Put Insight Selectors
| cloudtrail_put_insight_selectors | R Documentation |
Lets you enable Insights event logging by specifying the Insights selectors that you want to enable on an existing trail or event data store¶
Description¶
Lets you enable Insights event logging by specifying the Insights
selectors that you want to enable on an existing trail or event data
store. You also use put_insight_selectors to turn off Insights event
logging, by passing an empty list of Insights types. The valid Insights
event types are ApiErrorRateInsight and ApiCallRateInsight.
To enable Insights on an event data store, you must specify the ARNs (or
ID suffix of the ARNs) for the source event data store
(EventDataStore) and the destination event data store
(InsightsDestination). The source event data store logs management
events and enables Insights. The destination event data store logs
Insights events based upon the management event activity of the source
event data store. The source and destination event data stores must
belong to the same Amazon Web Services account.
To log Insights events for a trail, you must specify the name
(TrailName) of the CloudTrail trail for which you want to change or
add Insights selectors.
To log CloudTrail Insights events on API call volume, the trail or event
data store must log write management events. To log CloudTrail
Insights events on API error rate, the trail or event data store must
log read or write management events. You can call
get_event_selectors on a trail to check whether the trail logs
management events. You can call get_event_data_store on an event data
store to check whether the event data store logs management events.
For more information, see Logging CloudTrail Insights events in the CloudTrail User Guide.
Usage¶
Arguments¶
TrailNameThe name of the CloudTrail trail for which you want to change or add Insights selectors.
You cannot use this parameter with the
EventDataStoreandInsightsDestinationparameters.InsightSelectors[required] A JSON string that contains the Insights types you want to log on a trail or event data store.
ApiCallRateInsightandApiErrorRateInsightare valid Insight types.The
ApiCallRateInsightInsights type analyzes write-only management API calls that are aggregated per minute against a baseline API call volume.The
ApiErrorRateInsightInsights type analyzes management API calls that result in error codes. The error is shown if the API call is unsuccessful.EventDataStoreThe ARN (or ID suffix of the ARN) of the source event data store for which you want to change or add Insights selectors. To enable Insights on an event data store, you must provide both the
EventDataStoreandInsightsDestinationparameters.You cannot use this parameter with the
TrailNameparameter.InsightsDestinationThe ARN (or ID suffix of the ARN) of the destination event data store that logs Insights events. To enable Insights on an event data store, you must provide both the
EventDataStoreandInsightsDestinationparameters.You cannot use this parameter with the
TrailNameparameter.
Value¶
A list with the following syntax:
list(
TrailARN = "string",
InsightSelectors = list(
list(
InsightType = "ApiCallRateInsight"|"ApiErrorRateInsight"
)
),
EventDataStoreArn = "string",
InsightsDestination = "string"
)