libZSservicesZSamazonka-cloudwatch-logsZSamazonka-cloudwatch-logs
Copyright(c) 2013-2021 Brendan Hay
LicenseMozilla Public License, v. 2.0.
MaintainerBrendan Hay <brendan.g.hay+amazonka@gmail.com>
Stabilityauto-generated
Portabilitynon-portable (GHC extensions)
Safe HaskellNone

Amazonka.CloudWatchLogs.AssociateKmsKey

Description

Associates the specified Key Management Service customer master key (CMK) with the specified log group.

Associating an KMS CMK with a log group overrides any existing associations between the log group and a CMK. After a CMK is associated with a log group, all newly ingested data for the log group is encrypted using the CMK. This association is stored as long as the data encrypted with the CMK is still within CloudWatch Logs. This enables CloudWatch Logs to decrypt this data whenever it is requested.

CloudWatch Logs supports only symmetric CMKs. Do not use an associate an asymmetric CMK with your log group. For more information, see Using Symmetric and Asymmetric Keys.

It can take up to 5 minutes for this operation to take effect.

If you attempt to associate a CMK with a log group but the CMK does not exist or the CMK is disabled, you receive an InvalidParameterException error.

Synopsis

Creating a Request

data AssociateKmsKey Source #

See: newAssociateKmsKey smart constructor.

Constructors

AssociateKmsKey' 

Fields

Instances

Instances details
Eq AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Read AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Show AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Generic AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Associated Types

type Rep AssociateKmsKey :: Type -> Type #

NFData AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Methods

rnf :: AssociateKmsKey -> () #

Hashable AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

ToJSON AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

AWSRequest AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Associated Types

type AWSResponse AssociateKmsKey #

ToHeaders AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

ToPath AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

ToQuery AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

type Rep AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

type Rep AssociateKmsKey = D1 ('MetaData "AssociateKmsKey" "Amazonka.CloudWatchLogs.AssociateKmsKey" "libZSservicesZSamazonka-cloudwatch-logsZSamazonka-cloudwatch-logs" 'False) (C1 ('MetaCons "AssociateKmsKey'" 'PrefixI 'True) (S1 ('MetaSel ('Just "logGroupName") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 Text) :*: S1 ('MetaSel ('Just "kmsKeyId") 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 Text)))
type AWSResponse AssociateKmsKey Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

newAssociateKmsKey Source #

Create a value of AssociateKmsKey with all optional fields omitted.

Use generic-lens or optics to modify other optional fields.

The following record fields are available, with the corresponding lenses provided for backwards compatibility:

$sel:logGroupName:AssociateKmsKey', associateKmsKey_logGroupName - The name of the log group.

$sel:kmsKeyId:AssociateKmsKey', associateKmsKey_kmsKeyId - The Amazon Resource Name (ARN) of the CMK to use when encrypting log data. This must be a symmetric CMK. For more information, see Amazon Resource Names - Key Management Service and Using Symmetric and Asymmetric Keys.

Request Lenses

associateKmsKey_kmsKeyId :: Lens' AssociateKmsKey Text Source #

The Amazon Resource Name (ARN) of the CMK to use when encrypting log data. This must be a symmetric CMK. For more information, see Amazon Resource Names - Key Management Service and Using Symmetric and Asymmetric Keys.

Destructuring the Response

data AssociateKmsKeyResponse Source #

See: newAssociateKmsKeyResponse smart constructor.

Instances

Instances details
Eq AssociateKmsKeyResponse Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Read AssociateKmsKeyResponse Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Show AssociateKmsKeyResponse Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Generic AssociateKmsKeyResponse Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Associated Types

type Rep AssociateKmsKeyResponse :: Type -> Type #

NFData AssociateKmsKeyResponse Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

Methods

rnf :: AssociateKmsKeyResponse -> () #

type Rep AssociateKmsKeyResponse Source # 
Instance details

Defined in Amazonka.CloudWatchLogs.AssociateKmsKey

type Rep AssociateKmsKeyResponse = D1 ('MetaData "AssociateKmsKeyResponse" "Amazonka.CloudWatchLogs.AssociateKmsKey" "libZSservicesZSamazonka-cloudwatch-logsZSamazonka-cloudwatch-logs" 'False) (C1 ('MetaCons "AssociateKmsKeyResponse'" 'PrefixI 'False) (U1 :: Type -> Type))

newAssociateKmsKeyResponse :: AssociateKmsKeyResponse Source #

Create a value of AssociateKmsKeyResponse with all optional fields omitted.

Use generic-lens or optics to modify other optional fields.