resources.ARN
- You can use any operator with resources.ARN
,
but if you use Equals
or NotEquals
, the value must exactly match the
ARN of a valid resource of the type you've specified in the template as the value of
resources.type. For example, if resources.type equals AWS::S3::Object
, the
ARN must be in one of the following formats. To log all data events for all objects
in a specific S3 bucket, use the StartsWith
operator, and include only the
bucket ARN as the matching value.
The trailing slash is intentional; do not exclude it. Replace the text between less
than and greater than symbols (<>) with resource-specific information.
When resources.type equals AWS::DynamoDB::Table
, and the operator is set to
Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::Lambda::Function
, and the operator is set to
Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::AppConfig::Configuration
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::B2BI::Transformer
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::Bedrock::AgentAlias
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::Bedrock::KnowledgeBase
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::Cassandra::Table
, and the operator is set to
Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::CloudFront::KeyValueStore
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::CloudTrail::Channel
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::CodeWhisperer::Customization
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::CodeWhisperer::Profile
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::Cognito::IdentityPool
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::DynamoDB::Stream
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::EC2::Snapshot
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::EMRWAL::Workspace
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::FinSpace::Environment
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::Glue::Table
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::GreengrassV2::ComponentVersion
, and
the operator is set to Equals
or NotEquals
, the ARN must be in the following
format:
When resources.type
equals AWS::GreengrassV2::Deployment
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::GuardDuty::Detector
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::IoT::Certificate
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::IoT::Thing
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::IoTSiteWise::Asset
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::IoTSiteWise::TimeSeries
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::IoTTwinMaker::Entity
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::IoTTwinMaker::Workspace
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::KendraRanking::ExecutionPlan
, and the
operator is set to Equals
or NotEquals
, the ARN must be in the following
format:
When resources.type
equals AWS::KinesisVideo::Stream
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::ManagedBlockchain::Network
, and the
operator is set to Equals
or NotEquals
, the ARN must be in the following
format:
When resources.type
equals AWS::ManagedBlockchain::Node
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::MedicalImaging::Datastore
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::NeptuneGraph::Graph
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::PCAConnectorAD::Connector
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::QBusiness::Application
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::QBusiness::DataSource
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::QBusiness::Index
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::QBusiness::WebExperience
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::RDS::DBCluster
, and the operator is
set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::S3::AccessPoint
, and the operator is
set to Equals
or NotEquals
, the ARN must be in one of the following
formats. To log events on all objects in an S3 access point, we recommend that you
use only the access point ARN, don’t include the object path, and use the StartsWith
or NotStartsWith
operators.
When resources.type
equals AWS::S3ObjectLambda::AccessPoint
, and the
operator is set to Equals
or NotEquals
, the ARN must be in the following
format:
When resources.type
equals AWS::S3Outposts::Object
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SageMaker::Endpoint
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SageMaker::ExperimentTrialComponent
,
and the operator is set to Equals
or NotEquals
, the ARN must be in the
following format:
When resources.type
equals AWS::SageMaker::FeatureGroup
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SCN::Instance
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::ServiceDiscovery::Namespace
, and the
operator is set to Equals
or NotEquals
, the ARN must be in the following
format:
When resources.type
equals AWS::ServiceDiscovery::Service
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SNS::PlatformEndpoint
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SNS::Topic
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SWF::Domain
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SQS::Queue
, and the operator is set
to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::SSMMessages::ControlChannel
, and the
operator is set to Equals
or NotEquals
, the ARN must be in the following
format:
When resources.type
equals AWS::ThinClient::Device
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::ThinClient::Environment
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::Timestream::Database
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type
equals AWS::Timestream::Table
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format:
When resources.type equals AWS::VerifiedPermissions::PolicyStore
, and the operator
is set to Equals
or NotEquals
, the ARN must be in the following format: