DescribeKey - AWS Key Management Service


The following example shows an AWS CloudTrail log entry for the DescribeKey operation. AWS KMS records an entry like the following one when you call the DescribeKey operation or view KMS keys in the AWS KMS console. This call is the result of viewing a key in the AWS KMS management console.

{ "eventVersion": "1.08", "userIdentity": { "type": "IAMUser", "principalId": "EX_PRINCIPAL_ID", "arn": "arn:aws:iam::111122223333:user/Alice", "accountId": "111122223333", "accessKeyId": "EXAMPLE_KEY_ID", "userName": "Alice" }, "eventTime": "2022-09-26T18:01:36Z", "eventSource": "", "eventName": "DescribeKey", "awsRegion": "us-west-2", "sourceIPAddress": "", "userAgent": "AWS Internal", "requestParameters": { "keyId": "1234abcd-12ab-34cd-56ef-1234567890ab" }, "responseElements": null, "requestID": "12345126-30d5-4b28-98b9-9153da559963", "eventID": "abcde202-ba1a-467c-b4ba-f729d45ae521", "readOnly": true, "resources": [ { "accountId": "111122223333", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab" } ], "eventType": "AwsApiCall", "recipientAccountId": "111122223333" }