Understanding CloudTrail events
An event in CloudTrail is the record of an activity in an Amazon account. This activity can be an action taken by an IAM identity, or service that is monitorable by CloudTrail. CloudTrail events provide a history of both API and non-API account activity made through the Amazon Web Services Management Console, Amazon SDKs, command line tools, and other Amazon Web Services services.
CloudTrail log files aren't an ordered stack trace of the public API calls, so events don't appear in any specific order.
There are four types of CloudTrail events:
By default, trails and event data stores log management events, but not data events, network activity events, or Insights events.
All event types use a CloudTrail JSON log format. The log contains information about requests for
resources in your account, such as who made the request, the services used, the actions
performed, and parameters for the action. The event data is enclosed in a Records
array.
For information about CloudTrail event record fields for management, data, and network activity events, see CloudTrail record contents for management, data, and network activity events.
For information about CloudTrail event record fields for Insights events for trails, see CloudTrail record contents for Insights events for trails.
For information about CloudTrail event record fields for Insights events for event data stores, see CloudTrail record contents for Insights events for event data stores.
Management events
Management events provide information about management operations that are performed on resources in your Amazon account. These are also known as control plane operations.
Example management events include:
-
Configuring security (for example, Amazon Identity and Access Management
AttachRolePolicyAPI operations). -
Registering devices (for example, Amazon EC2
CreateDefaultVpcAPI operations). -
Configuring rules for routing data (for example, Amazon EC2
CreateSubnetAPI operations). -
Setting up logging (for example, Amazon CloudTrail
CreateTrailAPI operations).
Management events can also include non-API events that occur in your account. For
example, when a user signs in to your account, CloudTrail logs the
ConsoleLogin event. For more information, see Non-API events captured by CloudTrail.
By default, CloudTrail trails and CloudTrail Lake event data stores log management events. For more information about logging management events, see Logging management events.
The following example shows a single log record of a management event. In this event, an IAM user
named Mary_Major ran the aws cloudtrail start-logging command to call the CloudTrail StartLogging action
to start the logging process on a trail named myTrail.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "EXAMPLE6E4XEGITWATV6R", "arn": "arn:aws:iam::123456789012:user/Mary_Major", "accountId": "123456789012", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "userName": "Mary_Major", "sessionContext": { "attributes": { "creationDate": "2023-07-19T21:11:57Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-07-19T21:33:41Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "StartLogging", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "userAgent": "aws-cli/2.13.5 Python/3.11.4 Linux/4.14.255-314-253.539.amzn2.x86_64 exec-env/CloudShell exe/x86_64.amzn.2 prompt/off command/cloudtrail.start-logging", "requestParameters": { "name": "myTrail" }, "responseElements": null, "requestID": "9d478fc1-4f10-490f-a26b-EXAMPLE0e932", "eventID": "eae87c48-d421-4626-94f5-EXAMPLEac994", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "123456789012", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }, "sessionCredentialFromConsole": "true" }
In this next example, an IAM user user named Paulo_Santos
ran the aws cloudtrail start-event-data-store-ingestion command to call the StartEventDataStoreIngestion action
to start ingestion on an event data store.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "EXAMPLEPHCNW5EQV7NA54", "arn": "arn:aws:iam::123456789012:user/Paulo_Santos", "accountId": "123456789012", "accessKeyId": "(AKIAIOSFODNN7EXAMPLE", "userName": "Paulo_Santos", "sessionContext": { "attributes": { "creationDate": "2023-07-21T21:55:30Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-07-21T21:57:28Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "StartEventDataStoreIngestion", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "userAgent": "aws-cli/2.13.1 Python/3.11.4 Linux/4.14.255-314-253.539.amzn2.x86_64 exec-env/CloudShell exe/x86_64.amzn.2 prompt/off command/cloudtrail.start-event-data-store-ingestion", "requestParameters": { "eventDataStore": "arn:aws:cloudtrail:us-east-1:123456789012:eventdatastore/2a8f2138-0caa-46c8-a194-EXAMPLE87d41" }, "responseElements": null, "requestID": "f62a3494-ba4e-49ee-8e27-EXAMPLE4253f", "eventID": "d97ca7e2-04fe-45b4-882d-EXAMPLEa9b2c", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "123456789012", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }, "sessionCredentialFromConsole": "true" }
Data events
Data events provide information about the resource operations performed on or in a resource. These are also known as data plane operations. Data events are often high-volume activities.
Example data events include:
-
Amazon S3 object-level API activity (for example,
GetObject,DeleteObject, andPutObjectAPI operations) on objects in S3 buckets. -
Amazon Lambda function execution activity (the
InvokeAPI). -
CloudTrail
PutAuditEventsactivity on a CloudTrail Lake channel that is used to log events from outside Amazon. -
Amazon SNS
PublishandPublishBatchAPI operations on topics.
The following table shows the resource types available for trails. The Resource type (console) column shows the appropriate selection in the console.
The resources.type value column shows the
resources.type value that you would specify to include data
events of that type in your trail using the Amazon CLI or CloudTrail APIs.
For trails, you can use basic or advanced event selectors to log data events for Amazon S3 objects in general purpose buckets, Lambda functions, and DynamoDB tables (shown in the first three rows of the table). You can use only advanced event selectors to log the resource types shown in the remaining rows.
Data events supported by Amazon CloudTrail
| Amazon Web Services service | Description | Resource type (console) | resources.type value |
|---|---|---|---|
Amazon AppConfig |
Amazon AppConfig API activity for configuration operations such as calls to StartConfigurationSession and GetLatestConfiguration. For more information, see Amazon AppConfig. |
Amazon AppConfig |
|
Amazon AppSync |
Amazon AppSync API activity on AppSync GraphQL APIs. For more information, see Amazon AppSync. |
AppSync GraphQL |
|
Amazon Bedrock |
Amazon Bedrock APIKey CredentialProvider API activity. |
Bedrock-AgentCore APIKey CredentialProvider |
|
Amazon Bedrock |
Amazon Bedrock Browser API activity. |
Bedrock-AgentCore Browser |
|
Amazon Bedrock |
Amazon Bedrock Browser-Custom API activity. |
Bedrock-AgentCore Browser-Custom |
|
Bedrock-AgentCore Browser Profile |
API activity on |
Bedrock-AgentCore Browser Profile |
|
Amazon Bedrock |
Amazon Bedrock Code-Interpreter API activity. |
Bedrock-AgentCore Code-Interpreter |
|
Amazon Bedrock |
Amazon Bedrock Code-Interpreter-Custom API activity. |
Bedrock-AgentCore Code-Interpreter-Custom |
|
Amazon Bedrock |
Amazon Bedrock Gateway API activity. |
Bedrock-AgentCore Gateway |
|
Amazon Bedrock |
Amazon Bedrock Oauth2 CredentialProvider API activity. |
Bedrock-AgentCore Oauth2 CredentialProvider |
|
Amazon Bedrock |
Amazon Bedrock Runtime API activity. |
Bedrock-AgentCore Runtime |
|
Amazon Bedrock |
Amazon Bedrock Runtime-Endpoint API activity. |
Bedrock-AgentCore Runtime-Endpoint |
|
Amazon Bedrock |
Amazon Bedrock Token Vault API activity. |
Bedrock-AgentCore Token Vault |
|
Amazon Bedrock |
Amazon Bedrock Workload Identity API activity. |
Bedrock-AgentCore Workload Identity |
|
Amazon Bedrock |
Amazon Bedrock Workload Identity Directory API activity. |
Bedrock-AgentCore Workload Identity Directory |
|
Amazon Keyspaces (for Apache Cassandra) |
Amazon Keyspaces (for Apache Cassandra) API activity on Cassandra CDC streams. |
Cassandra CDC streams |
|
Amazon Keyspaces (for Apache Cassandra) |
Amazon Keyspaces API activity on a table. For more information, see Amazon Keyspaces (for Apache Cassandra). |
Cassandra table |
|
Amazon CloudWatch |
Amazon CloudWatch API activity on metrics. For more information, see Amazon CloudWatch. |
CloudWatch metric |
|
Amazon Cognito |
Amazon Cognito API activity on Amazon Cognito identity pools. For more information, see Amazon Cognito. |
Cognito Identity Pools |
|
Amazon DynamoDB |
Amazon DynamoDB API activity on streams. For more information, see Amazon DynamoDB. |
DynamoDB Streams |
|
Amazon DynamoDB |
Amazon DynamoDB item-level API activity on tables (for example, PutItem, DeleteItem, and UpdateItem API operations). For tables with streams enabled, the resources field in the data event contains both Amazon::DynamoDB::Stream and Amazon::DynamoDB::Table. If you specify Amazon::DynamoDB::Table for the resources.type, it will log both DynamoDB table and DynamoDB streams events by default. To exclude streams events, add a filter on the eventName field. For more information, see Amazon DynamoDB. |
DynamoDB |
|
Amazon Elastic Block Store |
Amazon Elastic Block Store (EBS) direct APIs, such as PutSnapshotBlock, GetSnapshotBlock, and ListChangedBlocks on Amazon EBS snapshots. For more information, see Amazon Elastic Block Store. |
EBS direct APIs |
|
Amazon Elastic Container Service |
Amazon Elastic Container Service API activity on a container instance. |
ECS container instance |
|
Amazon Elastic Kubernetes Service |
Amazon Elastic Kubernetes Service API activity on dashboards. |
EKS dashboard |
|
EventBridge endpoint |
API activity on |
EventBridge endpoint |
|
EventBridge event bus |
API activity on |
EventBridge event bus |
|
EventBridge partner event source |
API activity on |
EventBridge partner event source |
|
EventBridge rule |
API activity on |
EventBridge rule |
|
Amazon FSx |
Amazon FSx API activity on volumes. |
FSx Volume |
|
Amazon IoT Greengrass Version 2 |
Greengrass API activity from a Greengrass core device on a component version. Greengrass doesn't log access denied events. For more information, see Amazon IoT Greengrass Version 2. |
IoT Greengrass component version |
|
Amazon IoT Greengrass Version 2 |
Greengrass API activity from a Greengrass core device on a deployment. Greengrass doesn't log access denied events. For more information, see Amazon IoT Greengrass Version 2. |
IoT Greengrass deployment |
|
Amazon GuardDuty |
GuardDuty API activity on malware scans. |
GuardDuty malware scan |
|
Amazon IoT |
Amazon IoT API activity on certificates. For more information, see Amazon IoT. |
IoT certificate |
|
Amazon IoT |
Amazon IoT API activity on things. For more information, see Amazon IoT. |
IoT thing |
|
Amazon IoT tunnel |
API activity on |
Amazon IoT tunnel |
|
Amazon IoT SiteWise |
IoT SiteWise API activity on assets. For more information, see Amazon IoT SiteWise. |
IoT SiteWise asset |
|
Amazon IoT SiteWise |
IoT SiteWise API activity on time series. For more information, see Amazon IoT SiteWise. |
IoT SiteWise time series |
|
Amazon IoT TwinMaker |
IoT TwinMaker API activity on an entity. For more information, see Amazon IoT TwinMaker. |
IoT TwinMaker entity |
|
Amazon IoT TwinMaker |
IoT TwinMaker API activity on a workspace. For more information, see Amazon IoT TwinMaker. |
IoT TwinMaker workspace |
|
Amazon Kinesis Data Streams |
Kinesis Data Streams API activity on streams. For more information, see Amazon Kinesis Data Streams. |
Kinesis stream |
|
Amazon Kinesis Data Streams |
Kinesis Data Streams API activity on stream consumers. For more information, see Amazon Kinesis Data Streams. |
Kinesis stream consumer |
|
Amazon Data Firehose |
Amazon Data Firehose delivery stream API activity. |
Amazon Data Firehose |
|
Amazon Lambda |
Amazon Lambda function execution activity (the Invoke API). |
Lambda |
|
Amazon Managed Workflows for Apache Airflow |
Amazon MWAA API activity on environments. |
Managed Apache Airflow |
|
Amazon Redshift |
Redshift API activity on clusters. |
Redshift Cluster |
|
Amazon S3 |
Amazon S3 API activity on access points. For more information, see Amazon S3. |
S3 Access Point |
|
Amazon S3 |
Amazon S3 object-level API activity (for example, GetObject, DeleteObject, and PutObject API operations) on objects in general purpose buckets. For more information, see Amazon S3. |
S3 |
|
S3 Express Access Point |
API activity on |
S3 Express Access Point |
|
Amazon S3 |
Amazon S3 object-level API activity (for example, GetObject, DeleteObject, and PutObject API operations) on objects in directory buckets. For more information, see Amazon S3. |
S3 Express |
|
Amazon S3 |
Amazon S3 Object Lambda access points API activity, such as calls to CompleteMultipartUpload and GetObject. For more information, see Amazon S3. |
S3 Object Lambda |
|
Amazon S3 Tables |
Amazon S3 API activity on tables. For more information, see Amazon S3 Tables. |
S3 table |
|
Amazon S3 Tables |
Amazon S3 API activity on table buckets. For more information, see Amazon S3 Tables. |
S3 table bucket |
|
Amazon S3 Vectors |
Amazon S3 API activity on vector indexes. For more information, see Amazon S3 Vectors. |
S3 vector index |
|
Amazon S3 Vectors |
Amazon S3 API activity on vector buckets. For more information, see Amazon S3 Vectors. |
S3 vector bucket |
|
Amazon SageMaker AI |
Amazon SageMaker AI InvokeEndpointWithResponseStream activity on endpoints. For more information, see Amazon SageMaker AI. |
SageMaker endpoint |
|
Amazon SageMaker AI |
Amazon SageMaker AI API activity on feature stores. |
SageMaker Feature Store |
|
Amazon Cloud Map |
Amazon Cloud Map API activity on a namespace. For more information, see Amazon Cloud Map. |
Amazon Cloud Map namespace |
|
Amazon Cloud Map |
Amazon Cloud Map API activity on a service. For more information, see Amazon Cloud Map. |
Amazon Cloud Map service |
|
Amazon SNS |
Amazon SNS Publish API operations on platform endpoints. For more information, see Amazon SNS. |
SNS platform endpoint |
|
Amazon SNS |
Amazon SNS Publish and PublishBatch API operations on topics. For more information, see Amazon SNS. |
SNS topic |
|
Amazon SQS |
Amazon SQS API activity on messages. For more information, see Amazon SQS. |
SQS |
|
Amazon Systems Manager |
Systems Manager API activity on managed nodes. For more information, see Amazon Systems Manager. |
Systems Manager managed node |
|
Amazon Systems Manager |
Systems Manager API activity on control channels. For more information, see Amazon Systems Manager. |
Systems Manager |
|
Amazon Step Functions |
Step Functions API activity on activities. For more information, see Amazon Step Functions. |
Step Functions activity |
|
Amazon Step Functions |
Step Functions API activity on state machines. For more information, see Amazon Step Functions. |
Step Functions state machine |
|
Amazon SWF |
Amazon SWF API activity on domains. For more information, see Amazon SWF. |
SWF domain |
|
Amazon Verified Permissions |
Amazon Verified Permissions API activity on a policy store. |
Amazon Verified Permissions |
|
Amazon X-Ray |
X-Ray API activity on traces. For more information, see Amazon X-Ray. |
X-Ray trace |
|
Data events are not logged by default when you create a trail. To record CloudTrail data events, you must explicitly add the supported resources or resource types for which you want to collect activity. For more information, see Creating a trail with the CloudTrail console.
Additional charges apply for logging data events. For CloudTrail pricing, see Amazon CloudTrail Pricing
The following example shows a single log record of a data event for the Amazon SNS
Publish action.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "EX_PRINCIPAL_ID", "arn": "arn:aws:iam::123456789012:user/Bob", "accountId": "123456789012", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn": "arn:aws:iam::123456789012:role/Admin", "accountId": "123456789012", "userName": "ExampleUser" }, "attributes": { "creationDate": "2023-08-21T16:44:05Z", "mfaAuthenticated": "false" } } }, "eventTime": "2023-08-21T16:48:37Z", "eventSource": "sns.amazonaws.com", "eventName": "Publish", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "userAgent": "aws-cli/1.29.16 md/Botocore#1.31.16 ua/2.0 os/linux#5.4.250-173.369.amzn2int.x86_64 md/arch#x86_64 lang/python#3.8.17 md/pyimpl#CPython cfg/retry-mode#legacy botocore/1.31.16", "requestParameters": { "topicArn": "arn:aws:sns:us-east-1:123456789012:ExampleSNSTopic", "message": "HIDDEN_DUE_TO_SECURITY_REASONS", "subject": "HIDDEN_DUE_TO_SECURITY_REASONS", "messageStructure": "json", "messageAttributes": "HIDDEN_DUE_TO_SECURITY_REASONS" }, "responseElements": { "messageId": "0787cd1e-d92b-521c-a8b4-90434e8ef840" }, "requestID": "0a8ab208-11bf-5e01-bd2d-ef55861b545d", "eventID": "bb3496d4-5252-4660-9c28-3c6aebdb21c0", "readOnly": false, "resources": [{ "accountId": "123456789012", "type": "AWS::SNS::Topic", "ARN": "arn:aws:sns:us-east-1:123456789012:ExampleSNSTopic" }], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "123456789012", "eventCategory": "Data", "tlsDetails": { "tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "sns.us-east-1.amazonaws.com" } }
The next example shows a single log record of a data event for the Amazon Cognito
GetCredentialsForIdentity action.
{ "eventVersion": "1.08", "userIdentity": { "type": "Unknown" }, "eventTime": "2023-01-19T16:55:08Z", "eventSource": "cognito-identity.amazonaws.com", "eventName": "GetCredentialsForIdentity", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.4", "userAgent": "aws-cli/2.7.25 Python/3.9.11 Darwin/21.6.0 exe/x86_64 prompt/off command/cognito-identity.get-credentials-for-identity", "requestParameters": { "logins": { "cognito-idp.us-east-1.amazonaws.com/us-east-1_aaaaaaaaa": "HIDDEN_DUE_TO_SECURITY_REASONS" }, "identityId": "us-east-1:1cf667a2-49a6-454b-9e45-23199EXAMPLE" }, "responseElements": { "credentials": { "accessKeyId": "ASIAIOSFODNN7EXAMPLE", "sessionToken": "aAaAaAaAaAaAab1111111111EXAMPLE", "expiration": "Jan 19, 2023 5:55:08 PM" }, "identityId": "us-east-1:1cf667a2-49a6-454b-9e45-23199EXAMPLE" }, "requestID": "659dfc23-7c4e-4e7c-858a-1abce884d645", "eventID": "6ad1c766-5a41-4b28-b5ca-e223ccb00f0d", "readOnly": false, "resources": [{ "accountId": "111122223333", "type": "AWS::Cognito::IdentityPool", "ARN": "arn:aws:cognito-identity:us-east-1:111122223333:identitypool/us-east-1:2dg778b3-50b7-565c-0f56-34200EXAMPLE" }], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111122223333", "eventCategory": "Data" }
Network activity events
CloudTrail network activity events enable VPC endpoint owners to record Amazon API calls made using their VPC endpoints from a private VPC to the Amazon Web Services service. Network activity events provide visibility into the resource operations performed within a VPC.
You can log network activity events for the following services:
Amazon SageMaker
Amazon IoT Secured Tunneling
Amazon SSO
Amazon Step Functions
Amazon Transfer Family
Bedrock Agent Core
DynamoDB
IoT
Relational Database Service (RDS) Core Control Plane
Simple Notification Service (SNS)
Network activity events are not logged by default when you create a trail or event data store. To record CloudTrail network activity events, you must explicitly set the event source for which you want to collect activity. For more information, see Logging network activity events.
Additional charges apply for logging network activity events. For CloudTrail pricing, see Amazon CloudTrail Pricing
The following example shows a successful Amazon KMS ListKeys event that traversed a VPC endpoint. The vpcEndpointId field shows the ID of the VPC endpoint. The
vpcEndpointAccountId field shows the account ID of the VPC endpoint owner. In this example, the request was made by the VPC endpoint owner.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "ASIAIOSFODNN7EXAMPLE:role-name", "arn": "arn:aws:sts::123456789012:assumed-role/Admin/role-name", "accountId": "123456789012", "accessKeyId": "ASIAIOSFODNN7EXAMPLE", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "ASIAIOSFODNN7EXAMPLE", "arn": "arn:aws:iam::123456789012:role/Admin", "accountId": "123456789012", "userName": "Admin" }, "attributes": { "creationDate": "2024-06-04T23:10:46Z", "mfaAuthenticated": "false" } } }, "eventTime": "2024-06-04T23:12:50Z", "eventSource": "kms.amazonaws.com", "eventName": "ListKeys", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "requestID": "16bcc089-ac49-43f1-9177-EXAMPLE23731", "eventID": "228ca3c8-5f95-4a8a-9732-EXAMPLE60ed9", "eventType": "AwsVpceEvent", "recipientAccountId": "123456789012", "sharedEventID": "a1f3720c-ef19-47e9-a5d5-EXAMPLE8099f", "vpcEndpointId": "vpce-EXAMPLE08c1b6b9b7", "vpcEndpointAccountId": "123456789012", "eventCategory": "NetworkActivity" }
The next example shows an unsuccessful Amazon KMS ListKeys event with a VPC endpoint policy violation. Because a VPC policy violation occurred, both the
errorCode and errorMessage fields are present. The account ID in the recipientAccountId and vpcEndpointAccountId
fields is the same, which indicates the event was sent to the VPC endpoint owner. The accountId
in the userIdentity element is not the vpcEndpointAccountId, which indicates that the user making the request is not the VPC endpoint owner.
{ "eventVersion": "1.09", "userIdentity": { "type": "AWSAccount", "principalId": "AKIAIOSFODNN7EXAMPLE", "accountId": "777788889999" }, "eventTime": "2024-07-15T23:57:12Z", "eventSource": "kms.amazonaws.com", "eventName": "ListKeys", "awsRegion": "us-east-1", "sourceIPAddress": "192.0.2.0", "errorCode": "VpceAccessDenied", "errorMessage": "The request was denied due to a VPC endpoint policy", "requestID": "899003b8-abc4-42bb-ad95-EXAMPLE0c374", "eventID": "7c6e3d04-0c3b-42f2-8589-EXAMPLE826c0", "eventType": "AwsVpceEvent", "recipientAccountId": "123456789012", "sharedEventID": "702f74c4-f692-4bfd-8491-EXAMPLEb1ac4", "vpcEndpointId": "vpce-EXAMPLE08c1b6b9b7", "vpcEndpointAccountId": "123456789012", "eventCategory": "NetworkActivity" }
Insights events
CloudTrail Insights events capture unusual API call rate or error rate activity in your Amazon account by analyzing CloudTrail management activity. Insights events provide relevant information, such as the associated API, error code, incident time, and statistics, that help you understand and act on unusual activity. Unlike other types of events captured in a CloudTrail trail or event data store, Insights events are logged only when CloudTrail detects changes in your account's API usage or error rate logging that differ significantly from the account's typical usage patterns. For more information, see Working with CloudTrail Insights.
Examples of activity that might generate Insights events include:
-
Your account typically logs no more than 20 Amazon S3
deleteBucketAPI calls per minute, but your account starts to log an average of 100deleteBucketAPI calls per minute. An Insights event is logged at the start of the unusual activity, and another Insights event is logged to mark the end of the unusual activity. -
Your account typically logs 20 calls per minute to the Amazon EC2
AuthorizeSecurityGroupIngressAPI, but your account starts to log zero calls toAuthorizeSecurityGroupIngress. An Insights event is logged at the start of the unusual activity, and ten minutes later, when the unusual activity ends, another Insights event is logged to mark the end of the unusual activity. -
Your account typically logs less than one
AccessDeniedExceptionerror in a seven-day period on the Amazon Identity and Access Management API,DeleteInstanceProfile. Your account starts to log an average of 12AccessDeniedExceptionerrors per minute on theDeleteInstanceProfileAPI call. An Insights event is logged at the start of the unusual error rate activity, and another Insights event is logged to mark the end of the unusual activity.
These examples are provided for illustration purposes only. Your results may vary depending on your use case.
To log CloudTrail Insights events, you must explicitly enable Insights events on a new or existing trail or event data store. For more information about creating a trail, see Creating a trail with the CloudTrail console. For more information about creating an event data store, see Create an event data store for Insights events with the console.
Additional charges apply for Insights events. You will be charged separately if you enable Insights for both trails and event data stores. For more information, see Amazon CloudTrail Pricing
There are two events logged to show unusual activity in CloudTrail Insights: a start event and
an end event. The following example shows a single log record of a starting Insights event that
occurred when the Application Auto Scaling API CompleteLifecycleAction was called an unusual number
of times. For Insights events, the value of eventCategory is Insight.
An insightDetails block identifies the event state, source, name, Insights type,
and context, including statistics and attributions. For more information about the
insightDetails block, see CloudTrail record contents for Insights events for trails.
{ "eventVersion": "1.08", "eventTime": "2023-07-10T01:42:00Z", "awsRegion": "us-east-1", "eventID": "55ed45c5-0b0c-4228-9fe5-EXAMPLEc3f4d", "eventType": "AwsCloudTrailInsight", "recipientAccountId": "123456789012", "sharedEventID": "979c82fe-14d4-4e4c-aa01-EXAMPLE3acee", "insightDetails": { "state": "Start", "eventSource": "autoscaling.amazonaws.com", "eventName": "CompleteLifecycleAction", "insightType": "ApiCallRateInsight", "insightContext": { "statistics": { "baseline": { "average": 9.82222E-5 }, "insight": { "average": 5.0 }, "insightDuration": 1, "baselineDuration": 10181 }, "attributions": [{ "attribute": "userIdentityArn", "insight": [{ "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole1", "average": 5.0 }, { "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole2", "average": 5.0 }, { "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole3", "average": 5.0 }], "baseline": [{ "value": "arn:aws:sts::123456789012:assumed-role/CodeDeployRole1", "average": 9.82222E-5 }] }, { "attribute": "userAgent", "insight": [{ "value": "codedeploy.amazonaws.com", "average": 5.0 }], "baseline": [{ "value": "codedeploy.amazonaws.com", "average": 9.82222E-5 }] }, { "attribute": "errorCode", "insight": [{ "value": "null", "average": 5.0 }], "baseline": [{ "value": "null", "average": 9.82222E-5 }] }] } }, "eventCategory": "Insight" }