DeleteEventDataStore
DeleteEventDataStore
Event
Places a CloudTrail Lake event data store into PENDING_DELETION, with automatic deletion after seven days. Termination protection must be off and federation disabled; other dependencies can also block the request. RestoreEventDataStore can restore it within the waiting period.
Security Context
Unauthorized deletion can impair audit access and ultimately destroy stored evidence (T1685.002). Approved retirement or migration is also possible. Pending deletion restricts query operations, but is not immediate irreversible erasure. The ARN’s Region does not establish the store’s full collection scope or retention.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: cloudtrail.amazonaws.com and eventName: DeleteEventDataStore. Check collection scope and retention before interpreting absent records.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.eventDataStore | Store ARN or ID; recover collection and retention settings. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approval and inspect errors for termination protection, federation, channels, or ongoing imports.
- Verify current store status and establish the deletion deadline; use approved restoration within seven days if required.
- Recover organization/multi-Region scope, selectors, retention, and previous changes that enabled deletion.
- Correlate with DeleteTrail and verify restored ingestion/query access plus independent evidence copies.
Sample Event
Synthetic scenario. Draco requests deletion of a fictional store. Its seven-day retention, prior contents, and successful final deletion are not demonstrated. The recovery window is distinct from configured data retention. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:36:18Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "DeleteEventDataStore", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "eventDataStore": "arn:aws:cloudtrail:us-east-1:555123456789:eventdatastore/60000000-0000-4000-8000-000100000000" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011011110", "eventID": "90000000-0000-4000-8000-000011011111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...