AdvancedEventSelector
Advanced event selectors let you create fine-grained selectors for Amazon CloudTrail management, data, and network activity events. They help you control costs by logging only those events that are important to you. For more information about configuring advanced event selectors, see the Logging data events, Logging network activity events, and Logging management events topics in the Amazon CloudTrail User Guide.
You cannot apply both event selectors and advanced event selectors to a trail.
Supported CloudTrail event record fields for management events
-
eventCategory
(required) -
eventSource
-
readOnly
The following additional fields are available for event data stores:
-
eventName
-
eventType
-
sessionCredentialFromConsole
-
userIdentity.arn
Supported CloudTrail event record fields for data events
-
eventCategory
(required) -
resources.type
(required) -
readOnly
-
eventName
-
resources.ARN
The following additional fields are available for event data stores:
-
eventSource
-
eventType
-
sessionCredentialFromConsole
-
userIdentity.arn
Supported CloudTrail event record fields for network activity events
Note
Network activity events is in preview release for CloudTrail and is subject to change.
-
eventCategory
(required) -
eventSource
(required) -
eventName
-
errorCode
- The only valid value forerrorCode
isVpceAccessDenied
. -
vpcEndpointId
Note
For event data stores for CloudTrail Insights events, Amazon Config configuration items, Audit Manager evidence, or events outside of Amazon, the only supported field is
eventCategory
.
Contents
- FieldSelectors
-
Contains all selector statements in an advanced event selector.
Type: Array of AdvancedFieldSelector objects
Array Members: Minimum number of 1 item.
Required: Yes
- Name
-
An optional, descriptive name for an advanced event selector, such as "Log data events for only two S3 buckets".
Type: String
Length Constraints: Minimum length of 0. Maximum length of 1000.
Pattern:
.*
Required: No
See Also
For more information about using this API in one of the language-specific Amazon SDKs, see the following: