D      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./01 2 3 4 5 6 7 8 9 : ; < = > ? @ A B C D E F G H I J K L M N O P Q R S T U V W X Y Z [ \ ] ^ _ ` a b c d e f g h i j k l m n o p q r s t u v w x y z { | } ~                                                                    (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None05[              (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None!"058 The settings for a trail.See: 4 smart constructor. NA custom key-value pair associated with a resource such as a CloudTrail trail.See: 1 smart constructor. A resource tag.See: . smart constructor.ASpecifies the type and name of a resource referenced by an event.See: + smart constructor.1Contains information about a returned public key.See: & smart constructor.ASpecifies an attribute and value that filter the events returned.See: # smart constructor.oUse event selectors to specify whether you want your trail to log management and/or data events. When an event occurs in your account, CloudTrail evaluates the event selector for all trails. For each trail, if the event matches any event selector, the trail processes and logs the event. If the event doesn't match any event selector, the trail doesn't log the event.9You can configure up to five event selectors for a trail.See:  smart constructor.Contains information about an event that was returned by a lookup request. The result includes a representation of a CloudTrail event.See:  smart constructor.The Amazon S3 objects that you specify in your event selectors for your trail to log data events. Data events are object-level API operations that access S3 objects, such as  GetObject ,  DeleteObject , and  PutObjectH . You can specify up to 250 S3 buckets and object prefixes for a trail.Example_You create an event selector for a trail and specify an S3 bucket and an empty prefix, such as arn:aws:s3:::bucket-1/ .You upload an image file to bucket-1 .The  PutObject API operation occurs on an object in the S3 bucket that you specified in the event selector. The trail processes and logs the event.=You upload another image file to a different S3 bucket named arn:aws:s3:::bucket-2 .}The event occurs on an object in an S3 bucket that you didn't specify in the event selector. The trail doesn t log the event.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - A list of ARN-like strings for the specified S3 objects. To log data events for all objects in an S3 bucket, specify the bucket and an empty object prefix such as arn:aws:s3:::bucket-1/ . The trail logs data events for all objects in this S3 bucket. To log data events for specific objects, specify the S3 bucket and object prefix such as $arn:aws:s3:::bucket-1/example-imagesR . The trail logs data events for objects in this S3 bucket that match the prefix.e - The resource type in which you want to log data events. You can specify only the following value: AWS::S3::Object .A list of ARN-like strings for the specified S3 objects. To log data events for all objects in an S3 bucket, specify the bucket and an empty object prefix such as arn:aws:s3:::bucket-1/ . The trail logs data events for all objects in this S3 bucket. To log data events for specific objects, specify the S3 bucket and object prefix such as $arn:aws:s3:::bucket-1/example-imagesR . The trail logs data events for objects in this S3 bucket that match the prefix.bThe resource type in which you want to log data events. You can specify only the following value: AWS::S3::Object .Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:W - A user name or role name of the requester that called the API in the event returned.8 - A list of resources referenced by the event returned.+ - The date and time of the event returned.F - A JSON string that contains a representation of the event returned." - The name of the event returned.0 - The AWS service that the request was made to.+ - The CloudTrail ID of the event returned.TA user name or role name of the requester that called the API in the event returned.5A list of resources referenced by the event returned.(The date and time of the event returned.CA JSON string that contains a representation of the event returned.The name of the event returned.-The AWS service that the request was made to.(The CloudTrail ID of the event returned.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:  - CloudTrail supports logging only data events for S3 objects. You can specify up to 250 S3 buckets and object prefixes for a trail. For more information, see  http://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-management-and-data-events-with-cloudtrail.html#logging-data-events Data Events in the AWS CloudTrail User Guide .!k - Specify if you want your trail to log read-only events, write-only events, or all. For example, the EC2 GetConsoleOutput" is a read-only API operation and  RunInstances9 is a write-only API operation. By default, the value is All ."r - Specify if you want your event selector to include management events for your trail. For more information, see  http://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-management-and-data-events-with-cloudtrail.html#logging-management-eventsManagement Events in the AWS CloudTrail User Guide . By default, the value is true . CloudTrail supports logging only data events for S3 objects. You can specify up to 250 S3 buckets and object prefixes for a trail. For more information, see  http://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-management-and-data-events-with-cloudtrail.html#logging-data-events Data Events in the AWS CloudTrail User Guide .!hSpecify if you want your trail to log read-only events, write-only events, or all. For example, the EC2 GetConsoleOutput" is a read-only API operation and  RunInstances9 is a write-only API operation. By default, the value is All ."oSpecify if you want your event selector to include management events for your trail. For more information, see  http://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-management-and-data-events-with-cloudtrail.html#logging-management-eventsManagement Events in the AWS CloudTrail User Guide . By default, the value is true .#Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:$A - Specifies an attribute on which to filter the events returned.%4 - Specifies a value for the specified AttributeKey.$>Specifies an attribute on which to filter the events returned.%1Specifies a value for the specified AttributeKey.&Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:'% - The fingerprint of the public key.(1 - The ending time of validity of the public key.)8 - The DER encoded public key value in PKCS#1 format.-- Note: This Lens automatically encodes and decodes Base64 data. The underlying isomorphism will encode to Base64 representation during serialisation, and decode from Base64 representation during deserialisation. This Lens- accepts and returns only raw unencoded data.*3 - The starting time of validity of the public key.'"The fingerprint of the public key.(.The ending time of validity of the public key.)5The DER encoded public key value in PKCS#1 format.-- Note: This Lens automatically encodes and decodes Base64 data. The underlying isomorphism will encode to Base64 representation during serialisation, and decode from Base64 representation during deserialisation. This Lens- accepts and returns only raw unencoded data.*0The starting time of validity of the public key.+Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:, - The type of a resource referenced by the event returned. When the resource type cannot be determined, null is returned. Some examples of resource types are: Instance for EC2, Trail for CloudTrail,  DBInstance for RDS, and  AccessKeyG for IAM. For a list of resource types supported for event lookup, see  ]http://docs.aws.amazon.com/awscloudtrail/latest/userguide/lookup_supported_resourcetypes.html)Resource Types Supported for Event Lookup .- - The name of the resource referenced by the event returned. These are user-created names whose values will depend on the environment. For example, the resource name might be "auto-scaling-test-group" for an Auto Scaling Group or "i-1234567" for an EC2 Instance.,The type of a resource referenced by the event returned. When the resource type cannot be determined, null is returned. Some examples of resource types are: Instance for EC2, Trail for CloudTrail,  DBInstance for RDS, and  AccessKeyG for IAM. For a list of resource types supported for event lookup, see  ]http://docs.aws.amazon.com/awscloudtrail/latest/userguide/lookup_supported_resourcetypes.html)Resource Types Supported for Event Lookup .-The name of the resource referenced by the event returned. These are user-created names whose values will depend on the environment. For example, the resource name might be "auto-scaling-test-group" for an Auto Scaling Group or "i-1234567" for an EC2 Instance..Creates a value of  4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:/% - Specifies the ARN of the resource.0 - A list of tags./"Specifies the ARN of the resource.0A list of tags.1Creates a value of  4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:2c - The value in a key-value pair of a tag. The value must be no longer than 256 Unicode characters.3 - The key in a key-value pair. The key must be must be no longer than 128 Unicode characters. The key must be unique for the resource to which it applies.2`The value in a key-value pair of a tag. The value must be no longer than 256 Unicode characters.3The key in a key-value pair. The key must be must be no longer than 128 Unicode characters. The key must be unique for the resource to which it applies.4Creates a value of  4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:54 - Specifies whether log file validation is enabled.6A - Specifies the ARN of the trail. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail7 - Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files' .The maximum length is 200 characters.8 - Specifies the ARN of the Amazon SNS topic that CloudTrail uses to send notifications when log files are delivered. The format of a topic ARN is: *arn:aws:sns:us-east-1:123456789012:MyTopic9- - This field is deprecated. Use SnsTopicARN.: - Specifies an Amazon Resource Name (ARN), a unique identifier that represents the log group to which CloudTrail logs will be delivered.; - Specifies the KMS key ID that encrypts the logs delivered by CloudTrail. The value is a fully specified ARN to a KMS key in the format: Karn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012<- - The region in which the trail was created.=$ - Name of the trail set by calling  CreateTrail( . The maximum length is 128 characters.> - Set to TrueK to include AWS API calls from AWS global services such as IAM. Otherwise, False .?5 - Specifies if the trail has custom event selectors.@` - Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.AU - Name of the Amazon S3 bucket into which CloudTrail delivers your trail files. See  Yhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/create_trail_naming_policy.html$Amazon S3 Bucket Naming Requirements .BS - Specifies whether the trail belongs only to one region or exists in all regions.51Specifies whether log file validation is enabled.6>Specifies the ARN of the trail. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail7Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files' .The maximum length is 200 characters.8Specifies the ARN of the Amazon SNS topic that CloudTrail uses to send notifications when log files are delivered. The format of a topic ARN is: *arn:aws:sns:us-east-1:123456789012:MyTopic9*This field is deprecated. Use SnsTopicARN.:Specifies an Amazon Resource Name (ARN), a unique identifier that represents the log group to which CloudTrail logs will be delivered.;Specifies the KMS key ID that encrypts the logs delivered by CloudTrail. The value is a fully specified ARN to a KMS key in the format: Karn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012<*The region in which the trail was created.=!Name of the trail set by calling  CreateTrail( . The maximum length is 128 characters.>Set to TrueK to include AWS API calls from AWS global services such as IAM. Otherwise, False .?2Specifies if the trail has custom event selectors.@]Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.ARName of the Amazon S3 bucket into which CloudTrail delivers your trail files. See  Yhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/create_trail_naming_policy.html$Amazon S3 Bucket Naming Requirements .BPSpecifies whether the trail belongs only to one region or exists in all regions.  !"#$%&' ()* +,-./0123456789:;<=>?@ABCDEFG !"#$%$%&'()*+,-./01323456789:;<=>?@ABHIJKLMNOPQRSTUVWXYZ[\]^_`abcdeg  !"#$%&' ()* +,-./0123456789:;<=>?@ABCDEFG !"#$%&'()*+,-./0123456789:;<=>?@ABV  !"#$%&' ()* +,-./0123456789:;<=>?@ABCDEFG !"#$%&'()*+,-./0123456789:;<=>?@ABHIJKLMNOPQRSTUVWXYZ[\]^_`abcde(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None#C API version  2013-11-01, of the Amazon CloudTrail SDK configuration.DOccurs if the timestamp values are invalid. Either the start time occurs after the end time or the time range is outside the range of possible values.ELThis exception is thrown when the policy on the S3 bucket is not sufficient.FFThis exception is thrown when the maximum number of trails is reached.GGThis exception is thrown when the requested operation is not supported.HThis exception is deprecated.IWThis exception is thrown when the policy on the S3 bucket or KMS key is not sufficient.JLThis exception is thrown when the policy on the SNS topic is not sufficient.K=This exception is thrown when the provided role is not valid.L[The number of tags per trail has exceeded the permitted amount. Currently, the limit is 50.MmThis exception is thrown when an operation is called with an invalid trail ARN. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailN5Occurs when an invalid lookup attribute is specified.OuThis exception is thrown when the provided trail name is not valid. Trail names must meet the following requirements:aContain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-)>Start with a letter or number, and end with a letter or numberBe between 3 and 128 characters<Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespace are invalid.6Not be in IP address format (for example, 192.168.5.4)PGThis exception is thrown when the provided SNS topic name is not valid.QYThis exception is thrown when the specified resource type is not supported by CloudTrail.R6Cannot set a CloudWatch Logs delivery for this region.S{This exception is thrown when the KMS key does not exist, or when the S3 bucket and the KMS key are not in the same region.TIThis exception is thrown when the trail with the given name is not found.U"This exception is thrown when the PutEventSelectorst operation is called with an invalid number of event selectors, data resources, or an invalid value for a parameter:?Specify a valid number of event selectors (1 to 5) for a trail.JSpecify a valid number of data resources (1 to 250) for an event selector.CSpecify a valid value for a parameter. For example, specifying the  ReadWriteType parameter with a value of  read-only is invalid.VThis exception is deprecated.WGThis exception is thrown when the provided S3 bucket name is not valid.XMThis exception is thrown when the provided CloudWatch log group is not valid.YjThis exception is thrown when there is an issue with the specified KMS key and the trail can t be updated.ZEThis exception is thrown when the specified S3 bucket does not exist.[Invalid token or token that was previously used in a request with different parameters. This exception is thrown if the token is invalid.\kThis exception is thrown when the key or value specified for the tag does not match the regular expression ^([\p{L}\p{Z}\p{N}_.:/=+\-]*)$@ .]GThis exception is thrown when the requested operation is not permitted.^Reserved for future use._;This exception is thrown if the limit specified is invalid.`AThis exception is thrown when the specified trail already exists.aBThis exception is thrown when the provided S3 prefix is not valid.bBThis exception is thrown when the specified resource is not found.cRThis exception is thrown when the combination of parameters provided is not valid.d9This exception is thrown when the KMS key ARN is invalid.eThis exception is thrown when an operation is called on a trail from a region other than the region in which the trail was created.#CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdef  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcde  !"#$%&'()*+,- ./0 123 456789:;<=>?@AB#CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcde(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRfTReturns the objects or data listed below if successful. Otherwise, returns an error.See: s smart constructor.g+Specifies settings to update for the trail.See: h smart constructor.hCreates a value of g4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: i - Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files( . The maximum length is 200 characters.j - Specifies the name of the Amazon SNS topic defined for notification of log file delivery. The maximum length is 256 characters.kJ - Specifies whether log file validation is enabled. The default is false.l - Specifies a log group name using an Amazon Resource Name (ARN), a unique identifier that represents the log group to which CloudTrail logs will be delivered. Not required unless you specify CloudWatchLogsRoleArn.m - Specifies the KMS key ID to use to encrypt the logs delivered by CloudTrail. The value can be an alias name prefixed by "alias|", a fully specified ARN to an alias, a fully specified ARN to a key, or a globally unique identifier. Examples: * alias:MyAliasName * arn:aws:kms:us-east-1:123456789012:alias8MyAliasName * arn:aws:kms:us-east-1:123456789012:keyO12345678-1234-1234-1234-123456789012 * 12345678-1234-1234-1234-123456789012nf - Specifies whether the trail is publishing events from global services such as IAM to the log files.o` - Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.pW - Specifies the name of the Amazon S3 bucket designated for publishing log files. See  Yhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/create_trail_naming_policy.html$Amazon S3 Bucket Naming Requirements .q - Specifies whether the trail applies only to the current region or to all regions. The default is false. If the trail exists only in the current region and this value is set to true, shadow trails (replications of the trail) will be created in the other regions. If the trail exists in all regions and this value is set to false, the trail will remain in the region where it was created, and its shadow trails in other regions will be deleted.r4 - Specifies the name of the trail or trail ARN. If NameX is a trail name, the string must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespaceN are invalid. * Not be in IP address format (for example, 192.168.5.4) If Name+ is a trail ARN, it must be in the format: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailiSpecifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files( . The maximum length is 200 characters.jSpecifies the name of the Amazon SNS topic defined for notification of log file delivery. The maximum length is 256 characters.kGSpecifies whether log file validation is enabled. The default is false.lSpecifies a log group name using an Amazon Resource Name (ARN), a unique identifier that represents the log group to which CloudTrail logs will be delivered. Not required unless you specify CloudWatchLogsRoleArn.m~Specifies the KMS key ID to use to encrypt the logs delivered by CloudTrail. The value can be an alias name prefixed by "alias|", a fully specified ARN to an alias, a fully specified ARN to a key, or a globally unique identifier. Examples: * alias:MyAliasName * arn:aws:kms:us-east-1:123456789012:alias8MyAliasName * arn:aws:kms:us-east-1:123456789012:keyO12345678-1234-1234-1234-123456789012 * 12345678-1234-1234-1234-123456789012ncSpecifies whether the trail is publishing events from global services such as IAM to the log files.o]Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.pTSpecifies the name of the Amazon S3 bucket designated for publishing log files. See  Yhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/create_trail_naming_policy.html$Amazon S3 Bucket Naming Requirements .qSpecifies whether the trail applies only to the current region or to all regions. The default is false. If the trail exists only in the current region and this value is set to true, shadow trails (replications of the trail) will be created in the other regions. If the trail exists in all regions and this value is set to false, the trail will remain in the region where it was created, and its shadow trails in other regions will be deleted.r1Specifies the name of the trail or trail ARN. If NameX is a trail name, the string must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespaceN are invalid. * Not be in IP address format (for example, 192.168.5.4) If Name+ is a trail ARN, it must be in the format: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailsCreates a value of f4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: t> - Specifies whether log file integrity validation is enabled.uR - Specifies the ARN of the trail that was updated. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailv - Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files .w - Specifies the ARN of the Amazon SNS topic that CloudTrail uses to send notifications when log files are delivered. The format of a topic ARN is: *arn:aws:sns:us-east-1:123456789012:MyTopicx- - This field is deprecated. Use SnsTopicARN.yh - Specifies the Amazon Resource Name (ARN) of the log group to which CloudTrail logs will be delivered.z - Specifies the KMS key ID that encrypts the logs delivered by CloudTrail. The value is a fully specified ARN to a KMS key in the format: Karn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012{# - Specifies the name of the trail.|f - Specifies whether the trail is publishing events from global services such as IAM to the log files.}` - Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.~R - Specifies the name of the Amazon S3 bucket designated for publishing log files.F - Specifies whether the trail exists in one region or in all regions.! - -- | The response status code.t;Specifies whether log file integrity validation is enabled.uOSpecifies the ARN of the trail that was updated. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailvSpecifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files .wSpecifies the ARN of the Amazon SNS topic that CloudTrail uses to send notifications when log files are delivered. The format of a topic ARN is: *arn:aws:sns:us-east-1:123456789012:MyTopicx*This field is deprecated. Use SnsTopicARN.yeSpecifies the Amazon Resource Name (ARN) of the log group to which CloudTrail logs will be delivered.zSpecifies the KMS key ID that encrypts the logs delivered by CloudTrail. The value is a fully specified ARN to a KMS key in the format: Karn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012{ Specifies the name of the trail.|cSpecifies whether the trail is publishing events from global services such as IAM to the log files.}]Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.~OSpecifies the name of the Amazon S3 bucket designated for publishing log files.CSpecifies whether the trail exists in one region or in all regions.- | The response status code.<ffghijklmnopqrsgtuvwxyz{|}~hrijklmnopqrstuvwxyz{|}~fghijklmnopqrstuvwxyz{|}~hgijklmnopqrsftuvwxyz{|}~#ffghijklmnopqrsg tuvwxyz{|}~hijklmnopqrstuvwxyz{|}~(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)NoneDR(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.YPasses the request to CloudTrail to stop logging AWS API calls for the specified account.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Specifies the name or the CloudTrail ARN of the trail for which CloudTrail will stop logging AWS API calls. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailSpecifies the name or the CloudTrail ARN of the trail for which CloudTrail will stop logging AWS API calls. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailCreates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:! - -- | The response status code.- | The response status code.(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.HThe request to CloudTrail to start logging AWS API calls for an account.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Specifies the name or the CloudTrail ARN of the trail for which CloudTrail logs AWS API calls. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail}Specifies the name or the CloudTrail ARN of the trail for which CloudTrail logs AWS API calls. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailCreates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:! - -- | The response status code.- | The response status code.(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.*Specifies the tags to remove from a trail.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:* - Specifies a list of tags to be removed.c - Specifies the ARN of the trail from which tags should be removed. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail'Specifies a list of tags to be removed.`Specifies the ARN of the trail from which tags should be removed. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailCreates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:! - -- | The response status code.- | The response status code.(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DR See:  smart constructor.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Specifies the name of the trail or trail ARN. If you specify a trail name, the string must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespace are invalid. * Not be in IP address format (for example, 192.168.5.4) If you specify a trail ARN, it must be in the format: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailm - Specifies the settings for your event selectors. You can configure up to five event selectors for a trail.Specifies the name of the trail or trail ARN. If you specify a trail name, the string must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespace are invalid. * Not be in IP address format (for example, 192.168.5.4) If you specify a trail ARN, it must be in the format: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailjSpecifies the settings for your event selectors. You can configure up to five event selectors for a trail.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:g - Specifies the ARN of the trail that was updated with event selectors. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail; - Specifies the event selectors configured for your trail.! - -- | The response status code.dSpecifies the ARN of the trail that was updated with event selectors. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail8Specifies the event selectors configured for your trail.- | The response status code. (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DR -Contains a response to a LookupEvents action.See:  smart constructor.$Contains a request for LookupEvents.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Specifies that only events that occur after or at the specified time are returned. If the specified start time is after the specified end time, an error is returned.V - Contains a list of lookup attributes. Currently the list can contain only one item. - The token to use to get the next page of results after a previous API call. This token must be passed in with the same parameters that were specified in the the original call. For example, if the original call specified an AttributeKey of   with a value of root?, the call with NextToken should include those same parameters. - Specifies that only events that occur before or at the specified time are returned. If the specified end time is before the specified start time, an error is returned.W - The number of events to return. Possible values are 1 through 50. The default is 10.Specifies that only events that occur after or at the specified time are returned. If the specified start time is after the specified end time, an error is returned.SContains a list of lookup attributes. Currently the list can contain only one item.The token to use to get the next page of results after a previous API call. This token must be passed in with the same parameters that were specified in the the original call. For example, if the original call specified an AttributeKey of   with a value of root?, the call with NextToken should include those same parameters.Specifies that only events that occur before or at the specified time are returned. If the specified end time is before the specified start time, an error is returned.TThe number of events to return. Possible values are 1 through 50. The default is 10.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - The token to use to get the next page of results after a previous API call. If the token does not appear, there are no more results to return. The token must be passed in with the same parameters as the previous call. For example, if the original call specified an AttributeKey of   with a value of root?, the call with NextToken should include those same parameters. - A list of events returned based on the lookup attributes specified and the CloudTrail event. The events list is sorted by time. The most recent event is listed first.! - -- | The response status code.The token to use to get the next page of results after a previous API call. If the token does not appear, there are no more results to return. The token must be passed in with the same parameters as the previous call. For example, if the original call specified an AttributeKey of   with a value of root?, the call with NextToken should include those same parameters.A list of events returned based on the lookup attributes specified and the CloudTrail event. The events list is sorted by time. The most recent event is listed first.- | The response status code.       (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DR TReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.)Specifies a list of trail tags to return.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Reserved for future use.| - Specifies a list of trail ARNs whose tags will be listed. The list has a limit of 20 ARNs. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailReserved for future use.ySpecifies a list of trail ARNs whose tags will be listed. The list has a limit of 20 ARNs. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailCreates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Reserved for future use. - A list of resource tags.! - -- | The response status code.Reserved for future use.A list of resource tags.- | The response status code. !"#$%&   !"#$%& (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DR 1TReturns the objects or data listed below if successful. Otherwise, returns an error.See: 7 smart constructor.24Requests the public keys for a specified time range.See: 3 smart constructor.3Creates a value of 24 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:4 - Optionally specifies, in UTC, the start of the time range to look up public keys for CloudTrail digest files. If not specified, the current time is used, and the current public key is returned.5 - Reserved for future use.6 - Optionally specifies, in UTC, the end of the time range to look up public keys for CloudTrail digest files. If not specified, the current time is used.4Optionally specifies, in UTC, the start of the time range to look up public keys for CloudTrail digest files. If not specified, the current time is used, and the current public key is returned.5Reserved for future use.6Optionally specifies, in UTC, the end of the time range to look up public keys for CloudTrail digest files. If not specified, the current time is used.7Creates a value of 14 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:8* - Contains an array of PublicKey objects.9 - Reserved for future use.:! - -- | The response status code.8'Contains an array of PublicKey objects.9Reserved for future use.:- | The response status code.1234567:89:;<=>?@AB 123456789: 324567189:123456789:;<=>?@AB (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRMTReturns the objects or data listed below if successful. Otherwise, returns an error.See: Q smart constructor.N<The name of a trail about which you want the current status.See: O smart constructor.OCreates a value of N4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:P - Specifies the name or the CloudTrail ARN of the trail for which you are requesting status. To get the status of a shadow trail (a replication of the trail in another region), you must specify its ARN. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailPSpecifies the name or the CloudTrail ARN of the trail for which you are requesting status. To get the status of a shadow trail (a replication of the trail in another region), you must specify its ARN. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailQCreates a value of M4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:R - This field is deprecated.S - Displays any Amazon S3 error that CloudTrail encountered when attempting to deliver log files to the designated bucket. For more information see the topic  Bhttp://docs.aws.amazon.com/AmazonS3/latest/API/ErrorResponses.htmlError Responses in the Amazon S3 API Reference.Tm - Specifies the date and time that CloudTrail last delivered a digest file to an account's Amazon S3 bucket.U - This field is deprecated.Vj - Specifies the most recent date and time when CloudTrail started recording API calls for an AWS account.W - Displays any Amazon SNS error that CloudTrail encountered when attempting to send a notification. For more information about Amazon SNS errors, see the  5http://docs.aws.amazon.com/sns/latest/dg/welcome.htmlAmazon SNS Developer Guide .X - This field is deprecated.Y= - Whether the CloudTrail is currently logging AWS API calls.Z - This field is deprecated.[ - Displays any Amazon S3 error that CloudTrail encountered when attempting to deliver a digest file to the designated bucket. For more information see the topic  Bhttp://docs.aws.amazon.com/AmazonS3/latest/API/ErrorResponses.htmlError Responses in the Amazon S3 API Reference.\ - This field is deprecated.]i - Specifies the date and time that CloudTrail last delivered log files to an account's Amazon S3 bucket.^\ - Displays the most recent date and time when CloudTrail delivered logs to CloudWatch Logs._u - Displays any CloudWatch Logs error that CloudTrail encountered when attempting to deliver logs to CloudWatch Logs.` - Specifies the date and time of the most recent Amazon SNS notification that CloudTrail has written a new log file to an account's Amazon S3 bucket.a - This field is deprecated.bj - Specifies the most recent date and time when CloudTrail stopped recording API calls for an AWS account.c! - -- | The response status code.RThis field is deprecated.SDisplays any Amazon S3 error that CloudTrail encountered when attempting to deliver log files to the designated bucket. For more information see the topic  Bhttp://docs.aws.amazon.com/AmazonS3/latest/API/ErrorResponses.htmlError Responses in the Amazon S3 API Reference.TjSpecifies the date and time that CloudTrail last delivered a digest file to an account's Amazon S3 bucket.UThis field is deprecated.VgSpecifies the most recent date and time when CloudTrail started recording API calls for an AWS account.WDisplays any Amazon SNS error that CloudTrail encountered when attempting to send a notification. For more information about Amazon SNS errors, see the  5http://docs.aws.amazon.com/sns/latest/dg/welcome.htmlAmazon SNS Developer Guide .XThis field is deprecated.Y:Whether the CloudTrail is currently logging AWS API calls.ZThis field is deprecated.[Displays any Amazon S3 error that CloudTrail encountered when attempting to deliver a digest file to the designated bucket. For more information see the topic  Bhttp://docs.aws.amazon.com/AmazonS3/latest/API/ErrorResponses.htmlError Responses in the Amazon S3 API Reference.\This field is deprecated.]fSpecifies the date and time that CloudTrail last delivered log files to an account's Amazon S3 bucket.^YDisplays the most recent date and time when CloudTrail delivered logs to CloudWatch Logs._rDisplays any CloudWatch Logs error that CloudTrail encountered when attempting to deliver logs to CloudWatch Logs.`Specifies the date and time of the most recent Amazon SNS notification that CloudTrail has written a new log file to an account's Amazon S3 bucket.aThis field is deprecated.bgSpecifies the most recent date and time when CloudTrail stopped recording API calls for an AWS account.c- | The response status code.4MNOPPQcRSTUVWXYZ[\]^_`abcdefghijkMNOPQRSTUVWXYZ[\]^_`abcONPQMRSTUVWXYZ[\]^_`abcMNOPQRSTUVWXYZ[\]^_`abcdefghijk (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRvSee: z smart constructor.wSee: x smart constructor.xCreates a value of w4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:y - Specifies the name of the trail or trail ARN. If you specify a trail name, the string must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespace are invalid. * Not be in IP address format (for example, 192.168.5.4) If you specify a trail ARN, it must be in the format: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailySpecifies the name of the trail or trail ARN. If you specify a trail name, the string must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespace are invalid. * Not be in IP address format (for example, 192.168.5.4) If you specify a trail ARN, it must be in the format: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailzCreates a value of v4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:{8 - The specified trail ARN that has the event selectors.|9 - The event selectors that are configured for the trail.}! - -- | The response status code.{5The specified trail ARN that has the event selectors.|6The event selectors that are configured for the trail.}- | The response status code.vwxyyz}{|}~vwxyz{|}xwyzv{|}vwxyz{|}~ (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.$Returns information about the trail.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - Specifies whether to include shadow trails in the response. A shadow trail is the replication in a region of a trail that was created in a different region. The default is true.r - Specifies a list of trail names, trail ARNs, or both, of the trails to describe. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail If an empty list is specified, information for the trail in the current region is returned. * If an empty list is specified and IncludeShadowTrails is false, then information for all trails in the current region is returned. * If an empty list is specified and IncludeShadowTrails is null or true, then information for all trails in the current region and any associated shadow trails in other regions is returned.Specifies whether to include shadow trails in the response. A shadow trail is the replication in a region of a trail that was created in a different region. The default is true.oSpecifies a list of trail names, trail ARNs, or both, of the trails to describe. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail If an empty list is specified, information for the trail in the current region is returned. * If an empty list is specified and IncludeShadowTrails is false, then information for all trails in the current region is returned. * If an empty list is specified and IncludeShadowTrails is null or true, then information for all trails in the current region and any associated shadow trails in other regions is returned.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: - The list of trail objects.! - -- | The response status code.The list of trail objects.- | The response status code. (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.9The request that specifies the name of a trail to delete.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:f - Specifies the name or the CloudTrail ARN of the trail to be deleted. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailcSpecifies the name or the CloudTrail ARN of the trail to be deleted. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailCreates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:! - -- | The response status code.- | The response status code.(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.&Specifies the settings for each trail.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:  - Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files( . The maximum length is 200 characters. - Specifies the name of the Amazon SNS topic defined for notification of log file delivery. The maximum length is 256 characters.T - Specifies whether log file integrity validation is enabled. The default is false. - Specifies a log group name using an Amazon Resource Name (ARN), a unique identifier that represents the log group to which CloudTrail logs will be delivered. Not required unless you specify CloudWatchLogsRoleArn. - Specifies the KMS key ID to use to encrypt the logs delivered by CloudTrail. The value can be an alias name prefixed by "alias|", a fully specified ARN to an alias, a fully specified ARN to a key, or a globally unique identifier. Examples: * alias:MyAliasName * arn:aws:kms:us-east-1:123456789012:alias8MyAliasName * arn:aws:kms:us-east-1:123456789012:keyO12345678-1234-1234-1234-123456789012 * 12345678-1234-1234-1234-123456789012f - Specifies whether the trail is publishing events from global services such as IAM to the log files.` - Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.h - Specifies whether the trail is created in the current region or in all regions. The default is false.h - Specifies the name of the trail. The name must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespaceJ are invalid. * Not be in IP address format (for example, 192.168.5.4)W - Specifies the name of the Amazon S3 bucket designated for publishing log files. See  Yhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/create_trail_naming_policy.html$Amazon S3 Bucket Naming Requirements .Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files( . The maximum length is 200 characters.Specifies the name of the Amazon SNS topic defined for notification of log file delivery. The maximum length is 256 characters.QSpecifies whether log file integrity validation is enabled. The default is false.Specifies a log group name using an Amazon Resource Name (ARN), a unique identifier that represents the log group to which CloudTrail logs will be delivered. Not required unless you specify CloudWatchLogsRoleArn.~Specifies the KMS key ID to use to encrypt the logs delivered by CloudTrail. The value can be an alias name prefixed by "alias|", a fully specified ARN to an alias, a fully specified ARN to a key, or a globally unique identifier. Examples: * alias:MyAliasName * arn:aws:kms:us-east-1:123456789012:alias8MyAliasName * arn:aws:kms:us-east-1:123456789012:keyO12345678-1234-1234-1234-123456789012 * 12345678-1234-1234-1234-123456789012cSpecifies whether the trail is publishing events from global services such as IAM to the log files.]Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.eSpecifies whether the trail is created in the current region or in all regions. The default is false.eSpecifies the name of the trail. The name must meet the following requirements: * Contain only ASCII letters (a-z, A-Z), numbers (0-9), periods (.), underscores (_), or dashes (-) * Start with a letter or number, and end with a letter or number * Be between 3 and 128 characters * Have no adjacent periods, underscores or dashes. Names like  my-_namespace and  my--namespaceJ are invalid. * Not be in IP address format (for example, 192.168.5.4)TSpecifies the name of the Amazon S3 bucket designated for publishing log files. See  Yhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/create_trail_naming_policy.html$Amazon S3 Bucket Naming Requirements .Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired: > - Specifies whether log file integrity validation is enabled.R - Specifies the ARN of the trail that was created. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail - Specifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files . - Specifies the ARN of the Amazon SNS topic that CloudTrail uses to send notifications when log files are delivered. The format of a topic ARN is: *arn:aws:sns:us-east-1:123456789012:MyTopic- - This field is deprecated. Use SnsTopicARN.h - Specifies the Amazon Resource Name (ARN) of the log group to which CloudTrail logs will be delivered. - Specifies the KMS key ID that encrypts the logs delivered by CloudTrail. The value is a fully specified ARN to a KMS key in the format: Karn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012# - Specifies the name of the trail.f - Specifies whether the trail is publishing events from global services such as IAM to the log files.` - Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.R - Specifies the name of the Amazon S3 bucket designated for publishing log files.F - Specifies whether the trail exists in one region or in all regions.! - -- | The response status code.;Specifies whether log file integrity validation is enabled.OSpecifies the ARN of the trail that was created. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailSpecifies the Amazon S3 key prefix that comes after the name of the bucket you have designated for log file delivery. For more information, see  Xhttp://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-find-log-files.html!Finding Your CloudTrail Log Files .Specifies the ARN of the Amazon SNS topic that CloudTrail uses to send notifications when log files are delivered. The format of a topic ARN is: *arn:aws:sns:us-east-1:123456789012:MyTopic*This field is deprecated. Use SnsTopicARN.eSpecifies the Amazon Resource Name (ARN) of the log group to which CloudTrail logs will be delivered.Specifies the KMS key ID that encrypts the logs delivered by CloudTrail. The value is a fully specified ARN to a KMS key in the format: Karn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012 Specifies the name of the trail.cSpecifies whether the trail is publishing events from global services such as IAM to the log files.]Specifies the role for the CloudWatch Logs endpoint to assume to write to a user's log group.OSpecifies the name of the Amazon S3 bucket designated for publishing log files.CSpecifies whether the trail exists in one region or in all regions.- | The response status code.<# (c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None !"05DRTReturns the objects or data listed below if successful. Otherwise, returns an error.See:  smart constructor.%Specifies the tags to add to a trail.See:  smart constructor.Creates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:: - Contains a list of CloudTrail tags, up to a limit of 50i - Specifies the ARN of the trail to which one or more tags will be added. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail7Contains a list of CloudTrail tags, up to a limit of 50fSpecifies the ARN of the trail to which one or more tags will be added. The format of a trail ARN is: 7arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrailCreates a value of 4 with the minimum fields required to make a request.BUse one of the following lenses to modify other fields as desired:! - -- | The response status code.- | The response status code.(c) 2013-2017 Brendan HayMozilla Public License, v. 2.0..Brendan Hay <brendan.g.hay+amazonka@gmail.com>auto-generatednon-portable (GHC extensions)None   !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~123456789:MNOPQRSTUVWXYZ[\]^_`abcvwxyz{|}fCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcde  !"#$%&'()*+,- ./0 123 456789:;<=>?@AB !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCD E F G H I J K L M N O P Q R S T U V W X Y Z [ \ ] ^ _ ` a b c d e f g h i j k l m n o p q r s t u v w x y z { | } ~                                                                                             !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~                                             0amazonka-cloudtrail-1.5.0-GT2y6tjh7SRBi5UfY2VBo1Network.AWS.CloudTrail.Types"Network.AWS.CloudTrail.UpdateTrail"Network.AWS.CloudTrail.StopLogging#Network.AWS.CloudTrail.StartLogging!Network.AWS.CloudTrail.RemoveTags(Network.AWS.CloudTrail.PutEventSelectors#Network.AWS.CloudTrail.LookupEventsNetwork.AWS.CloudTrail.ListTags%Network.AWS.CloudTrail.ListPublicKeys%Network.AWS.CloudTrail.GetTrailStatus(Network.AWS.CloudTrail.GetEventSelectors%Network.AWS.CloudTrail.DescribeTrails"Network.AWS.CloudTrail.DeleteTrail"Network.AWS.CloudTrail.CreateTrailNetwork.AWS.CloudTrail.AddTags Network.AWS.CloudTrail.Types.Sum$Network.AWS.CloudTrail.Types.ProductNetwork.AWS.CloudTrail.WaitersNetwork.AWS.CloudTrail ReadWriteTypeAllReadOnly WriteOnlyLookupAttributeKeyEventId EventName EventSource ResourceName ResourceTypeUsernameTrailTag ResourceTagResource PublicKeyLookupAttribute EventSelectorEvent DataResource dataResourcedrValuesdrTypeevent eUsername eResources eEventTimeeCloudTrailEvent eEventName eEventSourceeEventId eventSelectoresDataResourcesesReadWriteTypeesIncludeManagementEventslookupAttributelaAttributeKeylaAttributeValue publicKey pkFingerprintpkValidityEndTimepkValuepkValidityStartTimeresource rResourceType rResourceName resourceTag rResourceId rTagsListtagtagValuetagKeytrailtLogFileValidationEnabled tTrailARN tS3KeyPrefix tSNSTopicARN tSNSTopicNametCloudWatchLogsLogGroupARN tKMSKeyId tHomeRegiontNametIncludeGlobalServiceEventstHasCustomEventSelectorstCloudWatchLogsRoleARN tS3BucketNametIsMultiRegionTrail cloudTrail_InvalidTimeRangeException$_InsufficientS3BucketPolicyException'_MaximumNumberOfTrailsExceededException_UnsupportedOperationException_KMSKeyDisabledException&_InsufficientEncryptionPolicyException$_InsufficientSNSTopicPolicyException&_InvalidCloudWatchLogsRoleARNException_TagsLimitExceededException_CloudTrailARNInvalidException!_InvalidLookupAttributesException_InvalidTrailNameException_InvalidSNSTopicNameException"_ResourceTypeNotSupportedException+_CloudWatchLogsDeliveryUnavailableException_KMSKeyNotFoundException_TrailNotFoundException_InvalidEventSelectorsException_TrailNotProvidedException_InvalidS3BucketNameException*_InvalidCloudWatchLogsLogGroupARNException _KMSException_S3BucketDoesNotExistException_InvalidNextTokenException_InvalidTagParameterException_OperationNotPermittedException_InvalidTokenException_InvalidMaxResultsException_TrailAlreadyExistsException_InvalidS3PrefixException_ResourceNotFoundException%_InvalidParameterCombinationException_InvalidKMSKeyIdException_InvalidHomeRegionExceptionUpdateTrailResponse UpdateTrail updateTrail utS3KeyPrefixutSNSTopicNameutEnableLogFileValidationutCloudWatchLogsLogGroupARN utKMSKeyIdutIncludeGlobalServiceEventsutCloudWatchLogsRoleARNutS3BucketNameutIsMultiRegionTrailutNameupdateTrailResponseutrsLogFileValidationEnabled utrsTrailARNutrsS3KeyPrefixutrsSNSTopicARNutrsSNSTopicNameutrsCloudWatchLogsLogGroupARN utrsKMSKeyIdutrsNameutrsIncludeGlobalServiceEventsutrsCloudWatchLogsRoleARNutrsS3BucketNameutrsIsMultiRegionTrailutrsResponseStatus$fNFDataUpdateTrailResponse$fToQueryUpdateTrail$fToPathUpdateTrail$fToJSONUpdateTrail$fToHeadersUpdateTrail$fNFDataUpdateTrail$fHashableUpdateTrail$fAWSRequestUpdateTrail$fEqUpdateTrail$fReadUpdateTrail$fShowUpdateTrail$fDataUpdateTrail$fGenericUpdateTrail$fEqUpdateTrailResponse$fReadUpdateTrailResponse$fShowUpdateTrailResponse$fDataUpdateTrailResponse$fGenericUpdateTrailResponseStopLoggingResponse StopLogging stopLoggingslNamestopLoggingResponseslrsResponseStatus$fNFDataStopLoggingResponse$fToQueryStopLogging$fToPathStopLogging$fToJSONStopLogging$fToHeadersStopLogging$fNFDataStopLogging$fHashableStopLogging$fAWSRequestStopLogging$fEqStopLogging$fReadStopLogging$fShowStopLogging$fDataStopLogging$fGenericStopLogging$fEqStopLoggingResponse$fReadStopLoggingResponse$fShowStopLoggingResponse$fDataStopLoggingResponse$fGenericStopLoggingResponseStartLoggingResponse StartLogging startLoggingsNamestartLoggingResponsesrsResponseStatus$fNFDataStartLoggingResponse$fToQueryStartLogging$fToPathStartLogging$fToJSONStartLogging$fToHeadersStartLogging$fNFDataStartLogging$fHashableStartLogging$fAWSRequestStartLogging$fEqStartLogging$fReadStartLogging$fShowStartLogging$fDataStartLogging$fGenericStartLogging$fEqStartLoggingResponse$fReadStartLoggingResponse$fShowStartLoggingResponse$fDataStartLoggingResponse$fGenericStartLoggingResponseRemoveTagsResponse RemoveTags removeTags rtTagsList rtResourceIdremoveTagsResponsertrsResponseStatus$fNFDataRemoveTagsResponse$fToQueryRemoveTags$fToPathRemoveTags$fToJSONRemoveTags$fToHeadersRemoveTags$fNFDataRemoveTags$fHashableRemoveTags$fAWSRequestRemoveTags$fEqRemoveTags$fReadRemoveTags$fShowRemoveTags$fDataRemoveTags$fGenericRemoveTags$fEqRemoveTagsResponse$fReadRemoveTagsResponse$fShowRemoveTagsResponse$fDataRemoveTagsResponse$fGenericRemoveTagsResponsePutEventSelectorsResponsePutEventSelectorsputEventSelectors pesTrailNamepesEventSelectorsputEventSelectorsResponse pesrsTrailARNpesrsEventSelectorspesrsResponseStatus!$fNFDataPutEventSelectorsResponse$fToQueryPutEventSelectors$fToPathPutEventSelectors$fToJSONPutEventSelectors$fToHeadersPutEventSelectors$fNFDataPutEventSelectors$fHashablePutEventSelectors$fAWSRequestPutEventSelectors$fEqPutEventSelectors$fReadPutEventSelectors$fShowPutEventSelectors$fDataPutEventSelectors$fGenericPutEventSelectors$fEqPutEventSelectorsResponse$fReadPutEventSelectorsResponse$fShowPutEventSelectorsResponse$fDataPutEventSelectorsResponse"$fGenericPutEventSelectorsResponseLookupEventsResponse LookupEvents lookupEvents leStartTimeleLookupAttributes leNextToken leEndTime leMaxResultslookupEventsResponse lersNextToken lersEventslersResponseStatus$fNFDataLookupEventsResponse$fToQueryLookupEvents$fToPathLookupEvents$fToJSONLookupEvents$fToHeadersLookupEvents$fNFDataLookupEvents$fHashableLookupEvents$fAWSRequestLookupEvents$fAWSPagerLookupEvents$fEqLookupEvents$fReadLookupEvents$fShowLookupEvents$fDataLookupEvents$fGenericLookupEvents$fEqLookupEventsResponse$fReadLookupEventsResponse$fShowLookupEventsResponse$fDataLookupEventsResponse$fGenericLookupEventsResponseListTagsResponseListTagslistTags ltNextTokenltResourceIdListlistTagsResponse ltrsNextTokenltrsResourceTagListltrsResponseStatus$fNFDataListTagsResponse$fToQueryListTags$fToPathListTags$fToJSONListTags$fToHeadersListTags$fNFDataListTags$fHashableListTags$fAWSRequestListTags $fEqListTags$fReadListTags$fShowListTags$fDataListTags$fGenericListTags$fEqListTagsResponse$fReadListTagsResponse$fShowListTagsResponse$fDataListTagsResponse$fGenericListTagsResponseListPublicKeysResponseListPublicKeyslistPublicKeys lpkStartTime lpkNextToken lpkEndTimelistPublicKeysResponselpkrsPublicKeyListlpkrsNextTokenlpkrsResponseStatus$fNFDataListPublicKeysResponse$fToQueryListPublicKeys$fToPathListPublicKeys$fToJSONListPublicKeys$fToHeadersListPublicKeys$fNFDataListPublicKeys$fHashableListPublicKeys$fAWSRequestListPublicKeys$fEqListPublicKeys$fReadListPublicKeys$fShowListPublicKeys$fDataListPublicKeys$fGenericListPublicKeys$fEqListPublicKeysResponse$fReadListPublicKeysResponse$fShowListPublicKeysResponse$fDataListPublicKeysResponse$fGenericListPublicKeysResponseGetTrailStatusResponseGetTrailStatusgetTrailStatusgtsNamegetTrailStatusResponsegtsrsTimeLoggingStoppedgtsrsLatestDeliveryErrorgtsrsLatestDigestDeliveryTime'gtsrsLatestNotificationAttemptSucceededgtsrsStartLoggingTimegtsrsLatestNotificationError#gtsrsLatestDeliveryAttemptSucceededgtsrsIsLogginggtsrsTimeLoggingStartedgtsrsLatestDigestDeliveryErrorgtsrsLatestDeliveryAttemptTimegtsrsLatestDeliveryTime%gtsrsLatestCloudWatchLogsDeliveryTime>srsLatestCloudWatchLogsDeliveryErrorgtsrsLatestNotificationTime"gtsrsLatestNotificationAttemptTimegtsrsStopLoggingTimegtsrsResponseStatus$fNFDataGetTrailStatusResponse$fToQueryGetTrailStatus$fToPathGetTrailStatus$fToJSONGetTrailStatus$fToHeadersGetTrailStatus$fNFDataGetTrailStatus$fHashableGetTrailStatus$fAWSRequestGetTrailStatus$fEqGetTrailStatus$fReadGetTrailStatus$fShowGetTrailStatus$fDataGetTrailStatus$fGenericGetTrailStatus$fEqGetTrailStatusResponse$fReadGetTrailStatusResponse$fShowGetTrailStatusResponse$fDataGetTrailStatusResponse$fGenericGetTrailStatusResponseGetEventSelectorsResponseGetEventSelectorsgetEventSelectors gesTrailNamegetEventSelectorsResponse gesrsTrailARNgesrsEventSelectorsgesrsResponseStatus!$fNFDataGetEventSelectorsResponse$fToQueryGetEventSelectors$fToPathGetEventSelectors$fToJSONGetEventSelectors$fToHeadersGetEventSelectors$fNFDataGetEventSelectors$fHashableGetEventSelectors$fAWSRequestGetEventSelectors$fEqGetEventSelectors$fReadGetEventSelectors$fShowGetEventSelectors$fDataGetEventSelectors$fGenericGetEventSelectors$fEqGetEventSelectorsResponse$fReadGetEventSelectorsResponse$fShowGetEventSelectorsResponse$fDataGetEventSelectorsResponse"$fGenericGetEventSelectorsResponseDescribeTrailsResponseDescribeTrailsdescribeTrailsdtIncludeShadowTrailsdtTrailNameListdescribeTrailsResponse dtrsTrailListdtrsResponseStatus$fNFDataDescribeTrailsResponse$fToQueryDescribeTrails$fToPathDescribeTrails$fToJSONDescribeTrails$fToHeadersDescribeTrails$fNFDataDescribeTrails$fHashableDescribeTrails$fAWSRequestDescribeTrails$fEqDescribeTrails$fReadDescribeTrails$fShowDescribeTrails$fDataDescribeTrails$fGenericDescribeTrails$fEqDescribeTrailsResponse$fReadDescribeTrailsResponse$fShowDescribeTrailsResponse$fDataDescribeTrailsResponse$fGenericDescribeTrailsResponseDeleteTrailResponse DeleteTrail deleteTraildtNamedeleteTrailResponsedrsResponseStatus$fNFDataDeleteTrailResponse$fToQueryDeleteTrail$fToPathDeleteTrail$fToJSONDeleteTrail$fToHeadersDeleteTrail$fNFDataDeleteTrail$fHashableDeleteTrail$fAWSRequestDeleteTrail$fEqDeleteTrail$fReadDeleteTrail$fShowDeleteTrail$fDataDeleteTrail$fGenericDeleteTrail$fEqDeleteTrailResponse$fReadDeleteTrailResponse$fShowDeleteTrailResponse$fDataDeleteTrailResponse$fGenericDeleteTrailResponseCreateTrailResponse CreateTrail createTrail ctS3KeyPrefixctSNSTopicNamectEnableLogFileValidationctCloudWatchLogsLogGroupARN ctKMSKeyIdctIncludeGlobalServiceEventsctCloudWatchLogsRoleARNctIsMultiRegionTrailctNamectS3BucketNamecreateTrailResponsectrsLogFileValidationEnabled ctrsTrailARNctrsS3KeyPrefixctrsSNSTopicARNctrsSNSTopicNamectrsCloudWatchLogsLogGroupARN ctrsKMSKeyIdctrsNamectrsIncludeGlobalServiceEventsctrsCloudWatchLogsRoleARNctrsS3BucketNamectrsIsMultiRegionTrailctrsResponseStatus$fNFDataCreateTrailResponse$fToQueryCreateTrail$fToPathCreateTrail$fToJSONCreateTrail$fToHeadersCreateTrail$fNFDataCreateTrail$fHashableCreateTrail$fAWSRequestCreateTrail$fEqCreateTrail$fReadCreateTrail$fShowCreateTrail$fDataCreateTrail$fGenericCreateTrail$fEqCreateTrailResponse$fReadCreateTrailResponse$fShowCreateTrailResponse$fDataCreateTrailResponse$fGenericCreateTrailResponseAddTagsResponseAddTagsaddTags atTagsList atResourceIdaddTagsResponseatrsResponseStatus$fNFDataAddTagsResponse$fToQueryAddTags$fToPathAddTags$fToJSONAddTags$fToHeadersAddTags$fNFDataAddTags$fHashableAddTags$fAWSRequestAddTags $fEqAddTags $fReadAddTags $fShowAddTags $fDataAddTags$fGenericAddTags$fEqAddTagsResponse$fReadAddTagsResponse$fShowAddTagsResponse$fDataAddTagsResponse$fGenericAddTagsResponse$fFromJSONReadWriteType$fToJSONReadWriteType$fToHeaderReadWriteType$fToQueryReadWriteType$fToByteStringReadWriteType$fNFDataReadWriteType$fHashableReadWriteType$fToTextReadWriteType$fFromTextReadWriteType$fToJSONLookupAttributeKey$fToHeaderLookupAttributeKey$fToQueryLookupAttributeKey $fToByteStringLookupAttributeKey$fNFDataLookupAttributeKey$fHashableLookupAttributeKey$fToTextLookupAttributeKey$fFromTextLookupAttributeKeyTrail'_tLogFileValidationEnabled _tTrailARN _tS3KeyPrefix _tSNSTopicARN_tSNSTopicName_tCloudWatchLogsLogGroupARN _tKMSKeyId _tHomeRegion_tName_tIncludeGlobalServiceEvents_tHasCustomEventSelectors_tCloudWatchLogsRoleARN_tS3BucketName_tIsMultiRegionTrailTag' _tagValue_tagKey ResourceTag' _rResourceId _rTagsList Resource'_rResourceType_rResourceName PublicKey'_pkFingerprint_pkValidityEndTime_pkValue_pkValidityStartTimeLookupAttribute'_laAttributeKey_laAttributeValueEventSelector'_esDataResources_esReadWriteType_esIncludeManagementEventsEvent' _eUsername _eResources _eEventTime_eCloudTrailEvent _eEventName _eEventSource _eEventId DataResource' _drValues_drType $fNFDataTrail$fHashableTrail$fFromJSONTrail $fToJSONTag $fNFDataTag $fHashableTag $fFromJSONTag$fNFDataResourceTag$fHashableResourceTag$fFromJSONResourceTag$fNFDataResource$fHashableResource$fFromJSONResource$fNFDataPublicKey$fHashablePublicKey$fFromJSONPublicKey$fToJSONLookupAttribute$fNFDataLookupAttribute$fHashableLookupAttribute$fToJSONEventSelector$fNFDataEventSelector$fHashableEventSelector$fFromJSONEventSelector $fNFDataEvent$fHashableEvent$fFromJSONEvent$fToJSONDataResource$fNFDataDataResource$fHashableDataResource$fFromJSONDataResourceUpdateTrailResponse'_utrsLogFileValidationEnabled _utrsTrailARN_utrsS3KeyPrefix_utrsSNSTopicARN_utrsSNSTopicName_utrsCloudWatchLogsLogGroupARN _utrsKMSKeyId _utrsName_utrsIncludeGlobalServiceEvents_utrsCloudWatchLogsRoleARN_utrsS3BucketName_utrsIsMultiRegionTrail_utrsResponseStatus UpdateTrail'_utS3KeyPrefix_utSNSTopicName_utEnableLogFileValidation_utCloudWatchLogsLogGroupARN _utKMSKeyId_utIncludeGlobalServiceEvents_utCloudWatchLogsRoleARN_utS3BucketName_utIsMultiRegionTrail_utNameStopLoggingResponse'_slrsResponseStatus StopLogging'_slNameStartLoggingResponse'_srsResponseStatus StartLogging'_sNameRemoveTagsResponse'_rtrsResponseStatus RemoveTags' _rtTagsList _rtResourceIdPutEventSelectorsResponse'_pesrsTrailARN_pesrsEventSelectors_pesrsResponseStatusPutEventSelectors' _pesTrailName_pesEventSelectorsLookupEventsResponse'_lersNextToken _lersEvents_lersResponseStatus LookupEvents' _leStartTime_leLookupAttributes _leNextToken _leEndTime _leMaxResultsListTagsResponse'_ltrsNextToken_ltrsResourceTagList_ltrsResponseStatus ListTags' _ltNextToken_ltResourceIdListListPublicKeysResponse'_lpkrsPublicKeyList_lpkrsNextToken_lpkrsResponseStatusListPublicKeys' _lpkStartTime _lpkNextToken _lpkEndTimeGetTrailStatusResponse'_gtsrsTimeLoggingStopped_gtsrsLatestDeliveryError_gtsrsLatestDigestDeliveryTime(_gtsrsLatestNotificationAttemptSucceeded_gtsrsStartLoggingTime_gtsrsLatestNotificationError$_gtsrsLatestDeliveryAttemptSucceeded_gtsrsIsLogging_gtsrsTimeLoggingStarted_gtsrsLatestDigestDeliveryError_gtsrsLatestDeliveryAttemptTime_gtsrsLatestDeliveryTime&_gtsrsLatestCloudWatchLogsDeliveryTime'_gtsrsLatestCloudWatchLogsDeliveryError_gtsrsLatestNotificationTime#_gtsrsLatestNotificationAttemptTime_gtsrsStopLoggingTime_gtsrsResponseStatusGetTrailStatus'_gtsNameGetEventSelectorsResponse'_gesrsTrailARN_gesrsEventSelectors_gesrsResponseStatusGetEventSelectors' _gesTrailNameDescribeTrailsResponse'_dtrsTrailList_dtrsResponseStatusDescribeTrails'_dtIncludeShadowTrails_dtTrailNameListDeleteTrailResponse'_drsResponseStatus DeleteTrail'_dtNameCreateTrailResponse'_ctrsLogFileValidationEnabled _ctrsTrailARN_ctrsS3KeyPrefix_ctrsSNSTopicARN_ctrsSNSTopicName_ctrsCloudWatchLogsLogGroupARN _ctrsKMSKeyId _ctrsName_ctrsIncludeGlobalServiceEvents_ctrsCloudWatchLogsRoleARN_ctrsS3BucketName_ctrsIsMultiRegionTrail_ctrsResponseStatus CreateTrail'_ctS3KeyPrefix_ctSNSTopicName_ctEnableLogFileValidation_ctCloudWatchLogsLogGroupARN _ctKMSKeyId_ctIncludeGlobalServiceEvents_ctCloudWatchLogsRoleARN_ctIsMultiRegionTrail_ctName_ctS3BucketNameAddTagsResponse'_atrsResponseStatusAddTags' _atTagsList _atResourceId