
Service
sagemaker

Description

A list of lineage groups shared with your Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0c3e3710-eab9-48fb-9f61-8ff548a2d78c",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListLineageGroups",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c30c7341-c015-4f88-b34c-747e1d77d24e",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListMlflowApps

#
Service
sagemaker

Description

Lists all MLflow Apps Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "88bf8fac-9137-495f-9123-797375303208",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListMlflowApps",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "f570f686-f167-4ba3-af55-b84705d921d1",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListMlflowTrackingServers

#
Service
sagemaker

Description

Lists all MLflow Tracking Servers. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c3943244-722d-4707-aac4-578ee4326d6f",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListMlflowTrackingServers",
  "awsRegion": "eu-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4b55cdde-cdbe-47e4-b3ed-781cc95c944b",
  "userAgent": "config.amazonaws.com"
}

ListModelBiasJobDefinitions

#
Service
sagemaker

Description

Lists model bias jobs definitions that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "75b96947-ad93-471f-a2aa-22fdba1c8a51",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListModelBiasJobDefinitions",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "2f459cd4-002c-4e67-8045-a4b812e94d3b",
  "userAgent": "config.amazonaws.com"
}

ListModelCardExportJobs

#
Service
sagemaker

Description

List the export jobs for the Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListModelCards

#
Service
sagemaker

Description

List existing model cards. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "03878d1d-14cc-4671-bda8-c8f8e817baee",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListModelCards",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4a8397d7-a255-4df4-ad65-64faa1525968",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListModelCardVersions

#
Service
sagemaker

Description

List existing versions of an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListModelExplainabilityJobDefinitions

#
Service
sagemaker

Description

Lists model explainability job definitions that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "284668d0-40d0-4144-aa8f-ce858b7e232c",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListModelExplainabilityJobDefinitions",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c02d35fe-e618-4007-bf34-197b21eb0030",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-2.amazonaws.com"
  }
}

ListModelMetadata

#
Service
sagemaker

Description

Lists the domain, framework, task, and model name of standard machine learning models found in common model zoos. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListModelPackageGroups

#
Service
sagemaker

Description

Gets a list of the model groups in your Amazon Web Services account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "dc082ae1-668e-45c1-ab70-0928687412bc",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListModelPackageGroups",
  "awsRegion": "ap-south-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "47b587d5-376f-4c7e-8141-b55e56999b5f",
  "userAgent": "config.amazonaws.com"
}

ListModelPackages

#
Service
sagemaker

Description

Lists the model packages that have been created. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8457bb7e-ec84-4b17-860f-14fea22ef522",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListModelPackages",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "df922bd0-76e7-42e1-b888-df0f5b6b3573",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-west-1.amazonaws.com"
  }
}

ListModelQualityJobDefinitions

#
Service
sagemaker

Description

Gets a list of model quality monitoring job definitions in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2dd41df0-ca44-4a9b-9866-30f7679dadb2",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListModelQualityJobDefinitions",
  "awsRegion": "eu-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "0fd7b34b-dc01-4fd9-92d4-9db25bb24456",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-central-1.amazonaws.com"
  }
}

ListModels

#
Service
sagemaker

Description

Lists models created with the CreateModel API. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListMonitoringAlertHistory

#
Service
sagemaker

Description

Gets a list of past alerts in a model monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListMonitoringAlerts

#
Service
sagemaker

Description

Gets the alerts for a single monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListMonitoringExecutions

#
Service
sagemaker

Description

Returns list of all monitoring job executions. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListMonitoringSchedules

#
Service
sagemaker

Description

Returns list of all monitoring schedules. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2bce08c6-8521-490b-817c-65b1996e2bae",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListMonitoringSchedules",
  "awsRegion": "ap-southeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f11b5062-b293-46c8-a671-262ba8029f4b",
  "userAgent": "config.amazonaws.com"
}

ListNotebookInstanceLifecycleConfigs

#
Service
sagemaker

Description

Lists notebook instance lifestyle configurations created with the CreateNotebookInstanceLifecycleConfig API. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c74d98a7-cc89-4854-80e3-23cf6cc8c123",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListNotebookInstanceLifecycleConfigs",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "05b74bec-b499-470b-ac4e-c54f598c9807",
  "userAgent": "config.amazonaws.com"
}

ListNotebookInstances

#
Service
sagemaker

Description

Returns a list of the SageMaker AI notebook instances in the requester's account in an Amazon Web Services Region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "14850577-25d4-4edc-a1f1-b0a866171428",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListNotebookInstances",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "8819c6dd-6e6f-4072-9420-b4428b71bcce",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-west-2.amazonaws.com"
  }
}

ListOptimizationJobs

#
Service
sagemaker

Description

Lists the optimization jobs in your account and their properties. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "dba875e9-f7cf-4dae-86ad-b75757e8c937",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListOptimizationJobs",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ea97ba8f-341b-4d5d-a507-2abb9904f420",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListPartnerApps

#
Service
sagemaker

Description

Lists all of the SageMaker Partner AI Apps in an account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "93c7898c-f0ae-4175-be06-cd59f5bfe047",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListPartnerApps",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "55546f51-decd-447d-a3cd-60c9e1b7866a",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListPipelineExecutions

#
Service
sagemaker

Description

Gets a list of the pipeline executions. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "cf75fe68-357f-4726-9ea2-7aeff31b2c99",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListPipelineExecutions",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7868f4b1-44c7-47e9-a92d-7c8e6276aba3",
  "userAgent": "aws-cli/2.35.0 md/awscrt#0.34.1 ua/2.1 os/linux#7.1.4-204.fc44.aarch64 md/arch#aarch64 lang/python#3.14.6 md/pyimpl#CPython exec-env/AmazonQ-For-CLI-Version-2.13.0-acp-client-kiro-tui m/Z,b,r,E,s cfg/retry-mode#standard md/installer#source md/distrib#fedora.44 sid/69848188a98e md/prompt#off md/command#sagemaker.list-pipeline-executions",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

ListPipelineExecutionSteps

#
Service
sagemaker

Description

Gets a list of PipeLineExecutionStep objects. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "23d643ee-c7f4-4cf8-8039-7aea3b1370bc",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListPipelineExecutionSteps",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ec880c51-8db1-44cd-8222-8df7efa9f4e2",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.176-223.369.amzn2023.aarch64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

ListPipelineParametersForExecution

#
Service
sagemaker

Description

Gets a list of parameters for a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3063a4be-bcf5-40f3-88b5-6ce2dd3faa0f",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListPipelineParametersForExecution",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "269ed7b7-aba0-4f46-a634-feebbf1df607",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:eu-west-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

ListPipelines

#
Service
sagemaker

Description

Gets a list of pipelines. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f3ce7acc-f77f-4aa1-a9cc-f6cc0d06d7ee",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListPipelines",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f8dbf96b-7aa3-4c77-be1b-e09270aa616e",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,C,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListPipelineVersions

#
Service
sagemaker

Description

Gets a list of all versions of the pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListProcessingJobs

#
Service
sagemaker

Description

Lists processing jobs that satisfy various filters. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1e4a6bf5-2012-4533-ac12-2c3142a95faa",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListProcessingJobs",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "df652d74-a6fc-45a0-b43b-f85e0714dd22",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-west-2.amazonaws.com"
  }
}

ListProjects

#
Service
sagemaker

Description

Gets a list of the projects in an Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListResourceCatalogs

#
Service
sagemaker

Description

Lists Amazon SageMaker Catalogs based on given filters and orders. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListSpaces

#
Service
sagemaker

Description

Lists spaces. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d602a6a1-dcb7-4495-8333-a7a6193a2b47",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListSpaces",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "894c12b3-ba72-4776-a939-d595433406ed",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-west-2.amazonaws.com"
  }
}

ListStageDevices

#
Service
sagemaker

Description

Lists devices allocated to the stage, containing detailed device information and deployment status. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListStudioLifecycleConfigs

#
Service
sagemaker

Description

Lists the Amazon SageMaker AI Studio Lifecycle Configurations in your Amazon Web Services Account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0ac59477-b9cc-45df-b8ed-7c907dd37c62",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListStudioLifecycleConfigs",
  "awsRegion": "eu-north-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "383c2316-5d31-43d2-b6df-07704460a134",
  "userAgent": "config.amazonaws.com"
}

ListSubscribedWorkteams

#
Service
sagemaker

Description

Gets a list of the work teams that you are subscribed to in the Amazon Web Services Marketplace. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListTags

#
Service
sagemaker

Description

Returns the tags for the specified SageMaker resource. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2ca74f35-836d-4476-bd57-32e5b148c0c7",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListTags",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "085b0fd9-4b01-435e-a6c8-1b1dd18b56ba",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListTrainingJobs

#
Service
sagemaker

Description

Lists training jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "01435000-9c0a-4c01-bce7-ba35aba2c44b",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListTrainingJobs",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f334bff9-8ef6-4b38-8f7d-08e457a6a796",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-2.amazonaws.com"
  }
}

ListTrainingJobsForHyperParameterTuningJob

#
Service
sagemaker

Description

Gets a list of TrainingJobSummary objects that describe the training jobs that a hyperparameter tuning job launched. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListTrainingPlans

#
Service
sagemaker

Description

Retrieves a list of training plans for the current account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "97e68983-5788-4ccc-9801-81e79deb25f1",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListTrainingPlans",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d43bf777-5979-4df8-85ac-4151dcb46765",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

ListTransformJobs

#
Service
sagemaker

Description

Lists transform jobs. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9a951559-4630-424f-afcc-28b984e63f98",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListTransformJobs",
  "awsRegion": "ap-southeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "39a68ed4-36d4-4045-a2b7-94a6f87789fe",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-1.amazonaws.com"
  }
}

ListTrialComponents

#
Service
sagemaker

Description

Lists the trial components in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7ea90dee-7aa7-4e3c-b9c7-b86e1f7cb653",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListTrialComponents",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "c6b64985-b87a-43e5-a801-230af1762b73",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.eu-west-1.amazonaws.com"
  }
}

ListTrials

#
Service
sagemaker

Description

Lists the trials in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7454b9d7-b9ae-4db5-bdc8-8b1ec88de13b",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListTrials",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "60409ce2-515d-4521-96bc-a464e79b3458",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

ListUltraServersByReservedCapacity

#
Service
sagemaker

Description

Lists all UltraServers that are part of a specified reserved capacity. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListUserProfiles

#
Service
sagemaker

Description

Lists user profiles. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "540ede2d-c524-43c6-9a18-c6f7d35aec27",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListUserProfiles",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "5bc25478-e940-497e-ac96-04dc35e02c33",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.235.0 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

ListWorkforces

#
Service
sagemaker

Description

Use this operation to list all private and vendor workforces in an Amazon Web Services Region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f36459d1-49f6-4c4d-ba3d-678ab2da20e7",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListWorkforces",
  "awsRegion": "ap-northeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d93b34ee-31fb-462b-bff3-6daeb0df2d56",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListWorkteams

#
Service
sagemaker

Description

Gets a list of private work teams that you have defined in a region. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "eb1e5b5f-2473-472b-8056-03bdaf5f120f",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListWorkteams",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "159be58d-9fa9-43f1-bdd3-f9a5ae11a9c0",
  "userAgent": "config.amazonaws.com"
}

PutModelPackageGroupPolicy

#
Service
sagemaker

Description

Adds a resouce policy to control access to a model group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

QueryLineage

#
Service
sagemaker

Description

Use this action to inspect your lineage and discover relationships between entities. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

RegisterDevices

#
Service
sagemaker

Description

Register devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

RenderUiTemplate

#
Service
sagemaker

Description

Renders the UI template so that you can preview the worker's experience. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

RetryPipelineExecution

#
Service
sagemaker

Description

Retry the execution of the pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

Search

#
Service
sagemaker

Description

Finds SageMaker resources that match a search query. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f4b703d9-bbc2-4119-bafd-d1a6bf245e72",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "Search",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1ef78b3a-fb50-40aa-8414-a6f964025d55",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

SearchTrainingPlanOfferings

#
Service
sagemaker

Description

Searches for available training plan offerings based on specified criteria. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

SendPipelineExecutionStepFailure

#
Service
sagemaker

Description

Notifies the pipeline that the execution of a callback step failed, along with a message describing why. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

SendPipelineExecutionStepSuccess

#
Service
sagemaker

Description

Notifies the pipeline that the execution of a callback step succeeded and provides a list of the step's output parameters. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartClusterHealthCheck

#
Service
sagemaker

Description

Start deep health checks for a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartEdgeDeploymentStage

#
Service
sagemaker

Description

Starts a stage in an edge deployment plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartInferenceExperiment

#
Service
sagemaker

Description

Starts an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartMlflowTrackingServer

#
Service
sagemaker

Description

Programmatically start an MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartMonitoringSchedule

#
Service
sagemaker

Description

Starts a previously stopped monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartNotebookInstance

#
Service
sagemaker

Description

Launches an ML compute instance with the latest version of the libraries and attaches your ML storage volume. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartPipelineExecution

#
Service
sagemaker

Description

Starts a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "cf0db6b1-7717-47c0-ba00-5cf867b08b3b",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "StartPipelineExecution",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "ec16bc9a-c5d5-4c87-96c6-14b421dcdd4c",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.175-219.359.amzn2023.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

StartSession

#
Service
sagemaker

Description

Initiates a remote connection session between a local integrated development environments (IDEs) and a remote SageMaker space. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopAIBenchmarkJob

#
Service
sagemaker

Description

Stops a running AI benchmark job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopAIRecommendationJob

#
Service
sagemaker

Description

Stops a running AI recommendation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopAutoMLJob

#
Service
sagemaker

Description

A method for forcing a running job to shut down. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopCompilationJob

#
Service
sagemaker

Description

Stops a model compilation job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopEdgeDeploymentStage

#
Service
sagemaker

Description

Stops a stage in an edge deployment plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopEdgePackagingJob

#
Service
sagemaker

Description

Request to stop an edge packaging job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopHyperParameterTuningJob

#
Service
sagemaker

Description

Stops a running hyperparameter tuning job and all running training jobs that the tuning job launched. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopInferenceExperiment

#
Service
sagemaker

Description

Stops an inference experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopInferenceRecommendationsJob

#
Service
sagemaker

Description

Stops an Inference Recommender job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopJob

#
Service
sagemaker

Description

Stops a running job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopLabelingJob

#
Service
sagemaker

Description

Stops a running labeling job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopMlflowTrackingServer

#
Service
sagemaker

Description

Programmatically stop an MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopMonitoringSchedule

#
Service
sagemaker

Description

Stops a previously started monitoring schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopNotebookInstance

#
Service
sagemaker

Description

Terminates the ML compute instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopOptimizationJob

#
Service
sagemaker

Description

Ends a running inference optimization job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopPipelineExecution

#
Service
sagemaker

Description

Stops a pipeline execution. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "df645cab-99e0-4916-84e0-63f5b8a49e15",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "StopPipelineExecution",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "4807335f-2455-424a-904c-bf808990c616",
  "userAgent": "aws-sdk-java/2.48.4 md/io#sync md/http#Apache5 ua/2.1 api/SageMaker#2.48.x os/Linux#6.1.176-223.369.amzn2023.aarch64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+10-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SageMaker::Pipeline",
      "ARN": "arn:aws:sagemaker:us-east-1:123456789012:pipeline/EXAMPLE"
    }
  ]
}

StopProcessingJob

#
Service
sagemaker

Description

Stops a processing job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StopTrainingJob

#
Service
sagemaker

Description

Stops a training job. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "11f6f054-c3ce-4741-986c-b71c56b287ec",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "StopTrainingJob",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "dab2a331-5486-47f5-ab48-183b7dd1cab0",
  "userAgent": "pipelines.sagemaker.amazonaws.com"
}

StopTransformJob

#
Service
sagemaker

Description

Stops a batch transform job. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateAction

#
Service
sagemaker

Description

Updates an action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateAppImageConfig

#
Service
sagemaker

Description

Updates the properties of an AppImageConfig. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateArtifact

#
Service
sagemaker

Description

Updates an artifact. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateCluster

#
Service
sagemaker

Description

Updates a SageMaker HyperPod cluster. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateClusterSchedulerConfig

#
Service
sagemaker

Description

Update the cluster policy configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateClusterSoftware

#
Service
sagemaker

Description

Updates the platform software of a SageMaker HyperPod cluster for security patching. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateCodeRepository

#
Service
sagemaker

Description

Updates the specified Git repository with the specified values. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateComputeQuota

#
Service
sagemaker

Description

Update the compute allocation definition. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateContext

#
Service
sagemaker

Description

Updates a context. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateDeviceFleet

#
Service
sagemaker

Description

Updates a fleet of devices. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateDevices

#
Service
sagemaker

Description

Updates one or more devices in a fleet. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateDomain

#
Service
sagemaker

Description

Updates the default settings for new user profiles in the domain. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "faa76eab-9e6c-4bfb-8117-fef77897a512",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "UpdateDomain",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "8f643bbb-0219-46b9-ab73-64a5c2a777da",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/sagemaker#1.253.1 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.us-east-1.amazonaws.com"
  }
}

UpdateEndpoint

#
Service
sagemaker

Description

Deploys the EndpointConfig specified in the request to a new fleet of instances. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateEndpointWeightsAndCapacities

#
Service
sagemaker

Description

Updates variant weight of one or more variants associated with an existing endpoint, or capacity of one variant associated with an existing endpoint. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateExperiment

#
Service
sagemaker

Description

Adds, updates, or removes the description of an experiment. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateFeatureGroup

#
Service
sagemaker

Description

Updates the feature group by either adding features or updating the online store configuration. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateFeatureMetadata

#
Service
sagemaker

Description

Updates the description and parameters of the feature group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateHub

#
Service
sagemaker

Description

Update a hub. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateHubContent

#
Service
sagemaker

Description

Updates SageMaker hub content (either a Model or Notebook resource). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateHubContentReference

#
Service
sagemaker

Description

Updates the contents of a SageMaker hub for a ModelReference resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateImage

#
Service
sagemaker

Description

Updates the properties of a SageMaker AI image. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateImageVersion

#
Service
sagemaker

Description

Updates the properties of a SageMaker AI image version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateInferenceComponent

#
Service
sagemaker

Description

Updates an inference component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateInferenceComponentRuntimeConfig

#
Service
sagemaker

Description

Runtime settings for a model that is deployed with an inference component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateInferenceExperiment

#
Service
sagemaker

Description

Updates an inference experiment that you created. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateMlflowApp

#
Service
sagemaker

Description

Updates an MLflow App. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateMlflowTrackingServer

#
Service
sagemaker

Description

Updates properties of an existing MLflow Tracking Server. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateModelCard

#
Service
sagemaker

Description

Update an Amazon SageMaker Model Card. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateModelPackage

#
Service
sagemaker

Description

Updates a versioned model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateMonitoringAlert

#
Service
sagemaker

Description

Update the parameters of a model monitor alert. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateMonitoringSchedule

#
Service
sagemaker

Description

Updates a previously created schedule. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateNotebookInstance

#
Service
sagemaker

Description

Updates a notebook instance. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateNotebookInstanceLifecycleConfig

#
Service
sagemaker

Description

Updates a notebook instance lifecycle configuration created with the CreateNotebookInstanceLifecycleConfig API. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content source high: Identifies an Amazon SageMaker notebook lifecycle configuration whose OnStart or OnCreate script, after base64 decoding, contains patterns associated with malicious activity such as reverse shells, EC2 instance metadata (IMDS) credential access, or download-and-execute commands. A lifecycle configuration runs as root on the notebook instance, so a script with these patterns is a strong indicator of an attempt to backdoor the notebook, steal the execution role's credentials, or establish persistent code execution. This rule decodes the script in the request and matches high-signal indicators; it is a higher-fidelity companion to the rule that alerts on any lifecycle configuration change.T1059, T1059.004, T1546↳ also matches CreateNotebookInstanceLifecycleConfig

UpdatePartnerApp

#
Service
sagemaker

Description

Updates all of the SageMaker Partner AI Apps in an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdatePipeline

#
Service
sagemaker

Description

Updates a pipeline. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdatePipelineExecution

#
Service
sagemaker

Description

Updates a pipeline execution. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdatePipelineVersion

#
Service
sagemaker

Description

Updates a pipeline version. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateProject

#
Service
sagemaker

Description

Updates a machine learning (ML) project that is created from a template that sets up an ML pipeline from training to deploying an approved model. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateSpace

#
Service
sagemaker

Description

Updates the settings of a space. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2bc0dd4e-8521-42a2-947a-1730bb643f5d",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "UpdateSpace",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "bd93c992-26b0-46d9-b7f5-61f3ddd4b70c",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ap-southeast-2.amazonaws.com"
  }
}

UpdateTrainingJob

#
Service
sagemaker

Description

Update a model training job to request a new Debugger profiling configuration or to change warm pool retention length. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateTrial

#
Service
sagemaker

Description

Updates the display name of a trial. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateTrialComponent

#
Service
sagemaker

Description

Updates one or more properties of a trial component. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateUserProfile

#
Service
sagemaker

Description

Updates a user profile. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateWorkforce

#
Service
sagemaker

Description

Use this operation to update your workforce. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateWorkteam

#
Service
sagemaker

Description

Updates an existing work team with new member definitions or description. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListSharedModelEvents

#
Service
sagemaker

Description

ListSharedModelEvents recorded by CloudTrail for Amazon SageMaker Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "880b62b0-f04d-488e-9dbf-740ac2e049ae",
  "eventSource": "sagemaker.amazonaws.com",
  "eventName": "ListSharedModelEvents",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b6e341df-5760-419c-9a71-b0c0b5abfb92",
  "userAgent": "Boto3/1.42.89 md/Botocore#1.42.89 md/internal ua/2.1 os/linux#6.12.94-123.180.amzn2023.x86_64 md/arch#x86_64 lang/python#3.10.19 md/pyimpl#CPython m/N,Z,b,D cfg/retry-mode#legacy Botocore/1.42.89",
  "errorCode": "UnknownOperationException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "api.sagemaker.ca-central-1.amazonaws.com"
  }
}