AWS KMS writes entries to your CloudTrail log when you call an AWS KMS operation and when an AWS service calls an operation on your behalf. AWS KMS also writes an entry when it calls an operation for you. For example, it writes an entry when it deletes a KMS key that you scheduled for deletion.
The following topics display examples of CloudTrail log entries for AWS KMS operations.
For examples of CloudTrail log entries of requests to AWS KMS from AWS Nitro Enclaves, see Monitoring requests for Nitro enclaves.