Put Insight Selectors
cloudtrail_put_insight_selectors | R Documentation |
Lets you enable Insights event logging by specifying the Insights selectors that you want to enable on an existing trail or event data store¶
Description¶
Lets you enable Insights event logging by specifying the Insights
selectors that you want to enable on an existing trail or event data
store. You also use put_insight_selectors
to turn off Insights event
logging, by passing an empty list of Insights types. The valid Insights
event types are ApiErrorRateInsight
and ApiCallRateInsight
.
To enable Insights on an event data store, you must specify the ARNs (or
ID suffix of the ARNs) for the source event data store
(EventDataStore
) and the destination event data store
(InsightsDestination
). The source event data store logs management
events and enables Insights. The destination event data store logs
Insights events based upon the management event activity of the source
event data store. The source and destination event data stores must
belong to the same Amazon Web Services account.
To log Insights events for a trail, you must specify the name
(TrailName
) of the CloudTrail trail for which you want to change or
add Insights selectors.
To log CloudTrail Insights events on API call volume, the trail or event
data store must log write
management events. To log CloudTrail
Insights events on API error rate, the trail or event data store must
log read
or write
management events. You can call
get_event_selectors
on a trail to check whether the trail logs
management events. You can call get_event_data_store
on an event data
store to check whether the event data store logs management events.
For more information, see Logging CloudTrail Insights events in the CloudTrail User Guide.
Usage¶
Arguments¶
TrailName
The name of the CloudTrail trail for which you want to change or add Insights selectors.
You cannot use this parameter with the
EventDataStore
andInsightsDestination
parameters.InsightSelectors
[required] A JSON string that contains the Insights types you want to log on a trail or event data store.
ApiCallRateInsight
andApiErrorRateInsight
are valid Insight types.The
ApiCallRateInsight
Insights type analyzes write-only management API calls that are aggregated per minute against a baseline API call volume.The
ApiErrorRateInsight
Insights type analyzes management API calls that result in error codes. The error is shown if the API call is unsuccessful.EventDataStore
The ARN (or ID suffix of the ARN) of the source event data store for which you want to change or add Insights selectors. To enable Insights on an event data store, you must provide both the
EventDataStore
andInsightsDestination
parameters.You cannot use this parameter with the
TrailName
parameter.InsightsDestination
The ARN (or ID suffix of the ARN) of the destination event data store that logs Insights events. To enable Insights on an event data store, you must provide both the
EventDataStore
andInsightsDestination
parameters.You cannot use this parameter with the
TrailName
parameter.
Value¶
A list with the following syntax:
list(
TrailARN = "string",
InsightSelectors = list(
list(
InsightType = "ApiCallRateInsight"|"ApiErrorRateInsight"
)
),
EventDataStoreArn = "string",
InsightsDestination = "string"
)