View a markdown version of this page

Actions, resources, and condition keys for Amazon EventBridge - Service Authorization Reference
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Actions, resources, and condition keys for Amazon EventBridge

Amazon EventBridge (service prefix: events) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by Amazon EventBridge

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation SDK client IAM action Condition key Possible value(s) Access level

CreateEventBus

eventbridgev2

events:CreateEventBus

Write

events:TagResource

Tagging, Write

CreateEventSource

eventbridgev2

events:CreateEventSource

Write

events:TagResource

Tagging, Write

CreateSubscriber

eventbridgev2

events:CreateSubscriber

Write

events:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

events.amazonaws.com

Write

DeleteEventBus

eventbridgev2

events:DeleteEventBus

Write

DeleteEventSource

eventbridgev2

events:DeleteEventSource

Write

DeleteResourcePolicy

eventbridgev2

events:DeleteResourcePolicy

Permissions management, Write

DeleteSubscriber

eventbridgev2

events:DeleteSubscriber

Write

DescribeEventBus

eventbridgev2

events:DescribeEventBus

Read

DescribeEventSource

eventbridgev2

events:DescribeEventSource

Read

DescribeSubscriber

eventbridgev2

events:DescribeSubscriber

Read

GetResourcePolicy

eventbridgev2

events:GetResourcePolicy

Read

ListEventBuses

eventbridgev2

events:ListEventBuses

List

ListEventSources

eventbridgev2

events:ListEventSources

List

ListResourcePolicies

eventbridgev2

events:ListResourcePolicies

List

ListSubscribers

eventbridgev2

events:ListSubscribers

List

ListTagsForResource

eventbridgev2

events:ListTagsForResource

List

PutEvents

eventbridgev2

events:PutEvents

Write

PutRawEvents

eventbridgev2

events:PutRawEvents

Write

PutResourcePolicy

eventbridgev2

events:PutResourcePolicy

Permissions management, Write

RevokeResource

eventbridgev2

events:RevokeResource

Write

TagResource

eventbridgev2

events:TagResource

Tagging, Write

UntagResource

eventbridgev2

events:UntagResource

Tagging, Write

UpdateEventBus

eventbridgev2

events:UpdateEventBus

Write

UpdateEventSource

eventbridgev2

events:UpdateEventSource

Write

UpdateSubscriber

eventbridgev2

events:UpdateSubscriber

Write

iam:PassRole

iam:PassedToService

events.amazonaws.com

Write

ActivateEventSource

events

events:ActivateEventSource

Write

CancelReplay

events

events:CancelReplay

Write

CreateApiDestination

events

events:CreateApiDestination

Write

CreateArchive

events

events:CreateArchive

Write

CreateConnection

events

events:CreateConnection

Write

CreateEndpoint

events

events:CreateEndpoint

Write

iam:PassRole

iam:PassedToService

events.amazonaws.com

Write

CreateEventBus

events

events:CreateEventBus

Write

events:TagResource

Tagging, Write

CreatePartnerEventSource

events

events:CreatePartnerEventSource

Write

DeactivateEventSource

events

events:DeactivateEventSource

Write

DeauthorizeConnection

events

events:DeauthorizeConnection

Write

DeleteApiDestination

events

events:DeleteApiDestination

Write

DeleteArchive

events

events:DeleteArchive

Write

DeleteConnection

events

events:DeleteConnection

Write

DeleteEndpoint

events

events:DeleteEndpoint

Write

DeleteEventBus

events

events:DeleteEventBus

Write

DeletePartnerEventSource

events

events:DeletePartnerEventSource

Write

DeleteRule

events

events:DeleteRule

Write

DescribeApiDestination

events

events:DescribeApiDestination

Read

DescribeArchive

events

events:DescribeArchive

Read

DescribeConnection

events

events:DescribeConnection

Read

DescribeEndpoint

events

events:DescribeEndpoint

Read

DescribeEventBus

events

events:DescribeEventBus

Read

DescribeEventSource

events

events:DescribeEventSource

Read

DescribePartnerEventSource

events

events:DescribePartnerEventSource

Read

DescribeReplay

events

events:DescribeReplay

Read

DescribeRule

events

events:DescribeRule

Read

DisableRule

events

events:DisableRule

Write

EnableRule

events

events:EnableRule

Write

ListApiDestinations

events

events:ListApiDestinations

List

ListArchives

events

events:ListArchives

List

ListConnections

events

events:ListConnections

List

ListEndpoints

events

events:ListEndpoints

List

ListEventBuses

events

events:ListEventBuses

List

ListEventSources

events

events:ListEventSources

List

ListPartnerEventSourceAccounts

events

events:ListPartnerEventSourceAccounts

List

ListPartnerEventSources

events

events:ListPartnerEventSources

List

ListReplays

events

events:ListReplays

List

ListRuleNamesByTarget

events

events:ListRuleNamesByTarget

List

ListRules

events

events:ListRules

List

ListTagsForResource

events

events:ListTagsForResource

List

ListTargetsByRule

events

events:ListTargetsByRule

List

PutEvents

events

events:PutEvents

Write

PutPartnerEvents

events

events:PutPartnerEvents

Write

PutPermission

events

events:PutPermission

Permissions management, Write

PutRule

events

events:PutRule

Write

events:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

events.amazonaws.com

Write

PutTargets

events

events:PutTargets

Write

iam:PassRole

iam:PassedToService

events.amazonaws.com

Write

RemovePermission

events

events:RemovePermission

Permissions management, Write

RemoveTargets

events

events:RemoveTargets

Write

StartReplay

events

events:StartReplay

Write

TagResource

events

events:TagResource

Tagging, Write

TestEventPattern

events

events:TestEventPattern

Read

UntagResource

events

events:UntagResource

Tagging, Write

UpdateApiDestination

events

events:UpdateApiDestination

Write

UpdateArchive

events

events:UpdateArchive

Write

UpdateConnection

events

events:UpdateConnection

Write

UpdateEndpoint

events

events:UpdateEndpoint

Write

iam:PassRole

iam:PassedToService

events.amazonaws.com

Write

UpdateEventBus

events

events:UpdateEventBus

Write

Actions defined by Amazon EventBridge

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in Amazon. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

ActivateEventSource

Grants permission to activate partner event sources

event-source*

Write

CancelReplay

Grants permission to cancel a replay

replay*

Write

CreateApiDestination

Grants permission to create a new api destination

api-destination*

Write

connection*

CreateArchive

Grants permission to create a new archive

alias

Write

archive*

event-bus*

aws:ResourceTag/${TagKey}

key

CreateConnection

Grants permission to create a new connection

connection*

Write

CreateEndpoint

Grants permission to create an endpoint

endpoint*

events:EventBusArn

Write

CreateEventBus

Grants permission to create event buses

event-bus

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

event-busv2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

CreateEventSource

Grants permission to create an event source that forwards events to an event bus

event-busv2*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:source

Write

event-sourcev2*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:source

CreatePartnerEventSource

Grants permission to create partner event sources

event-source*

Write

CreateSubscriber

Grants permission to create a subscriber

event-busv2*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:ContentFilterPresent

events:Metadata/${MetadataKey}

events:Metadata/${MetadataKey}/Matcher

Write

subscriber*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:ContentFilterPresent

events:Metadata/${MetadataKey}

events:Metadata/${MetadataKey}/Matcher

DeactivateEventSource

Grants permission to deactivate event sources

event-source*

Write

DeauthorizeConnection

Grants permission to deauthorize a connection, deleting its stored authorization secrets

connection*

Write

DeleteApiDestination

Grants permission to delete an api destination

api-destination*

Write

DeleteArchive

Grants permission to delete an archive

archive*

Write

DeleteConnection

Grants permission to delete a connection

connection*

Write

DeleteEndpoint

Grants permission to delete an endpoint

endpoint*

Write

DeleteEventBus

Grants permission to delete event buses

event-bus

aws:ResourceTag/${TagKey}

Write

event-busv2

aws:ResourceTag/${TagKey}

DeleteEventSource

Grants permission to delete an event source

event-sourcev2*

aws:ResourceTag/${TagKey}

Write

DeletePartnerEventSource

Grants permission to delete partner event sources

event-source*

Write

DeleteResourcePolicy

Grants permission to delete a resource policy attached to an event bus

event-busv2*

aws:ResourceTag/${TagKey}

events:PolicyName

Permissions management, Write

DeleteRule

Grants permission to delete rules

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

Write

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

DeleteSubscriber

Grants permission to delete a subscriber

subscriber*

aws:ResourceTag/${TagKey}

Write

DescribeApiDestination

Grants permission to retrieve details about an api destination

api-destination*

Read

connection*

DescribeArchive

Grants permission to retrieve details about an archive

archive*

Read

DescribeConnection

Grants permission to retrieve details about a conection

connection*

Read

DescribeEndpoint

Grants permission to retrieve details about an endpoint

endpoint*

Read

DescribeEventBus

Grants permission to retrieve details about event buses

event-bus

aws:ResourceTag/${TagKey}

Read

event-busv2

aws:ResourceTag/${TagKey}

DescribeEventSource

Grants permission to retrieve details about event sources

event-source

Read

event-sourcev2

aws:ResourceTag/${TagKey}

DescribePartnerEventSource

Grants permission to retrieve details about partner event sources

event-source*

Read

DescribeReplay

Grants permission to retrieve the details of a replay

replay*

Read

DescribeRule

Grants permission to retrieve details about rules

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

Read

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

DescribeSubscriber

Grants permission to retrieve details about a subscriber

subscriber*

aws:ResourceTag/${TagKey}

Read

DisableRule

Grants permission to disable rules

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

Write

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

EnableRule

Grants permission to enable rules

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

Write

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

GetResourcePolicy

Grants permission to retrieve the resource policy attached to an event bus

event-busv2*

aws:ResourceTag/${TagKey}

events:PolicyName

Read

ListApiDestinations

Grants permission to retrieve a list of api destinations

List

ListArchives

Grants permission to retrieve a list of archives

List

ListConnections

Grants permission to retrieve a list of connections

List

ListEndpoints

Grants permission to retrieve a list of endpoints

List

ListEventBuses

Grants permission to retrieve a list of the event buses in your account

List

ListEventSources

Grants permission to to retrieve a list of event sources shared with this account

List

ListPartnerEventSourceAccounts

Grants permission to retrieve a list of Amazon Web Services account IDs associated with an event source

event-source*

List

ListPartnerEventSources

Grants permission to retrieve a list partner event sources

List

ListReplays

Grants permission to retrieve a list of replays

List

ListResourcePolicies

Grants permission to list the resource policies attached to an event bus

event-busv2*

aws:ResourceTag/${TagKey}

List

ListRuleNamesByTarget

Grants permission to retrieve a list of the names of the rules associated with a target

List

ListRules

Grants permission to retrieve a list of the Amazon EventBridge rules in the account

List

ListSubscribers

Grants permission to retrieve a list of subscribers

List

ListTagsForResource

Grants permission to retrieve a list of tags associated with an Amazon EventBridge resource

event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

List

event-busv2

aws:ResourceTag/${TagKey}

events:creatorAccount

event-sourcev2

aws:ResourceTag/${TagKey}

events:creatorAccount

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

subscriber

aws:ResourceTag/${TagKey}

events:creatorAccount

ListTargetsByRule

Grants permission to retrieve a list of targets defined for a rule

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

List

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

PutEvents

Grants permission to send custom events to Amazon EventBridge

event-bus

aws:ResourceTag/${TagKey}

events:detail-type

events:eventBusInvocation

events:source

events:SystemMetadata/AwsDetailType

events:SystemMetadata/AwsSource

events:SystemMetadata/ContentType

Write

event-busv2

aws:ResourceTag/${TagKey}

events:detail-type

events:eventBusInvocation

events:source

events:SystemMetadata/AwsDetailType

events:SystemMetadata/AwsSource

events:SystemMetadata/ContentType

PutPartnerEvents

Grants permission to sends custom events to Amazon EventBridge

Write

PutPermission

Grants permission to use the PutPermission action to grants permission to another Amazon Web Services account to put events to your default event bus

Permissions management, Write

PutRawEvents

Grants permission to publish raw-format events with custom content types, metadata, binary payloads, and FIFO ordering to Amazon EventBridge

event-busv2*

aws:ResourceTag/${TagKey}

events:eventBusInvocation

events:Metadata/${MetadataKey}

events:SystemMetadata/AwsDetailType

events:SystemMetadata/AwsSource

events:SystemMetadata/ContentType

Write

PutResourcePolicy

Grants permission to attach a resource policy to an event bus

event-busv2*

aws:ResourceTag/${TagKey}

events:PolicyName

Permissions management, Write

PutRule

Grants permission to create or updates rules

rule-on-custom-event-bus

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

events:detail-type

events:detail.eventTypeCode

events:detail.service

events:detail.userIdentity.principalId

events:ManagedBy

events:source

Write

rule-on-default-event-bus

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

events:detail-type

events:detail.eventTypeCode

events:detail.service

events:detail.userIdentity.principalId

events:ManagedBy

events:source

PutTargets

Grants permission to add targets to a rule

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

events:TargetArn

Write

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

events:TargetArn

RemovePermission

Grants permission to revoke the permission of another Amazon Web Services account to put events to your default event bus

Permissions management, Write

RemoveTargets

Grants permission to removes targets from a rule

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

Write

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

events:creatorAccount

events:ManagedBy

RevokeResource

Grants permission to revoke a subscriber or an event source on an event bus

event-busv2*

aws:ResourceTag/${TagKey}

Write

StartReplay

Grants permission to start a replay of an archive

archive*

Write

event-bus*

aws:ResourceTag/${TagKey}

replay*

TagResource

Grants permission to add a tag to an Amazon EventBridge resource

event-bus

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

Tagging, Write

event-busv2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

event-sourcev2

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

rule-on-custom-event-bus

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

rule-on-default-event-bus

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

subscriber

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

TestEventPattern

Grants permission to test whether an event pattern matches the provided event

Read

UntagResource

Grants permission to remove a tag from an Amazon EventBridge resource

event-bus

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

Tagging, Write

event-busv2

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

event-sourcev2

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

rule-on-custom-event-bus

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

rule-on-default-event-bus

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

subscriber

aws:ResourceTag/${TagKey}

aws:TagKeys

events:creatorAccount

UpdateApiDestination

Grants permission to update an api destination

api-destination*

Write

UpdateArchive

Grants permission to update an archive

alias

Write

archive*

key

UpdateConnection

Grants permission to update a connection

connection*

Write

UpdateEndpoint

Grants permission to update an endpoint

endpoint*

events:EventBusArn

Write

UpdateEventBus

Grants permission to update event buses

event-bus

aws:ResourceTag/${TagKey}

Write

event-busv2

aws:ResourceTag/${TagKey}

UpdateEventSource

Grants permission to update an event source

event-busv2

aws:ResourceTag/${TagKey}

events:source

Write

event-sourcev2*

aws:ResourceTag/${TagKey}

events:source

UpdateSubscriber

Grants permission to update a subscriber

event-busv2

aws:ResourceTag/${TagKey}

events:ContentFilterPresent

events:Metadata/${MetadataKey}

events:Metadata/${MetadataKey}/Matcher

Write

subscriber*

aws:ResourceTag/${TagKey}

events:ContentFilterPresent

events:Metadata/${MetadataKey}

events:Metadata/${MetadataKey}/Matcher

Permission-only actions for Amazon EventBridge

The following actions are defined by Amazon EventBridge but are not directly invocable through any API operation. They can only be used in IAM policy statements to grant or deny permissions.

Actions Description Resource types (*required) Condition keys Access level

AllowVendedLogDeliveryForResource

Grants permission to configure vended log delivery for EventBridge

event-bus

aws:ResourceTag/${TagKey}

Write

subscriber

aws:ResourceTag/${TagKey}

InvokeApiDestination

Grants permission to invoke an api destination

api-destination*

Write

RetrieveConnectionCredentials

Grants permission to retrieve credentials from a connection

connection*

Write

Resource types defined by Amazon EventBridge

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements.

Resource types ARN Condition keys

alias

arn:${Partition}:kms:${Region}:${Account}:alias/${Alias}

api-destination

arn:${Partition}:events:${Region}:${Account}:api-destination/${ApiDestinationName}

archive

arn:${Partition}:events:${Region}:${Account}:archive/${ArchiveName}

connection

arn:${Partition}:events:${Region}:${Account}:connection/${ConnectionName}

create-snapshot

arn:${Partition}:events:${Region}:${Account}:target/create-snapshot

endpoint

arn:${Partition}:events:${Region}:${Account}:endpoint/${EndpointName}

event-bus

arn:${Partition}:events:${Region}:${Account}:event-bus/${EventBusName}

aws:ResourceTag/${TagKey}

event-busv2

arn:${Partition}:events:${Region}:${Account}:event-busv2/${EventBusName}/${OpaqueId}

aws:ResourceTag/${TagKey}

event-source

arn:${Partition}:events:${Region}::event-source/${EventSourceName}

event-sourcev2

arn:${Partition}:events:${Region}:${Account}:event-sourcev2/${SourceType}/${EventSourceName}/${OpaqueId}

aws:ResourceTag/${TagKey}

key

arn:${Partition}:kms:${Region}:${Account}:key/${KeyId}

reboot-instance

arn:${Partition}:events:${Region}:${Account}:target/reboot-instance

replay

arn:${Partition}:events:${Region}:${Account}:replay/${ReplayName}

rule-on-custom-event-bus

arn:${Partition}:events:${Region}:${Account}:rule/${EventBusName}/${RuleName}

aws:ResourceTag/${TagKey}

rule-on-default-event-bus

arn:${Partition}:events:${Region}:${Account}:rule/${RuleName}

aws:ResourceTag/${TagKey}

stop-instance

arn:${Partition}:events:${Region}:${Account}:target/stop-instance

subscriber

arn:${Partition}:events:${Region}:${Account}:subscriber/${SubscriberName}/${OpaqueId}

aws:ResourceTag/${TagKey}

terminate-instance

arn:${Partition}:events:${Region}:${Account}:target/terminate-instance

Condition keys for Amazon EventBridge

Amazon EventBridge defines the following condition keys that can be used in the Condition element of an IAM policy.

Condition keys Description Type

aws:RequestTag/${TagKey}

Filters access by the allowed set of values for each of the tags to event bus and rule actions

String

aws:ResourceTag/${TagKey}

Filters access by tag-value associated with the resource to event bus and rule actions

String

aws:TagKeys

Filters access by the tags in the request to event bus and rule actions

ArrayOfString

events:ContentFilterPresent

Filters access by whether a subscriber declares a payload-scope content filter to CreateSubscriber and UpdateSubscriber actions

Bool

events:EventBusArn

Filters access by the ARN of the event buses that can be associated with an endpoint to CreateEndpoint and UpdateEndpoint actions

ArrayOfARN

events:ManagedBy

Filters access by Amazon services. If a rule is created by an Amazon service on your behalf, the value is the principal name of the service that created the rule

String

events:Metadata/${MetadataKey}

Filters access by a metadata key-value pair on the published event to PutRawEvents actions, or by the exact-match values declared for that key in a subscriber's metadata filter to CreateSubscriber and UpdateSubscriber actions

ArrayOfString

events:Metadata/${MetadataKey}/Matcher

Filters access by the match type declared for a metadata key in a subscriber's filter to CreateSubscriber and UpdateSubscriber actions

String

events:PolicyName

Filters access by the name of the resource policy specified in the request to resource policy actions

String

events:SystemMetadata/AwsDetailType

Filters access by the detail type recorded in the system metadata of an event forwarded onto an event bus to PutEvents and PutRawEvents actions

String

events:SystemMetadata/AwsSource

Filters access by the source recorded in the system metadata of an event forwarded onto an event bus to PutEvents and PutRawEvents actions

String

events:SystemMetadata/ContentType

Filters access by the content type declared on an event for PutRawEvents and for forwarded events authorized as PutEvents

String

events:TargetArn

Filters access by the ARN of a target that can be put to a rule to PutTargets actions. TargetARN doesn't include DeadLetterConfigArn

ArrayOfARN

events:creatorAccount

Filters access by the account the rule was created in to rule actions

String

events:detail-type

Filters access by the literal string of the detail-type of the event to PutEvents and PutRule actions

ArrayOfString

events:detail.eventTypeCode

Filters access by the literal string for the detail.eventTypeCode field of the event to PutRule actions

String

events:detail.service

Filters access by the literal string for the detail.service field of the event to PutRule actions

String

events:detail.userIdentity.principalId

Filters access by the literal string for the detail.useridentity.principalid field of the event to PutRule actions

String

events:eventBusInvocation

Filters access to PutEvents and PutRawEvents by whether an event was forwarded from an event bus rather than published through a direct API call

String

events:source

Filters access by the Amazon service or Amazon partner event source that generated the event to PutEvents and PutRule actions, or by the configured source of an event source to the CreateEventSource and UpdateEventSource actions. Matches the literal string of the source field of the event

ArrayOfString