AWS CloudTrail endpoints and quotas - AWS General Reference

AWS CloudTrail endpoints and quotas

The following are the service endpoints and service quotas for this service. To connect programmatically to an AWS service, you use an endpoint. In addition to the standard AWS endpoints, some AWS services offer FIPS endpoints in selected Regions. For more information, see AWS service endpoints. Service quotas, also referred to as limits, are the maximum number of service resources or operations for your AWS account. For more information, see AWS service quotas.

Service endpoints

Control plane endpoints

The following table contains AWS Region-specific endpoints that AWS CloudTrail supports for control plane operations. For more information, see the AWS CloudTrail API Reference.

Region Name Region Endpoint Protocol
US East (Ohio) us-east-2

cloudtrail.us-east-2.amazonaws.com

cloudtrail-fips.us-east-2.amazonaws.com

HTTPS

HTTPS

US East (N. Virginia) us-east-1

cloudtrail.us-east-1.amazonaws.com

cloudtrail-fips.us-east-1.amazonaws.com

HTTPS

HTTPS

US West (N. California) us-west-1

cloudtrail.us-west-1.amazonaws.com

cloudtrail-fips.us-west-1.amazonaws.com

HTTPS

HTTPS

US West (Oregon) us-west-2

cloudtrail.us-west-2.amazonaws.com

cloudtrail-fips.us-west-2.amazonaws.com

HTTPS

HTTPS

Africa (Cape Town) af-south-1 cloudtrail.af-south-1.amazonaws.com HTTPS
Asia Pacific (Hong Kong) ap-east-1 cloudtrail.ap-east-1.amazonaws.com HTTPS
Asia Pacific (Hyderabad) ap-south-2 cloudtrail.ap-south-2.amazonaws.com HTTPS
Asia Pacific (Jakarta) ap-southeast-3 cloudtrail.ap-southeast-3.amazonaws.com HTTPS
Asia Pacific (Melbourne) ap-southeast-4 cloudtrail.ap-southeast-4.amazonaws.com HTTPS
Asia Pacific (Mumbai) ap-south-1 cloudtrail.ap-south-1.amazonaws.com HTTPS
Asia Pacific (Osaka) ap-northeast-3 cloudtrail.ap-northeast-3.amazonaws.com HTTPS
Asia Pacific (Seoul) ap-northeast-2 cloudtrail.ap-northeast-2.amazonaws.com HTTPS
Asia Pacific (Singapore) ap-southeast-1 cloudtrail.ap-southeast-1.amazonaws.com HTTPS
Asia Pacific (Sydney) ap-southeast-2 cloudtrail.ap-southeast-2.amazonaws.com HTTPS
Asia Pacific (Tokyo) ap-northeast-1 cloudtrail.ap-northeast-1.amazonaws.com HTTPS
Canada (Central) ca-central-1 cloudtrail.ca-central-1.amazonaws.com HTTPS
Canada West (Calgary) ca-west-1 cloudtrail.ca-west-1.amazonaws.com HTTPS
Europe (Frankfurt) eu-central-1 cloudtrail.eu-central-1.amazonaws.com HTTPS
Europe (Ireland) eu-west-1 cloudtrail.eu-west-1.amazonaws.com HTTPS
Europe (London) eu-west-2 cloudtrail.eu-west-2.amazonaws.com HTTPS
Europe (Milan) eu-south-1 cloudtrail.eu-south-1.amazonaws.com HTTPS
Europe (Paris) eu-west-3 cloudtrail.eu-west-3.amazonaws.com HTTPS
Europe (Spain) eu-south-2 cloudtrail.eu-south-2.amazonaws.com HTTPS
Europe (Stockholm) eu-north-1 cloudtrail.eu-north-1.amazonaws.com HTTPS
Europe (Zurich) eu-central-2 cloudtrail.eu-central-2.amazonaws.com HTTPS
Israel (Tel Aviv) il-central-1 cloudtrail.il-central-1.amazonaws.com HTTPS
Middle East (Bahrain) me-south-1 cloudtrail.me-south-1.amazonaws.com HTTPS
Middle East (UAE) me-central-1 cloudtrail.me-central-1.amazonaws.com HTTPS
South America (São Paulo) sa-east-1 cloudtrail.sa-east-1.amazonaws.com HTTPS
AWS GovCloud (US-East) us-gov-east-1 cloudtrail.us-gov-east-1.amazonaws.com HTTPS
AWS GovCloud (US-West) us-gov-west-1 cloudtrail.us-gov-west-1.amazonaws.com HTTPS

Data plane endpoints

The following table contains AWS Region-specific endpoints that AWS CloudTrail supports for data plane operations. For more information, see the AWS CloudTrail Data API Reference.

Region Name Region Endpoint Protocol
US East (Ohio) us-east-2 cloudtrail-data.us-east-2.amazonaws.com HTTPS
US East (N. Virginia) us-east-1 cloudtrail-data.us-east-1.amazonaws.com HTTPS
US West (N. California) us-west-1 cloudtrail-data.us-west-1.amazonaws.com HTTPS
US West (Oregon) us-west-2 cloudtrail-data.us-west-2.amazonaws.com HTTPS
Africa (Cape Town) af-south-1 cloudtrail-data.af-south-1.amazonaws.com HTTPS
Asia Pacific (Hong Kong) ap-east-1 cloudtrail-data.ap-east-1.amazonaws.com HTTPS
Asia Pacific (Jakarta) ap-southeast-3 cloudtrail-data.ap-southeast-3.amazonaws.com HTTPS
Asia Pacific (Mumbai) ap-south-1 cloudtrail-data.ap-south-1.amazonaws.com HTTPS
Asia Pacific (Osaka) ap-northeast-3 cloudtrail-data.ap-northeast-3.amazonaws.com HTTPS
Asia Pacific (Seoul) ap-northeast-2 cloudtrail-data.ap-northeast-2.amazonaws.com HTTPS
Asia Pacific (Singapore) ap-southeast-1 cloudtrail-data.ap-southeast-1.amazonaws.com HTTPS
Asia Pacific (Sydney) ap-southeast-2 cloudtrail-data.ap-southeast-2.amazonaws.com HTTPS
Asia Pacific (Tokyo) ap-northeast-1 cloudtrail-data.ap-northeast-1.amazonaws.com HTTPS
Canada (Central) ca-central-1 cloudtrail-data.ca-central-1.amazonaws.com HTTPS
Europe (Frankfurt) eu-central-1 cloudtrail-data.eu-central-1.amazonaws.com HTTPS
Europe (Ireland) eu-west-1 cloudtrail-data.eu-west-1.amazonaws.com HTTPS
Europe (London) eu-west-2 cloudtrail-data.eu-west-2.amazonaws.com HTTPS
Europe (Milan) eu-south-1 cloudtrail-data.eu-south-1.amazonaws.com HTTPS
Europe (Paris) eu-west-3 cloudtrail-data.eu-west-3.amazonaws.com HTTPS
Europe (Stockholm) eu-north-1 cloudtrail-data.eu-north-1.amazonaws.com HTTPS
Middle East (Bahrain) me-south-1 cloudtrail-data.me-south-1.amazonaws.com HTTPS
Middle East (UAE) me-central-1 cloudtrail-data.me-central-1.amazonaws.com HTTPS
South America (São Paulo) sa-east-1 cloudtrail-data.sa-east-1.amazonaws.com HTTPS

Service quotas

Name Default Adjustable Description
Conditions across all advanced event selectors Each supported Region: 500 No If a trail uses advanced event selectors, a maximum of 500 total values for all conditions in all advanced event selectors is allowed. Unless a trail logs data events on all resources, such as all S3 buckets, a trail is limited to 250 data resources. Data resources can be distributed across event selectors, but the total cannot exceed 250.
Data resources across all event selectors in a trail Each supported Region: 250 No If you choose to limit data events by using event selectors or advanced event selectors, the total number of data resources cannot exceed 250 across all event selectors in a trail.
Event data stores Each supported Region: 10 No The maximum number of event data stores that you can have in any one region. This includes single-region event data stores for the region as well as any multi-region event data stores across all regions.
Event selectors Each supported Region: 5 No The maximum number of event selectors per trail.
Event size Each supported Region: 256 Kilobytes No The maximum event size (in KB). All event versions: events over 256 KB cannot be sent to CloudWatch Logs. Event version 1.05 and newer: maximum event size of 256 KB.
Trails per region Each supported Region: 5 No The maximum number of trails per region.
Transactions per second (TPS) for all other APIs Each supported Region: 1 No The maximum number of operation requests you can make per second without being throttled.
Transactions per second (TPS) for the CancelQuery, StartQuery APIs Each supported Region: 3 No The maximum number of operation requests you can make per second without being throttled.
Transactions per second (TPS) for the LookupEvents API Each supported Region: 2 No The maximum number of operation requests you can make per second without being throttled.
Transactions per second (TPS) for the get, describe, and list APIs Each supported Region: 10 No The maximum number of operation requests you can make per second without being throttled. The LookupEvents API is not included in this category.

For more information, see Quotas in AWS CloudTrail.