AWSGuardDuty - GuardDuty Alert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies Amazon GuardDuty findings and creates a Microsoft Sentinel alert for each finding. Use the GuardDuty finding details in the alert to determine the specific malicious or suspicious activity that was detected.

Attribute Value
Type Analytic Rule
Solution Amazon Web Services
ID bf0cde21-0c41-48f6-a40c-6b5bd71fa106
Severity Medium
Status Available
Kind Scheduled
Required Connectors AWSS3
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AWSGuardDuty

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Amazon Web Services