Configures an event selector for your trail. Use event selectors to further specify the management and data event settings for your trail. By default, trails created without specific event selectors will be configured to log all read and write management events, and no data events.
When an event occurs in your account, CloudTrail evaluates the event selectors in all trails. For each trail, if the event matches any event selector, the trail processes and logs the event. If the event doesn't match any event selector, the trail doesn't log the event.
- You create an event selector for a trail and specify that you want write-only events.
- The EC2
RunInstances API operations occur in your account.
- CloudTrail evaluates whether the events match your event selectors.
RunInstances is a write-only event and it matches your event selector. The trail logs the event.
GetConsoleOutput is a read-only event but it doesn't match your event selector. The trail doesn't log the event.
operation must be called from the region in which the trail was created; otherwise, an
You can configure up to five event selectors for each trail. For more information, see Logging Data and Management Events for Trails
and Limits in AWS CloudTrail
in the AWS CloudTrail User Guide
Note: For scripts written against earlier versions of this module this cmdlet can also be invoked with the alias, Write-CTEventSelectors