AWS Security ChangesHomeSearch

AWS healthlake: HealthLake data transformation job auditing via CloudTrail

Service: healthlake · 2026-09-27 · Documentation medium

File: healthlake/latest/devguide/data-transformation-features.md · Type: logging

Summary

Clarifies that job logs and per-job metrics are not available in the customer account, and directs users to AWS CloudTrail (filtering on event names like StartDataTransformationJob) to audit API calls that start and describe jobs.

Security assessment

The changed line documents that job logs/metrics are unavailable and points users to CloudTrail for auditing job-related API calls, which is audit/logging guidance with security relevance but no specific vulnerability addressed.

Evidence

+Track a running job through the AWS Management Console job detail page or the DescribeDataTransformationJob API: status, files processed (rows for CSV), resources generated, and failures. Job logs and per-job metrics are not available in your account. To audit the API calls that start and describe jobs, use AWS CloudTrail and filter on the event name, for example `StartDataTransformationJob`. These events reference the data transformation profile, so the associated resource is the profile ARN rather than the job ID. For more information, see [Logging HealthLake API calls using AWS CloudTrail](./monitoring-cloudtrail.html).

Diff

diff --git a/healthlake/latest/devguide/data-transformation-features.md b/healthlake/latest/devguide/data-transformation-features.md
index 154b4f93a..6a83241ce 100644
--- a//healthlake/latest/devguide/data-transformation-features.md
+++ b//healthlake/latest/devguide/data-transformation-features.md
@@ -229 +229 @@ The service creates a job-scoped folder under your output Amazon S3 URI using th
-Track a running job through the AWS Management Console job detail page or the DescribeDataTransformationJob API: status, files processed (rows for CSV), resources generated, and failures. Job metrics and logs are also available in Amazon CloudWatch.
+Track a running job through the AWS Management Console job detail page or the DescribeDataTransformationJob API: status, files processed (rows for CSV), resources generated, and failures. Job logs and per-job metrics are not available in your account. To audit the API calls that start and describe jobs, use AWS CloudTrail and filter on the event name, for example `StartDataTransformationJob`. These events reference the data transformation profile, so the associated resource is the profile ARN rather than the job ID. For more information, see [Logging HealthLake API calls using AWS CloudTrail](./monitoring-cloudtrail.html).