Like many I'm sure, we've received an email from Amazon stating:
We recently observed Signature Version 2 requests on an Amazon SES SMTP endpoint originating from your account.
Is there any way to identify what these calls are as we have several IAM users and large codebases and haven't yet been able to trace the origin of these calls.
I'm thinking this should be possible with CloudWatch/CloudTrail but can't see how to do this.