AWS Systems Manager Incident Manager

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Systems Manager Incident Manager rules that match the service but not a specific eventName.NN
BatchGetIncidentFindingsRetrieves details about all specified findings for an incident, including descriptive details about each finding. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateReplicationSetA replication set replicates and encrypts your data to the provided Regions with the provided KMS key. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateResponsePlanCreates a response plan that automates the initial response to incidents. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateTimelineEventCreates a custom timeline event on the incident details page of an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteIncidentRecordDelete an incident record from Incident Manager. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteReplicationSetDeletes all Regions in your replication set. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResourcePolicyDeletes the resource policy that Resource Access Manager uses to share your Incident Manager resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteResponsePlanDeletes the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteTimelineEventDeletes a timeline event from an incident. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetIncidentRecordReturns the details for the specified incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetReplicationSetRetrieve your Incident Manager replication set. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetResourcePoliciesRetrieves the resource policies attached to the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetResponsePlanRetrieves the details of the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetTimelineEventRetrieves a timeline event based on its ID and incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListIncidentFindingsRetrieves a list of the IDs of findings, plus their last modified times, that have been identified for a specified incident. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListIncidentRecordsLists all incident records in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListRelatedItemsList all related items for an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListReplicationSetsLists details about the replication set configured in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListResponsePlansLists all response plans in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceLists the tags that are attached to the specified response plan or incident. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTimelineEventsLists timeline events for the specified incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutResourcePolicyAdds a resource policy to the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
StartIncidentUsed to start an incident from CloudWatch alarms, EventBridge events, or manually. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceAdds a tag to a response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves a tag from a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateDeletionProtectionUpdate deletion protection to either allow or deny deletion of the final Region in a replication set. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateIncidentRecordUpdate the details of an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateRelatedItemsAdd or remove related items from the related items tab of an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateReplicationSetAdd or delete Regions from your replication set. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateResponsePlanUpdates the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateTimelineEventUpdates a timeline event. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: AWS Systems Manager Incident Manager (catch-all)

#
Service
ssm-incidents

Description

Catch-all entry for AWS Systems Manager Incident Manager rules that match the service but not a specific eventName.

BatchGetIncidentFindings

#
Service
ssm-incidents

Description

Retrieves details about all specified findings for an incident, including descriptive details about each finding. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateReplicationSet

#
Service
ssm-incidents

Description

A replication set replicates and encrypts your data to the provided Regions with the provided KMS key. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateResponsePlan

#
Service
ssm-incidents

Description

Creates a response plan that automates the initial response to incidents. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateTimelineEvent

#
Service
ssm-incidents

Description

Creates a custom timeline event on the incident details page of an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteIncidentRecord

#
Service
ssm-incidents

Description

Delete an incident record from Incident Manager. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteReplicationSet

#
Service
ssm-incidents

Description

Deletes all Regions in your replication set. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResourcePolicy

#
Service
ssm-incidents

Description

Deletes the resource policy that Resource Access Manager uses to share your Incident Manager resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteResponsePlan

#
Service
ssm-incidents

Description

Deletes the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteTimelineEvent

#
Service
ssm-incidents

Description

Deletes a timeline event from an incident. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetIncidentRecord

#
Service
ssm-incidents

Description

Returns the details for the specified incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetReplicationSet

#
Service
ssm-incidents

Description

Retrieve your Incident Manager replication set. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "38f87a81-b2d5-4a09-be0b-a02882a15917",
  "eventSource": "ssm-incidents.amazonaws.com",
  "eventName": "GetReplicationSet",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "09a9cb70-fdb7-49f9-bac4-8d8f222d4905",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/ssmincidents#1.40.2 m/E,i"
}

GetResourcePolicies

#
Service
ssm-incidents

Description

Retrieves the resource policies attached to the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetResponsePlan

#
Service
ssm-incidents

Description

Retrieves the details of the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetTimelineEvent

#
Service
ssm-incidents

Description

Retrieves a timeline event based on its ID and incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListIncidentFindings

#
Service
ssm-incidents

Description

Retrieves a list of the IDs of findings, plus their last modified times, that have been identified for a specified incident. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListIncidentRecords

#
Service
ssm-incidents

Description

Lists all incident records in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "21ec6cb6-5078-42f8-87a7-e5c5965534e7",
  "eventSource": "ssm-incidents.amazonaws.com",
  "eventName": "ListIncidentRecords",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bb79a325-44fe-43ca-b265-0144a00efb61",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:153.0) Gecko/20100101 Firefox/153.0"
}

ListRelatedItems

#
Service
ssm-incidents

Description

List all related items for an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListReplicationSets

#
Service
ssm-incidents

Description

Lists details about the replication set configured in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "73e32f44-90af-4d3a-9737-28e0aa66517a",
  "eventSource": "ssm-incidents.amazonaws.com",
  "eventName": "ListReplicationSets",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "92b1d2c2-0262-4a52-8628-a982b227eadc",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/ssmincidents#1.40.2 m/E,i"
}

ListResponsePlans

#
Service
ssm-incidents

Description

Lists all response plans in your account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c17775c4-cf01-4bad-a108-7e13d7f34371",
  "eventSource": "ssm-incidents.amazonaws.com",
  "eventName": "ListResponsePlans",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "98a08d27-bb09-4f1e-a428-7d48bbbe18fc",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListTagsForResource

#
Service
ssm-incidents

Description

Lists the tags that are attached to the specified response plan or incident. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTimelineEvents

#
Service
ssm-incidents

Description

Lists timeline events for the specified incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutResourcePolicy

#
Service
ssm-incidents

Description

Adds a resource policy to the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

StartIncident

#
Service
ssm-incidents

Description

Used to start an incident from CloudWatch alarms, EventBridge events, or manually. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
ssm-incidents

Description

Adds a tag to a response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
ssm-incidents

Description

Removes a tag from a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateDeletionProtection

#
Service
ssm-incidents

Description

Update deletion protection to either allow or deny deletion of the final Region in a replication set. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateIncidentRecord

#
Service
ssm-incidents

Description

Update the details of an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateRelatedItems

#
Service
ssm-incidents

Description

Add or remove related items from the related items tab of an incident record. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateReplicationSet

#
Service
ssm-incidents

Description

Add or delete Regions from your replication set. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateResponsePlan

#
Service
ssm-incidents

Description

Updates the specified response plan. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateTimelineEvent

#
Service
ssm-incidents

Description

Updates a timeline event. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.