Skip to content

Service: cloudtrail

Attached Policies

Policy ARN Policy Name
arn:aws:iam::aws:policy/ReadOnlyAccess ReadOnlyAccess
arn:aws:iam::aws:policy/SecurityAudit SecurityAudit
arn:aws:iam::aws:policy/AWSConfigUserAccess AWSConfigUserAccess
arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryFullAccess AmazonEC2ContainerRegistryFullAccess
arn:aws:iam::aws:policy/job-function/ViewOnlyAccess ViewOnlyAccess
arn:aws:iam::aws:policy/job-function/SupportUser SupportUser
arn:aws:iam::aws:policy/job-function/SystemAdministrator SystemAdministrator
arn:aws:iam::aws:policy/aws-service-role/AWSTrustedAdvisorServiceRolePolicy AWSTrustedAdvisorServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/AWSConfigServiceRolePolicy AWSConfigServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/CloudTrailServiceRolePolicy CloudTrailServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/AWSSecurityHubServiceRolePolicy AWSSecurityHubServiceRolePolicy
arn:aws:iam::aws:policy/service-role/AWSControlTowerServiceRolePolicy AWSControlTowerServiceRolePolicy
arn:aws:iam::aws:policy/AWSLakeFormationDataAdmin AWSLakeFormationDataAdmin
arn:aws:iam::aws:policy/AWSCodePipeline_FullAccess AWSCodePipeline_FullAccess
arn:aws:iam::aws:policy/service-role/AWS_ConfigRole AWS_ConfigRole
arn:aws:iam::aws:policy/AWSCloudTrail_FullAccess AWSCloudTrail_FullAccess
arn:aws:iam::aws:policy/aws-service-role/AWSSupportServiceRolePolicy AWSSupportServiceRolePolicy
arn:aws:iam::aws:policy/AwsGlueDataBrewFullAccessPolicy AwsGlueDataBrewFullAccessPolicy
arn:aws:iam::aws:policy/aws-service-role/AmazonDevOpsGuruServiceRolePolicy AmazonDevOpsGuruServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/AWSAuditManagerServiceRolePolicy AWSAuditManagerServiceRolePolicy
arn:aws:iam::aws:policy/AWSElasticBeanstalkReadOnly AWSElasticBeanstalkReadOnly
arn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalk AdministratorAccess-AWSElasticBeanstalk
arn:aws:iam::aws:policy/AWSCompromisedKeyQuarantineV2 AWSCompromisedKeyQuarantineV2
arn:aws:iam::aws:policy/aws-service-role/AmazonRDSCustomServiceRolePolicy AmazonRDSCustomServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/AmazonRDSCustomPreviewServiceRolePolicy AmazonRDSCustomPreviewServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/AmazonInspector2ServiceRolePolicy AmazonInspector2ServiceRolePolicy
arn:aws:iam::aws:policy/AmazonCloudWatchEvidentlyFullAccess AmazonCloudWatchEvidentlyFullAccess
arn:aws:iam::aws:policy/AWSCloudTrail_ReadOnlyAccess AWSCloudTrail_ReadOnlyAccess
arn:aws:iam::aws:policy/aws-service-role/AWSResourceExplorerServiceRolePolicy AWSResourceExplorerServiceRolePolicy
arn:aws:iam::aws:policy/aws-service-role/SecurityLakeServiceLinkedRole SecurityLakeServiceLinkedRole
arn:aws:iam::aws:policy/service-role/ROSASRESupportPolicy ROSASRESupportPolicy
arn:aws:iam::aws:policy/AWSCompromisedKeyQuarantineV3 AWSCompromisedKeyQuarantineV3
arn:aws:iam::aws:policy/ResourceGroupsTaggingAPITagUntagSupportedResources ResourceGroupsTaggingAPITagUntagSupportedResources
arn:aws:iam::aws:policy/AWSPartnerLedSupportReadOnlyAccess AWSPartnerLedSupportReadOnlyAccess
arn:aws:iam::aws:policy/AIOpsAssistantPolicy AIOpsAssistantPolicy
arn:aws:iam::aws:policy/AIOpsConsoleAdminPolicy AIOpsConsoleAdminPolicy

Allowed Actions

Action Service
cloudtrail:* cloudtrail
cloudtrail:AddTags cloudtrail
cloudtrail:CreateServiceLinkedChannel cloudtrail
cloudtrail:CreateTrail cloudtrail
cloudtrail:DeleteServiceLinkedChannel cloudtrail
cloudtrail:DeleteTrail cloudtrail
cloudtrail:Describe* cloudtrail
cloudtrail:DescribeTrails cloudtrail
cloudtrail:Get* cloudtrail
cloudtrail:GetChannel cloudtrail
cloudtrail:GetEventDataStore cloudtrail
cloudtrail:GetEventSelectors cloudtrail
cloudtrail:GetInsightSelectors cloudtrail
cloudtrail:GetQueryResults cloudtrail
cloudtrail:GetResourcePolicy cloudtrail
cloudtrail:GetServiceLinkedChannel cloudtrail
cloudtrail:GetTrail cloudtrail
cloudtrail:GetTrailStatus cloudtrail
cloudtrail:List* cloudtrail
cloudtrail:ListChannels cloudtrail
cloudtrail:ListEventDataStores cloudtrail
cloudtrail:ListPublicKeys cloudtrail
cloudtrail:ListServiceLinkedChannels cloudtrail
cloudtrail:ListTags cloudtrail
cloudtrail:ListTrails cloudtrail
cloudtrail:LookupEvents cloudtrail
cloudtrail:PutEventSelectors cloudtrail
cloudtrail:RemoveTags cloudtrail
cloudtrail:StartLogging cloudtrail
cloudtrail:StartQuery cloudtrail
cloudtrail:StopLogging cloudtrail
cloudtrail:UpdateServiceLinkedChannel cloudtrail
cloudtrail:UpdateTrail cloudtrail
cloudtrail:describeTrails cloudtrail
cloudtrail:getEventSelectors cloudtrail
cloudtrail:getInsightSelectors cloudtrail
cloudtrail:getTrail cloudtrail
cloudtrail:getTrailStatus cloudtrail
cloudtrail:listPublicKeys cloudtrail
cloudtrail:listTags cloudtrail
cloudtrail:listTrails cloudtrail
cloudtrail:lookupEvents cloudtrail