RevokeGrant - AWS Key Management Service

RevokeGrant

The following example shows an AWS CloudTrail log entry generated by calling the RevokeGrant operation. For information about revoking grants, see Retiring and revoking grants.

{ "eventVersion": "1.08", "userIdentity": { "type": "IAMUser", "principalId": "EX_PRINCIPAL_ID", "arn": "arn:aws:iam::111122223333:user/Alice", "accountId": "111122223333", "accessKeyId": "EXAMPLE_KEY_ID", "userName": "Alice" }, "eventTime": "2022-09-01T19:35:17Z", "eventSource": "kms.amazonaws.com", "eventName": "RevokeGrant", "awsRegion": "us-west-2", "sourceIPAddress": "192.0.2.0", "userAgent": "AWS Internal", "requestParameters": { "keyId": "1234abcd-12ab-34cd-56ef-1234567890ab", "grantId": "abcde1237f76e4ba7987489ac329fbfba6ad343d6f7075dbd1ef191f0120514a" }, "responseElements": null, "requestID": "59d94c03-c5b7-428d-ae6e-f2c4b47d2917", "eventID": "07a23a39-6526-4ae2-b31e-d35fbe9e24ee", "readOnly": false, "resources": [ { "accountId": "111122223333", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111122223333", "eventCategory": "Management" }