aws cloudtrail lookup-events
SafeWho did what (CloudTrail)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=ResourceName,AttributeValue=<res>
Traces API calls — the primary source for 'who deleted that and when' investigations.
Examples
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=TerminateInstancesTermination history
Syntax
aws cloudtrail lookup-events [--lookup-attributes k=v] [--start-time t]
Before you run it
Read only.
Related commands
- az monitor activity-log listQuery the activity log
- aws iam list-usersAudit IAM users/keys
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store