Package-level declarations
Types
CloudWatch Omni is a unified observability experience built on Amazon CloudWatch. You work in a space, an isolated environment that holds your telemetry and controls who can access it, and your data is stored in the CloudWatch Dataset for correlated analysis of logs, metrics, and traces.
Inherited functions
Creates an AccessGrant that authorizes a principal to perform a set of actions on resources in a space. Optionally narrow the grant with scoped actions that limit it to specific resources and fields. Use ListAccessGrants and GetAccessGrant to retrieve grants, and DeleteAccessGrant to remove them.
Creates an access profile in a space. Use GetAccessProfile and ListAccessProfiles to retrieve profiles, and UpdateAccessProfile to modify one.
Creates a new alert within a space. Use GetAlert and ListAlerts to retrieve alerts, UpdateAlert to modify one, and DeleteAlert to remove it.
Creates a domain with identity provider configuration. Use GetDomain to retrieve the domain, UpdateDomain to change its configuration, and CreateSpace to add spaces within it.
Creates an AccessGrant that authorizes a principal to administer an organization domain.
Creates an organization-scoped domain for the caller's AWS Organization. Only the organization's management account can call this operation.
Creates an integration with a third-party provider. Returns the integration identifier and its initial status; when the provider requires interactive consent, an authorization URL is returned for the user to complete setup.
Creates a new dashboard within a space. Use GetOmniDashboard and ListOmniDashboards to retrieve dashboards, UpdateOmniDashboard to modify one, and DeleteOmniDashboard to remove it.
Generates a one-time code for deep-link authentication. Direct the user's browser to the returned deepLinkUrl before it expires. The code is exchanged for an authenticated, domain-scoped session and can be used only once.
Creates a space in a domain. Use GetSpace to retrieve the space, ListSpaces to enumerate spaces, UpdateSpace to modify it, and DeleteSpace to remove it.
Creates a new SQL view. A view is a named, reusable SQL query that can be referenced from telemetry queries. View names must be unique within the account and region. Only USER views can be created — MANAGED views are provisioned by AWS.
Removes an existing AccessGrant, revoking the access it granted. A service-managed grant cannot be deleted.
Removes an access profile. An access profile cannot be deleted while access grants reference it.
Deletes an alert by its identifier. Idempotent: deleting an alert that has already been removed succeeds without error.
Removes a domain and all of its resources. Call this operation in the Region where the domain was created. A domain cannot be deleted while it contains spaces.
Removes an existing organization access grant, revoking the access it granted. A service-managed grant cannot be deleted.
Removes an organization domain and all of its resources. Call this operation in the Region where the domain was created. A domain cannot be deleted while it contains spaces.
Deletes an integration. Returns the resulting status.
Removes a dashboard from a space.
Removes a space and all of its resources.
Deletes the specified view. Queries that reference the view fail after it is deleted. Managed views cannot be deleted.
Retrieves the full detail of a single AccessGrant by ID.
Retrieves an access profile by ID. The response indicates whether the calling principal is currently allowed to assume the profile.
Retrieves a single alert by its identifier. Use ListAlerts to enumerate alerts in the space.
Queries the context graph with filtering, traversal, and pagination support. Pagination note: nodes and edges are returned together as a coherent subgraph. Pagination cursors advance over nodes (the primary collection); each page includes all edges connecting nodes within that page. Callers should treat nodes as the paginated collection and edges as supplementary relationship data attached to those nodes.
Retrieves the details of a domain by ID.
Retrieves the full detail of a single organization access grant by ID.
Retrieves the details of an organization domain by ID.
Returns the details of a single integration, identified by its identifier, Amazon Resource Name, or name.
Retrieves the intelligence configuration for the calling account. Account is identified via FAS (caller identity). Returns the default configuration if none exists yet.
Retrieves a dashboard by ID within a space.
Retrieves the details of a space by ID.
Returns temporary credentials for a space in an organization member account. The credentials are valid for one hour. The caller must be the organization's management account or a delegated administrator with access to the target space. The target account must be an active member of the same organization as the domain, and the space must already exist.
Returns the results for the specified query.
Returns the definition and metadata of the specified view.
Returns AccessGrants, with optional filtering by domain, space, principal, or permission. A grant is returned only when it matches every filter supplied. With no filters, returns the grants for the current account and Region.
Returns the access profiles in a space.
Lists alerts within a space, optionally filtered by exact name(s), a single name prefix, or exact alertId(s), with pagination. Use GetAlert to retrieve a single alert's full detail.
Returns organization-level domain access grants, with optional filtering by domain, principal, or permission. A grant is returned only when it matches every filter supplied. With no filters, returns the grants for the caller's organization.
Returns the caller's domains: the account-scoped domain and the organization-scoped domain, if either exists. At most two domains are returned.
Lists the integrations in the account, optionally filtered by type, status, or name. Results are paginated.
Returns the dashboards in a space, optionally filtered by name prefix.
Returns the spaces in the account, optionally filtered by domain.
Returns the spaces across all member accounts in the organization.
Lists fields available for telemetry queries. Returns a list of fields included in the specified dataset, granular to telemetry type. Returned field names reflect the exact stored casing and are case-sensitive when referenced in query expressions; the query engine does not normalize identifier case.
Lists telemetry query sessions. Returns a list of telemetry query sessions owned by the caller.
Lists the views in the caller's account and region. Returns a summary for each view, optionally filtered by view type. View definitions are not included — use GetView to retrieve them.
Creates or updates the intelligence configuration for the calling account. Account is identified via FAS (caller identity).
Searches Identity Center for users and groups in a domain. The domain must be configured with Identity Center. To grant access to a result, pass its principalId to CreateAccessGrant with a principalType of IDC_USER for a user or IDC_GROUP for a group.
Starts a telemetry query within a session. Submits the provided query string for execution in the specified session. Use GetTelemetryQueryResults to poll for results and check query status.
Starts a new telemetry query session. A session provides a logical grouping for one or more telemetry queries. The returned session ID is required when starting queries via StartTelemetryQuery.
Stops a running telemetry query.
Stops a telemetry query session. Terminates the specified session. After a session is stopped it cannot be reused.
Updates the name or description of an access profile. Only the provided fields are changed; omitted fields are left unchanged.
Updates an existing alert. Only non-null fields overwrite existing values.
Updates a domain's name or identity provider configuration. Only the provided fields are changed; omitted fields are left unchanged. Renaming a domain also changes the endpoint URLs derived from its name.
Updates an organization domain's name or identity provider configuration. Call this operation in the Region where the domain was created. Only the provided fields are changed; omitted fields are left unchanged. Renaming a domain also changes the endpoint URLs derived from its name.
Updates an existing integration, identified by its id, ARN, or name. Only the fields you provide are changed.
Updates an existing dashboard within a space. Only the provided fields are changed; omitted fields are left unchanged.
Updates a space. Only the provided fields are changed; omitted fields are left unchanged.
Updates an existing view's definition and/or description. Only the fields you provide are changed. Managed views cannot be updated.
Create a copy of the client with one or more configuration values overridden. This method allows the caller to perform scoped config overrides for one or more client operations.