Download your CloudTrail Lake saved query results - Amazon CloudTrail
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Download your CloudTrail Lake saved query results

When you save query results, CloudTrail delivers two types of files to your Amazon S3 bucket.

  • A sign file in JSON format that you can use to validate the query result files. The sign file is named result_sign.json. For more information about the sign file, see CloudTrail sign file structure.

  • One or more query result files in CSV format, which contain the results from the query. The number of query result files delivered is dependent upon the total size of the query results. The maximum file size for a query result file is 1 TB. Each query result file is named result_number.csv.gz. For example, if the total size of the query results was 2 TB, you would have two query result files, result_1.csv.gz and result_2.csv.gz.

CloudTrail query result and sign files are Amazon S3 objects. You can use the S3 console, the Amazon Command Line Interface (CLI), or the S3 API to retrieve query result and sign files.

The following procedure describes how to download the query result and sign files with the Amazon S3 console.

To download your query result or sign file with the Amazon S3 console
  1. Open the Amazon S3 console.

  2. Choose the bucket and choose the file that you want to download.

                    CloudTrail query result file
  3. Choose Download and follow any prompts to save the file.


    Some browsers, such as Chrome, automatically extract the query result file for you. If your browser does this for you, skip to step 5.

  4. Use a product such as 7-Zip to extract the query result file.

  5. Open the query result or sign file.