CloudTrail¶
Client¶
AsyncCloudTrailClient
¶
AsyncCloudTrailClient(config: AsyncCloudTrailConfig | None = None, plugins: list[Plugin] | None = None)
This is the CloudTrail API Reference. It provides descriptions of actions, data types, common parameters, and common errors for CloudTrail.
CloudTrail is a web service that records Amazon Web Services API calls for your Amazon Web Services account and delivers log files to an Amazon S3 bucket. The recorded information includes the identity of the user, the start time of the Amazon Web Services API call, the source IP address, the request parameters, and the response elements returned by the service.
Note
As an alternative to the API, you can use one of the Amazon Web Services SDKs, which consist of libraries and sample code for various programming languages and platforms (Java, Ruby, .NET, iOS, Android, etc.). The SDKs provide programmatic access to CloudTrail. For example, the SDKs handle cryptographically signing requests, managing errors, and retrying requests automatically. For more information about the Amazon Web Services SDKs, including how to download and install them, see Tools to Build on Amazon Web Services.
See the CloudTrail User Guide for information about the data that is included with each Amazon Web Services API call listed in the log files.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
config
|
AsyncCloudTrailConfig | None
|
Optional configuration for the client. Here you can set things like the endpoint for HTTP services or auth credentials. |
None
|
plugins
|
list[Plugin] | None
|
A list of callables applied once to the client's base configuration. Their changes are inherited by every operation invocation. |
None
|
Operations¶
add_tagscancel_querycreate_channelcreate_dashboardcreate_event_data_storecreate_traildelete_channeldelete_dashboarddelete_event_data_storedelete_resource_policydelete_trailderegister_organization_delegated_admindescribe_querydescribe_trailsdisable_federationenable_federationgenerate_queryget_channelget_dashboardget_event_configurationget_event_data_storeget_event_selectorsget_importget_insight_selectorsget_query_resultsget_resource_policyget_trailget_trail_statuslist_channelslist_dashboardslist_event_data_storeslist_import_failureslist_importslist_insights_datalist_insights_metric_datalist_public_keyslist_querieslist_tagslist_trailslookup_eventsput_event_configurationput_event_selectorsput_insight_selectorsput_resource_policyregister_organization_delegated_adminremove_tagsrestore_event_data_storesearch_sample_queriesstart_dashboard_refreshstart_event_data_store_ingestionstart_importstart_loggingstart_querystop_event_data_store_ingestionstop_importstop_loggingupdate_channelupdate_dashboardupdate_event_data_storeupdate_trail
Configuration¶
AsyncCloudTrailConfig
dataclass
¶
Bases: AsyncAwsConfig
CloudTrail configuration (async-resolved).
Attributes¶
auth_scheme_resolver
class-attribute
instance-attribute
¶
An auth scheme resolver that determines the auth scheme for each operation.
auth_schemes
class-attribute
instance-attribute
¶
A map of auth scheme ids to auth schemes.
aws_access_key_id
class-attribute
instance-attribute
¶
aws_access_key_id: str | None = None
The identifier for a secret access key.
aws_credentials_identity_resolver
class-attribute
instance-attribute
¶
aws_credentials_identity_resolver: IdentityResolver[AWSCredentialsIdentity, AWSIdentityProperties] | None = None
Resolves AWS Credentials. Required for operations that use Sigv4 Auth.
aws_secret_access_key
class-attribute
instance-attribute
¶
aws_secret_access_key: str | None = None
A secret access key that can be used to sign requests.
aws_session_token
class-attribute
instance-attribute
¶
aws_session_token: str | None = None
The session token used with temporary AWS credentials.
endpoint_resolver
class-attribute
instance-attribute
¶
The endpoint resolver used to resolve the final endpoint per-operation based on the configuration.
interceptors
class-attribute
instance-attribute
¶
The list of interceptors, which are hooks that are called during the execution of a request.
protocol
class-attribute
instance-attribute
¶
The protocol to serialize and deserialize requests with.
region
class-attribute
instance-attribute
¶
region: str | None = None
The AWS region to connect to. The configured region is used to determine the service endpoint.
sdk_ua_app_id
class-attribute
instance-attribute
¶
sdk_ua_app_id: str | None = None
A unique and opaque application ID that is appended to the User-Agent header.
user_agent_extra
class-attribute
instance-attribute
¶
user_agent_extra: str | None = None
Additional suffix to be added to the User-Agent header.
Methods:¶
resolve
async
classmethod
¶
resolve(*, profile: str | None = None, fs: FileSystem | None = None, config_file_path: str | None = None, credentials_file_path: str | None = None, **overrides: Unpack[_AsyncCloudTrailConfigOverrides]) -> Self
Resolve config from environment, config files, defaults, and explicit overrides.
Plugin
module-attribute
¶
Plugin: TypeAlias = Callable[[AsyncCloudTrailConfig], None]
A callable that customizes a client configuration. Service-level plugins are applied once to the base configuration inherited by every operation. Operation-level plugins apply only to a single operation invocation.
Structures¶
AdvancedEventSelectorAdvancedFieldSelectorAggregationConfigurationChannelContextKeySelectorDashboardDetailDataResourceDestinationEventEventDataStoreEventSelectorImportFailureListItemImportSourceImportStatisticsImportsListItemIngestionStatusInsightSelectorLookupAttributePartitionKeyPublicKeyQueryQueryStatisticsQueryStatisticsForDescribeQueryRefreshScheduleRefreshScheduleFrequencyRequestWidgetResourceResourceTagS3ImportSourceSearchSampleQueriesSearchResultSourceConfigTagTrailTrailInfoWidget
Errors¶
AccessDeniedExceptionAccountHasOngoingImportExceptionAccountNotFoundExceptionAccountNotRegisteredExceptionAccountRegisteredExceptionCannotDelegateManagementAccountExceptionChannelARNInvalidExceptionChannelAlreadyExistsExceptionChannelExistsForEDSExceptionChannelMaxLimitExceededExceptionChannelNotFoundExceptionCloudTrailARNInvalidExceptionCloudTrailAccessNotEnabledExceptionCloudTrailInvalidClientTokenIdExceptionCloudWatchLogsDeliveryUnavailableExceptionConcurrentModificationExceptionConflictExceptionDelegatedAdminAccountLimitExceededExceptionEventDataStoreARNInvalidExceptionEventDataStoreAlreadyExistsExceptionEventDataStoreFederationEnabledExceptionEventDataStoreHasOngoingImportExceptionEventDataStoreMaxLimitExceededExceptionEventDataStoreNotFoundExceptionEventDataStoreTerminationProtectedExceptionGenerateResponseExceptionImportNotFoundExceptionInactiveEventDataStoreExceptionInactiveQueryExceptionInsightNotEnabledExceptionInsufficientDependencyServiceAccessPermissionExceptionInsufficientEncryptionPolicyExceptionInsufficientIAMAccessPermissionExceptionInsufficientS3BucketPolicyExceptionInsufficientSnsTopicPolicyExceptionInvalidCloudWatchLogsLogGroupArnExceptionInvalidCloudWatchLogsRoleArnExceptionInvalidDateRangeExceptionInvalidEventCategoryExceptionInvalidEventDataStoreCategoryExceptionInvalidEventDataStoreStatusExceptionInvalidEventSelectorsExceptionInvalidHomeRegionExceptionInvalidImportSourceExceptionInvalidInsightSelectorsExceptionInvalidKmsKeyIdExceptionInvalidLookupAttributesExceptionInvalidMaxResultsExceptionInvalidNextTokenExceptionInvalidParameterCombinationExceptionInvalidParameterExceptionInvalidQueryStatementExceptionInvalidQueryStatusExceptionInvalidS3BucketNameExceptionInvalidS3PrefixExceptionInvalidSnsTopicNameExceptionInvalidSourceExceptionInvalidTagParameterExceptionInvalidTimeRangeExceptionInvalidTokenExceptionInvalidTrailNameExceptionKmsExceptionKmsKeyDisabledExceptionKmsKeyNotFoundExceptionMaxConcurrentQueriesExceptionMaximumNumberOfTrailsExceededExceptionNoManagementAccountSLRExistsExceptionNotOrganizationManagementAccountExceptionNotOrganizationMasterAccountExceptionOperationNotPermittedExceptionOrganizationNotInAllFeaturesModeExceptionOrganizationsNotInUseExceptionQueryIdNotFoundExceptionResourceARNNotValidExceptionResourceNotFoundExceptionResourcePolicyNotFoundExceptionResourcePolicyNotValidExceptionResourceTypeNotSupportedExceptionS3BucketDoesNotExistExceptionServiceErrorServiceQuotaExceededExceptionTagsLimitExceededExceptionThrottlingExceptionTrailAlreadyExistsExceptionTrailNotFoundExceptionTrailNotProvidedExceptionUnsupportedOperationException
Enums¶
BillingModeDashboardStatusDashboardTypeDeliveryStatusDestinationTypeEventCategoryEventCategoryAggregationEventDataStoreStatusFederationStatusImportFailureStatusImportStatusInsightTypeInsightsMetricDataTypeListInsightsDataDimensionKeyListInsightsDataTypeLookupAttributeKeyMaxEventSizeQueryStatusReadWriteTypeRefreshScheduleFrequencyUnitRefreshScheduleStatusSourceEventCategoryTemplateType