Skip to content

aws.codecatalyst.list_event_logs

Example SQL Queries

SELECT * FROM
aws.codecatalyst.list_event_logs
WHERE
"space_name" = 'VALUE'
AND "start_time" = 'VALUE'
AND "end_time" = 'VALUE';

Description

Retrieves a list of events that occurred during a specific time in a space. You can use these events to audit user and system activity in a space. For more information, see Monitoring in the Amazon CodeCatalyst User Guide.

ListEventLogs guarantees events for the last 30 days in a given space. You can also view and retrieve a list of management events over the last 90 days for Amazon CodeCatalyst in the CloudTrail console by viewing Event history, or by creating a trail to create and maintain a record of events that extends past 90 days. For more information, see Working with CloudTrail Event History and Working with CloudTrail trails.

Table Definition

Column NameColumn Data Type
end_time Required Input Column

The time after which you do not want any events retrieved, in coordinated universal time (UTC) timestamp format as specified in RFC 3339.

TIMESTAMP_S
space_name Required Input Column

The name of the space.

VARCHAR
start_time Required Input Column

The date and time when you want to start retrieving events, in coordinated universal time (UTC) timestamp format as specified in RFC 3339.

TIMESTAMP_S
event_name Input Column

The name of the event.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

error_code

The code of the error, if any.

VARCHAR
event_category

The category for the event.

VARCHAR
event_source

The source of the event.

VARCHAR
event_time

The time the event took place, in coordinated universal time (UTC) timestamp format as specified in RFC 3339.

TIMESTAMP_S
event_type

The type of the event.

VARCHAR
id

The system-generated unique ID of the event.

VARCHAR
operation_type

The type of the event.

VARCHAR
project_information

Information about the project where the event occurred.

STRUCT(
"name" VARCHAR,
"project_id" VARCHAR
)
Show child fields
project_information.name

The name of the project in the space.

project_information.project_id

The system-generated unique ID of the project.

request_id

The system-generated unique ID of the request.

VARCHAR
request_payload

Information about the payload of the request.

STRUCT(
"content_type" VARCHAR,
"data" VARCHAR
)
Show child fields
request_payload.content_type

The type of content in the event payload.

request_payload.data

The data included in the event payload.

response_payload

Information about the payload of the response, if any.

STRUCT(
"content_type" VARCHAR,
"data" VARCHAR
)
Show child fields
response_payload.content_type

The type of content in the event payload.

response_payload.data

The data included in the event payload.

source_ip_address

The IP address of the user whose actions are recorded in the event.

VARCHAR
user_agent

The user agent whose actions are recorded in the event.

VARCHAR
user_identity

The system-generated unique ID of the user whose actions are recorded in the event.

STRUCT(
"user_type" VARCHAR,
"principal_id" VARCHAR,
"user_name" VARCHAR,
"aws_account_id" VARCHAR
)
Show child fields
user_identity.aws_account_id

The Amazon Web Services account number of the user in Amazon Web Services, if any.

user_identity.principal_id

The ID of the Amazon CodeCatalyst service principal.

user_identity.user_name

The display name of the user in Amazon CodeCatalyst.

user_identity.user_type

The role assigned to the user in a Amazon CodeCatalyst space or project when the event occurred.