Skip to main content
Looks up management events or CloudTrail Insights events that are captured by CloudTrail. You can look up events that occurred in a region within the last 90 days. Lookup supports the following attributes for management events:
  • Amazon Web Services access key
  • Event ID
  • Event name
  • Event source
  • Read only
  • Resource name
  • Resource type
  • User name
Lookup supports the following attributes for Insights events:
  • Event ID
  • Event name
  • Event source
All attributes are optional. The default number of results returned is 50, with a maximum of 50 possible. The response includes a token that you can use to get the next page of results.
The rate of lookup requests is limited to two per second, per account, per region. If this limit is exceeded, a throttling error occurs.
External DocumentationTo learn more, visit the AWS documentation.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

Get Ip Activity from Aws Cloudtrail Logs
Workflow LibraryPreview this Workflow on desktop