JAEN

Cloud

aws cloudtrail lookup-events

SafeWho did what (CloudTrail)

aws cloudtrail lookup-events --lookup-attributes AttributeKey=ResourceName,AttributeValue=<res>

Traces API calls — the primary source for 'who deleted that and when' investigations.

Examples

  • aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=TerminateInstancesTermination history

Syntax

aws cloudtrail lookup-events [--lookup-attributes k=v] [--start-time t]

Before you run it

Read only.

Related commands

The same reference, with no signal at all

Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.

Get it free on the App Store