public class AWSCloudTrailClient extends AmazonWebServiceClient implements AWSCloudTrail
AWS CloudTrail
This is the CloudTrail API Reference. It provides descriptions of actions, data types, common parameters, and common errors for CloudTrail.
CloudTrail is a web service that records AWS API calls for your AWS account and delivers log files to an Amazon S3 bucket. The recorded information includes the identity of the user, the start time of the AWS API call, the source IP address, the request parameters, and the response elements returned by the service.
NOTE: As an alternative to using the API, you can use one of the AWS SDKs, which consist of libraries and sample code for various programming languages and platforms (Java, Ruby, .NET, iOS, Android, etc.). The SDKs provide a convenient way to create programmatic access to AWSCloudTrail. For example, the SDKs take care of cryptographically signing requests, managing errors, and retrying requests automatically. For information about the AWS SDKs, including how to download and install them, see the Tools for Amazon Web Services page.
See the CloudTrail User Guide for information about the data that is included with each AWS API call listed in the log files.
| Modifier and Type | Field and Description |
|---|---|
protected List<com.amazonaws.transform.JsonErrorUnmarshaller> |
jsonErrorUnmarshallers
List of exception unmarshallers for all AWSCloudTrail exceptions.
|
client, clientConfiguration, endpoint, LOGGING_AWS_REQUEST_METRIC, requestHandler2s, timeOffset| Constructor and Description |
|---|
AWSCloudTrailClient()
Constructs a new client to invoke service methods on
AWSCloudTrail.
|
AWSCloudTrailClient(AWSCredentials awsCredentials)
Constructs a new client to invoke service methods on
AWSCloudTrail using the specified AWS account credentials.
|
AWSCloudTrailClient(AWSCredentials awsCredentials,
ClientConfiguration clientConfiguration)
Constructs a new client to invoke service methods on
AWSCloudTrail using the specified AWS account credentials
and client configuration options.
|
AWSCloudTrailClient(AWSCredentialsProvider awsCredentialsProvider)
Constructs a new client to invoke service methods on
AWSCloudTrail using the specified AWS account credentials provider.
|
AWSCloudTrailClient(AWSCredentialsProvider awsCredentialsProvider,
ClientConfiguration clientConfiguration)
Constructs a new client to invoke service methods on
AWSCloudTrail using the specified AWS account credentials
provider and client configuration options.
|
AWSCloudTrailClient(AWSCredentialsProvider awsCredentialsProvider,
ClientConfiguration clientConfiguration,
RequestMetricCollector requestMetricCollector)
Constructs a new client to invoke service methods on
AWSCloudTrail using the specified AWS account credentials
provider, client configuration options and request metric collector.
|
AWSCloudTrailClient(ClientConfiguration clientConfiguration)
Constructs a new client to invoke service methods on
AWSCloudTrail.
|
| Modifier and Type | Method and Description |
|---|---|
AddTagsResult |
addTags(AddTagsRequest addTagsRequest)
Adds one or more tags to a trail, up to a limit of 10.
|
CreateTrailResult |
createTrail(CreateTrailRequest createTrailRequest)
Creates a trail that specifies the settings for delivery of log data
to an Amazon S3 bucket.
|
DeleteTrailResult |
deleteTrail(DeleteTrailRequest deleteTrailRequest)
Deletes a trail.
|
DescribeTrailsResult |
describeTrails()
Retrieves settings for the trail associated with the current region
for your account.
|
DescribeTrailsResult |
describeTrails(DescribeTrailsRequest describeTrailsRequest)
Retrieves settings for the trail associated with the current region
for your account.
|
ResponseMetadata |
getCachedResponseMetadata(AmazonWebServiceRequest request)
Returns additional metadata for a previously executed successful, request, typically used for
debugging issues where a service isn't acting as expected.
|
GetTrailStatusResult |
getTrailStatus(GetTrailStatusRequest getTrailStatusRequest)
Returns a JSON-formatted list of information about the specified
trail.
|
ListPublicKeysResult |
listPublicKeys()
Returns all public keys whose private keys were used to sign the
digest files within the specified time range.
|
ListPublicKeysResult |
listPublicKeys(ListPublicKeysRequest listPublicKeysRequest)
Returns all public keys whose private keys were used to sign the
digest files within the specified time range.
|
ListTagsResult |
listTags(ListTagsRequest listTagsRequest)
Lists the tags for the trail in the current region.
|
LookupEventsResult |
lookupEvents()
Looks up API activity events captured by CloudTrail that create,
update, or delete resources in your account.
|
LookupEventsResult |
lookupEvents(LookupEventsRequest lookupEventsRequest)
Looks up API activity events captured by CloudTrail that create,
update, or delete resources in your account.
|
RemoveTagsResult |
removeTags(RemoveTagsRequest removeTagsRequest)
Removes the specified tags from a trail.
|
void |
setEndpoint(String endpoint)
Overrides the default endpoint for this client ("https://cloudtrail.us-east-1.amazonaws.com").
|
void |
setEndpoint(String endpoint,
String serviceName,
String regionId) |
StartLoggingResult |
startLogging(StartLoggingRequest startLoggingRequest)
Starts the recording of AWS API calls and log file delivery for a
trail.
|
StopLoggingResult |
stopLogging(StopLoggingRequest stopLoggingRequest)
Suspends the recording of AWS API calls and log file delivery for the
specified trail.
|
UpdateTrailResult |
updateTrail(UpdateTrailRequest updateTrailRequest)
Updates the settings that specify delivery of log files.
|
addRequestHandler, addRequestHandler, beforeMarshalling, configSigner, configSigner, configureRegion, createExecutionContext, createExecutionContext, createExecutionContext, endClientExecution, endClientExecution, findRequestMetricCollector, getRequestMetricsCollector, getServiceAbbreviation, getServiceName, getServiceNameIntern, getSigner, getSignerByURI, getSignerRegionOverride, getTimeOffset, isProfilingEnabled, isRequestMetricsEnabled, removeRequestHandler, removeRequestHandler, requestMetricCollector, setEndpointPrefix, setRegion, setServiceNameIntern, setSignerRegionOverride, setTimeOffset, shutdown, withEndpoint, withRegion, withRegion, withTimeOffsetclone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitsetRegion, shutdownprotected List<com.amazonaws.transform.JsonErrorUnmarshaller> jsonErrorUnmarshallers
public AWSCloudTrailClient()
All service calls made using this new client object are blocking, and will not return until the service call completes.
DefaultAWSCredentialsProviderChainpublic AWSCloudTrailClient(ClientConfiguration clientConfiguration)
All service calls made using this new client object are blocking, and will not return until the service call completes.
clientConfiguration - The client configuration options controlling how this
client connects to AWSCloudTrail
(ex: proxy settings, retry counts, etc.).DefaultAWSCredentialsProviderChainpublic AWSCloudTrailClient(AWSCredentials awsCredentials)
All service calls made using this new client object are blocking, and will not return until the service call completes.
awsCredentials - The AWS credentials (access key ID and secret key) to use
when authenticating with AWS services.public AWSCloudTrailClient(AWSCredentials awsCredentials, ClientConfiguration clientConfiguration)
All service calls made using this new client object are blocking, and will not return until the service call completes.
awsCredentials - The AWS credentials (access key ID and secret key) to use
when authenticating with AWS services.clientConfiguration - The client configuration options controlling how this
client connects to AWSCloudTrail
(ex: proxy settings, retry counts, etc.).public AWSCloudTrailClient(AWSCredentialsProvider awsCredentialsProvider)
All service calls made using this new client object are blocking, and will not return until the service call completes.
awsCredentialsProvider - The AWS credentials provider which will provide credentials
to authenticate requests with AWS services.public AWSCloudTrailClient(AWSCredentialsProvider awsCredentialsProvider, ClientConfiguration clientConfiguration)
All service calls made using this new client object are blocking, and will not return until the service call completes.
awsCredentialsProvider - The AWS credentials provider which will provide credentials
to authenticate requests with AWS services.clientConfiguration - The client configuration options controlling how this
client connects to AWSCloudTrail
(ex: proxy settings, retry counts, etc.).public AWSCloudTrailClient(AWSCredentialsProvider awsCredentialsProvider, ClientConfiguration clientConfiguration, RequestMetricCollector requestMetricCollector)
All service calls made using this new client object are blocking, and will not return until the service call completes.
awsCredentialsProvider - The AWS credentials provider which will provide credentials
to authenticate requests with AWS services.clientConfiguration - The client configuration options controlling how this
client connects to AWSCloudTrail
(ex: proxy settings, retry counts, etc.).requestMetricCollector - optional request metric collectorpublic ListTagsResult listTags(ListTagsRequest listTagsRequest)
Lists the tags for the trail in the current region.
listTags in interface AWSCloudTraillistTagsRequest - Container for the necessary parameters to
execute the ListTags service method on AWSCloudTrail.ResourceTypeNotSupportedExceptionResourceNotFoundExceptionUnsupportedOperationExceptionCloudTrailARNInvalidExceptionInvalidTrailNameExceptionInvalidTokenExceptionOperationNotPermittedExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public GetTrailStatusResult getTrailStatus(GetTrailStatusRequest getTrailStatusRequest)
Returns a JSON-formatted list of information about the specified trail. Fields include information on delivery errors, Amazon SNS and Amazon S3 errors, and start and stop logging times for each trail. This operation returns trail status from a single region. To return trail status from all regions, you must call the operation on each region.
getTrailStatus in interface AWSCloudTrailgetTrailStatusRequest - Container for the necessary parameters to
execute the GetTrailStatus service method on AWSCloudTrail.InvalidTrailNameExceptionTrailNotFoundExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public RemoveTagsResult removeTags(RemoveTagsRequest removeTagsRequest)
Removes the specified tags from a trail.
removeTags in interface AWSCloudTrailremoveTagsRequest - Container for the necessary parameters to
execute the RemoveTags service method on AWSCloudTrail.ResourceTypeNotSupportedExceptionResourceNotFoundExceptionUnsupportedOperationExceptionCloudTrailARNInvalidExceptionInvalidTrailNameExceptionInvalidTagParameterExceptionOperationNotPermittedExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public DeleteTrailResult deleteTrail(DeleteTrailRequest deleteTrailRequest)
Deletes a trail. This operation must be called from the region in which the trail was created.
deleteTrail in interface AWSCloudTraildeleteTrailRequest - Container for the necessary parameters to
execute the DeleteTrail service method on AWSCloudTrail.InvalidTrailNameExceptionTrailNotFoundExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public LookupEventsResult lookupEvents(LookupEventsRequest lookupEventsRequest)
Looks up API activity events captured by CloudTrail that create, update, or delete resources in your account. Events for a region can be looked up for the times in which you had CloudTrail turned on in that region during the last seven days. Lookup supports five different attributes: time range (defined by a start time and end time), user name, event name, resource type, and resource name. All attributes are optional. The maximum number of attributes that can be specified in any one lookup request are time range and one other attribute. The default number of results returned is 10, with a maximum of 50 possible. The response includes a token that you can use to get the next page of results.
IMPORTANT:The rate of lookup requests is limited to one per second per account. If this limit is exceeded, a throttling error occurs.
IMPORTANT:Events that occurred during the selected time range will not be available for lookup if CloudTrail logging was not enabled when the events occurred.
lookupEvents in interface AWSCloudTraillookupEventsRequest - Container for the necessary parameters to
execute the LookupEvents service method on AWSCloudTrail.InvalidMaxResultsExceptionInvalidNextTokenExceptionInvalidLookupAttributesExceptionInvalidTimeRangeExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public CreateTrailResult createTrail(CreateTrailRequest createTrailRequest)
Creates a trail that specifies the settings for delivery of log data to an Amazon S3 bucket.
createTrail in interface AWSCloudTrailcreateTrailRequest - Container for the necessary parameters to
execute the CreateTrail service method on AWSCloudTrail.InsufficientEncryptionPolicyExceptionInvalidTrailNameExceptionInvalidCloudWatchLogsLogGroupArnExceptionTrailAlreadyExistsExceptionInvalidS3BucketNameExceptionKmsKeyDisabledExceptionTrailNotProvidedExceptionInvalidSnsTopicNameExceptionS3BucketDoesNotExistExceptionUnsupportedOperationExceptionKmsKeyNotFoundExceptionInvalidS3PrefixExceptionInvalidCloudWatchLogsRoleArnExceptionMaximumNumberOfTrailsExceededExceptionInvalidKmsKeyIdExceptionInsufficientSnsTopicPolicyExceptionCloudWatchLogsDeliveryUnavailableExceptionOperationNotPermittedExceptionInsufficientS3BucketPolicyExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public UpdateTrailResult updateTrail(UpdateTrailRequest updateTrailRequest)
Updates the settings that specify delivery of log files. Changes to a trail do not require stopping the CloudTrail service. Use this action to designate an existing bucket for log delivery. If the existing bucket has previously been a target for CloudTrail log files, an IAM policy exists for the bucket.
updateTrail in interface AWSCloudTrailupdateTrailRequest - Container for the necessary parameters to
execute the UpdateTrail service method on AWSCloudTrail.InsufficientEncryptionPolicyExceptionInvalidTrailNameExceptionInvalidCloudWatchLogsLogGroupArnExceptionInvalidS3BucketNameExceptionKmsKeyDisabledExceptionTrailNotProvidedExceptionInvalidSnsTopicNameExceptionS3BucketDoesNotExistExceptionUnsupportedOperationExceptionKmsKeyNotFoundExceptionInvalidCloudWatchLogsRoleArnExceptionInvalidS3PrefixExceptionInvalidKmsKeyIdExceptionInsufficientSnsTopicPolicyExceptionCloudWatchLogsDeliveryUnavailableExceptionOperationNotPermittedExceptionTrailNotFoundExceptionInsufficientS3BucketPolicyExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public StopLoggingResult stopLogging(StopLoggingRequest stopLoggingRequest)
Suspends the recording of AWS API calls and log file delivery for the specified trail. Under most circumstances, there is no need to use this action. You can update a trail without stopping it first. This action is the only way to stop recording.
stopLogging in interface AWSCloudTrailstopLoggingRequest - Container for the necessary parameters to
execute the StopLogging service method on AWSCloudTrail.InvalidTrailNameExceptionTrailNotFoundExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public DescribeTrailsResult describeTrails(DescribeTrailsRequest describeTrailsRequest)
Retrieves settings for the trail associated with the current region for your account.
describeTrails in interface AWSCloudTraildescribeTrailsRequest - Container for the necessary parameters to
execute the DescribeTrails service method on AWSCloudTrail.UnsupportedOperationExceptionOperationNotPermittedExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public ListPublicKeysResult listPublicKeys(ListPublicKeysRequest listPublicKeysRequest)
Returns all public keys whose private keys were used to sign the digest files within the specified time range. The public key is needed to validate digest files that were signed with its corresponding private key.
NOTE:CloudTrail uses different private/public key pairs per region. Each digest file is signed with a private key unique to its region. Therefore, when you validate a digest file from a particular region, you must look in the same region for its corresponding public key.
listPublicKeys in interface AWSCloudTraillistPublicKeysRequest - Container for the necessary parameters to
execute the ListPublicKeys service method on AWSCloudTrail.UnsupportedOperationExceptionInvalidTokenExceptionOperationNotPermittedExceptionInvalidTimeRangeExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public AddTagsResult addTags(AddTagsRequest addTagsRequest)
Adds one or more tags to a trail, up to a limit of 10. Tags must be unique per trail. Overwrites an existing tag's value when a new value is specified for an existing tag key. If you specify a key without a value, the tag will be created with the specified key and a value of null.
addTags in interface AWSCloudTrailaddTagsRequest - Container for the necessary parameters to
execute the AddTags service method on AWSCloudTrail.ResourceTypeNotSupportedExceptionTagsLimitExceededExceptionResourceNotFoundExceptionUnsupportedOperationExceptionCloudTrailARNInvalidExceptionInvalidTrailNameExceptionInvalidTagParameterExceptionOperationNotPermittedExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public StartLoggingResult startLogging(StartLoggingRequest startLoggingRequest)
Starts the recording of AWS API calls and log file delivery for a trail.
startLogging in interface AWSCloudTrailstartLoggingRequest - Container for the necessary parameters to
execute the StartLogging service method on AWSCloudTrail.InvalidTrailNameExceptionTrailNotFoundExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public LookupEventsResult lookupEvents() throws AmazonServiceException, AmazonClientException
Looks up API activity events captured by CloudTrail that create, update, or delete resources in your account. Events for a region can be looked up for the times in which you had CloudTrail turned on in that region during the last seven days. Lookup supports five different attributes: time range (defined by a start time and end time), user name, event name, resource type, and resource name. All attributes are optional. The maximum number of attributes that can be specified in any one lookup request are time range and one other attribute. The default number of results returned is 10, with a maximum of 50 possible. The response includes a token that you can use to get the next page of results.
IMPORTANT:The rate of lookup requests is limited to one per second per account. If this limit is exceeded, a throttling error occurs.
IMPORTANT:Events that occurred during the selected time range will not be available for lookup if CloudTrail logging was not enabled when the events occurred.
lookupEvents in interface AWSCloudTrailInvalidMaxResultsExceptionInvalidNextTokenExceptionInvalidLookupAttributesExceptionInvalidTimeRangeExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public DescribeTrailsResult describeTrails() throws AmazonServiceException, AmazonClientException
Retrieves settings for the trail associated with the current region for your account.
describeTrails in interface AWSCloudTrailUnsupportedOperationExceptionOperationNotPermittedExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public ListPublicKeysResult listPublicKeys() throws AmazonServiceException, AmazonClientException
Returns all public keys whose private keys were used to sign the digest files within the specified time range. The public key is needed to validate digest files that were signed with its corresponding private key.
NOTE:CloudTrail uses different private/public key pairs per region. Each digest file is signed with a private key unique to its region. Therefore, when you validate a digest file from a particular region, you must look in the same region for its corresponding public key.
listPublicKeys in interface AWSCloudTrailUnsupportedOperationExceptionInvalidTokenExceptionOperationNotPermittedExceptionInvalidTimeRangeExceptionAmazonClientException - If any internal errors are encountered inside the client while
attempting to make the request or handle the response. For example
if a network connection is not available.AmazonServiceException - If an error response is returned by AWSCloudTrail indicating
either a problem with the data in the request, or a server side issue.public void setEndpoint(String endpoint)
AWSCloudTrail
Callers can pass in just the endpoint (ex: "cloudtrail.us-east-1.amazonaws.com") or a full
URL, including the protocol (ex: "https://cloudtrail.us-east-1.amazonaws.com"). If the
protocol is not specified here, the default protocol from this client's
ClientConfiguration will be used, which by default is HTTPS.
For more information on using AWS regions with the AWS SDK for Java, and a complete list of all available endpoints for all AWS services, see: http://developer.amazonwebservices.com/connect/entry.jspa?externalID=3912
This method is not threadsafe. An endpoint should be configured when the client is created and before any service requests are made. Changing it afterwards creates inevitable race conditions for any service requests in transit or retrying.
setEndpoint in interface AWSCloudTrailsetEndpoint in class AmazonWebServiceClientendpoint - The endpoint (ex: "cloudtrail.us-east-1.amazonaws.com") or a full URL,
including the protocol (ex: "https://cloudtrail.us-east-1.amazonaws.com") of
the region specific AWS endpoint this client will communicate
with.public void setEndpoint(String endpoint, String serviceName, String regionId) throws IllegalArgumentException
setEndpoint in class AmazonWebServiceClientIllegalArgumentExceptionpublic ResponseMetadata getCachedResponseMetadata(AmazonWebServiceRequest request)
Response metadata is only cached for a limited period of time, so if you need to access this extra diagnostic information for an executed request, you should use this method to retrieve it as soon as possible after executing the request.
getCachedResponseMetadata in interface AWSCloudTrailrequest - The originally executed requestCopyright © 2015. All rights reserved.