put_insight_selectors¶
Operation¶
put_insight_selectors
async
¶
put_insight_selectors(input: PutInsightSelectorsInput, plugins: list[Plugin] | None = None) -> PutInsightSelectorsOutput
Lets you enable Insights event logging on specific event categories by
specifying the Insights selectors that you want to enable on an existing
trail or event data store. You also use PutInsightSelectors to turn
off Insights event logging, by passing an empty list of Insights types.
The valid Insights event types are ApiErrorRateInsight and
ApiCallRateInsight, and valid EventCategories are Management and
Data.
Note
Insights on data events are not supported on event data stores. For event data stores, you can only enable Insights on management events.
To enable Insights on an event data store, you must specify the ARNs (or
ID suffix of the ARNs) for the source event data store
(EventDataStore) and the destination event data store
(InsightsDestination). The source event data store logs management
events and enables Insights. The destination event data store logs
Insights events based upon the management event activity of the source
event data store. The source and destination event data stores must
belong to the same Amazon Web Services account.
To log Insights events for a trail, you must specify the name
(TrailName) of the CloudTrail trail for which you want to change or
add Insights selectors.
-
For Management events Insights: To log CloudTrail Insights on the API call rate, the trail or event data store must log
writemanagement events. To log CloudTrail Insights on the API error rate, the trail or event data store must logreadorwritemanagement events. -
For Data events Insights: To log CloudTrail Insights on the API call rate or API error rate, the trail must log
readorwritedata events. Data events Insights are not supported on event data store.
To log CloudTrail Insights events on API call volume, the trail or event
data store must log write management events. To log CloudTrail
Insights events on API error rate, the trail or event data store must
log read or write management events. You can call
GetEventSelectors on a trail to check whether the trail logs
management events. You can call GetEventDataStore on an event data
store to check whether the event data store logs management events.
For more information, see Working with CloudTrail Insights in the CloudTrail User Guide.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
input
|
PutInsightSelectorsInput
|
An instance of |
required |
plugins
|
list[Plugin] | None
|
A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations. |
None
|
Returns:
| Type | Description |
|---|---|
PutInsightSelectorsOutput
|
An instance of |
Input¶
PutInsightSelectorsInput
dataclass
¶
Dataclass for PutInsightSelectorsInput structure.
Attributes¶
event_data_store
class-attribute
instance-attribute
¶
event_data_store: str | None = None
The ARN (or ID suffix of the ARN) of the source event data store for
which you want to change or add Insights selectors. To enable Insights
on an event data store, you must provide both the EventDataStore and
InsightsDestination parameters.
You cannot use this parameter with the TrailName parameter.
insight_selectors
class-attribute
instance-attribute
¶
insight_selectors: list[InsightSelector] | None = None
Contains the Insights types you want to log on a specific category of
events on a trail or event data store. ApiCallRateInsight and
ApiErrorRateInsight are valid Insight types.The EventCategory field
can specify Management or Data events or both. For event data store,
you can log Insights for management events only.
The ApiCallRateInsight Insights type analyzes write-only management
API calls or read and write data API calls that are aggregated per
minute against a baseline API call volume.
The ApiErrorRateInsight Insights type analyzes management and data API
calls that result in error codes. The error is shown if the API call is
unsuccessful.
insights_destination
class-attribute
instance-attribute
¶
insights_destination: str | None = None
The ARN (or ID suffix of the ARN) of the destination event data store
that logs Insights events. To enable Insights on an event data store,
you must provide both the EventDataStore and InsightsDestination
parameters.
You cannot use this parameter with the TrailName parameter.
Output¶
PutInsightSelectorsOutput
dataclass
¶
Dataclass for PutInsightSelectorsOutput structure.
Attributes¶
event_data_store_arn
class-attribute
instance-attribute
¶
event_data_store_arn: str | None = None
The Amazon Resource Name (ARN) of the source event data store for which you want to change or add Insights selectors.
insight_selectors
class-attribute
instance-attribute
¶
insight_selectors: list[InsightSelector] | None = None
Contains the Insights types you want to log on a specific category of
events in a trail or event data store. ApiCallRateInsight and
ApiErrorRateInsight are valid Insight types.The EventCategory field
can specify Management or Data events or both. For event data store,
you can only log Insights for management events only.