AWSCloudTrail

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for AWSCloudTrail table in Azure Monitor Logs.

Attribute Value
Category AWS
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✓ Yes
Lake-Only Ingestion ✓ Yes (source)
Azure Monitor Tables Reference View Documentation
Azure Monitor Logs Ingestion API View Documentation

Contents

Schema (55 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
AdditionalEventData string Additional data about the event that was not part of the request or response.
APIVersion string Identifies the API version associated with the AwsApiCall eventType value.
AwsEventId string GUID generated by CloudTrail to uniquely identify each event. You can use this value to identify a single event.
AWSRegion string The AWS region that the request was made to.
AwsRequestId string deprecated, please use AwsRequestId_ instead.
AwsRequestId_ string The value that identifies the request. The service being called generates this value.
Category string Shows the event category that is used in LookupEvents calls.
CidrIp string The CIDR IP is located under RequestParameters in CloudTrail, and it is used to specify the IP permissions for a security group rule. The IPv4 CIDR range.
CipherSuite string Optional. Part of tlsDetails. The cipher suite (combination of security algorithms used) of a request.
ClientProvidedHostHeader string Optional. Part of tlsDetails. The client-provided host name used in the service API call, which is typically the FQDN of the service endpoint.
DestinationPort string The DestinationPort is located under RequestParameters in CloudTrail, and it is used to specify the IP permissions for a security group rule. The end of port range for the TCP and UDP protocols, or an ICMP code.
EC2RoleDelivery string The friendly name of the user or role that issued the session.
ErrorCode string The AWS service error if the request returns an error.
ErrorMessage string The error description when available. This message includes messages for authorization failures. CloudTrail captures the message logged by the service in its exception handling.
EventName string The requested action, which is one of the actions in the API for that service.
EventSource string The service that the request was made to. This name is typically a short form of the service name without spaces plus .amazonaws.com.
EventTypeName string Identifies the type of event that generated the event record. This can be the one of the following values: AwsApiCall, AwsServiceEvent, AwsConsoleAction , AwsConsoleSignIn.
EventVersion string The version of the log event format.
IpProtocol string The IP protocol is located under RequestParameters in CloudTrail, and it is used to specify the IP permissions for a security group rule. The IP protocol name or number. The valid values are tcp, udp, icmp, or a protocol number.
ManagementEvent bool A Boolean value that identifies whether the event is a management event.
OperationName string Constant value: CloudTrail.
ReadOnly bool Identifies whether this operation is a read-only operation.
RecipientAccountId string Represents the account ID that received this event. The recipientAccountID may be different from the CloudTrail userIdentity Element accountId. This can occur in cross-account resource access.
RequestParameters string The parameters, if any, that were sent with the request. These parameters are documented in the API reference documentation for the appropriate AWS service.
Resources string A list of resources accessed in the event.
ResponseElements string The response element for actions that make changes (create, update, or delete actions). If an action does not change state (for example, a request to get or list objects), this element is omitted.
ServiceEventDetails string Identifies the service event, including what triggered the event and the result.
SessionCreationDate datetime The date and time when the temporary security credentials were issued.
SessionIssuerAccountId string The account that owns the entity that was used to get credentials.
SessionIssuerArn string The ARN of the source (account, IAM user, or role) that was used to get temporary security credentials.
SessionIssuerPrincipalId string The internal ID of the entity that was used to get credentials.
SessionIssuerType string The source of the temporary security credentials, such as Root, IAMUser, or Role.
SessionIssuerUserName string The friendly name of the user or role that issued the session.
SessionMfaAuthenticated bool The value is true if the root user or IAM user whose credentials were used for the request also was authenticated with an MFA device; otherwise, false.
SharedEventId string GUID generated by CloudTrail to uniquely identify CloudTrail events from the same AWS action that is sent to different AWS accounts.
SourceIpAddress string The IP address that the request was made from. For actions that originate from the service console, the address reported is for the underlying customer resource, not the console web server. For services in AWS, only the DNS name is displayed.
SourcePort string The SourcePort is located under RequestParameters in CloudTrail, and it is used to specify the IP permissions for a security group rule. The start of port range for the TCP and UDP protocols, or an ICMP type number.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The timestamp (UTC). An event's time stamp comes from the local host that provides the service API endpoint on which the API call was made.
TlsVersion string Optional. Part of tlsDetails. The TLS version of a request.
Type string The name of the table
UserAgent string The agent through which the request was made, such as the AWS Management Console, an AWS service, the AWS SDKs or the AWS CLI.
UserIdentityAccessKeyId string The access key ID that was used to sign the request.
UserIdentityAccountId string The account that owns the entity that granted permissions for the request.
UserIdentityArn string The Amazon Resource Name (ARN) of the principal that made the call.
UserIdentityInvokedBy string The name of the AWS service that made the request.
UserIdentityPrincipalid string A unique identifier for the entity that made the call.
UserIdentityStoreArn string ARN of the identity store (e.g., IAM Identity Center/SSO directory) from which the user identity originates.
UserIdentityType string The type of the identity. The following values are possible: Root, IAMUser, AssumedRole, FederatedUser, Directory, AWSAccount, AWSService, Unknown.
UserIdentityUserId string Unique internal AWS identifier of the IAM entity (user, role, or federated identity) that performed the action.
UserIdentityUserName string The name of the identity that made the call.
VpcEndpointId string Identifies the VPC endpoint in which requests were made from a VPC to another AWS service.

Solutions (13)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
Amazon Web Services
Amazon Web Services S3 EventName == "CreateUser"

Content Items Using This Table (118)

Analytic Rules (73)

In solution Amazon Web Services:

Analytic Rule Selection Criteria
AWSCloudTrail - AWS GuardDuty detector disabled or suspended EventName in "DeleteDetector,UpdateDetector"
AWSCloudTrail - Amazon ECR image scanning disabled EventName == "PutImageScanningConfiguration"
AWSCloudTrail - Changes made to AWS CloudTrail logs EventName in "DeleteEventBus,DeleteFlowLogs,DeleteTrail,StopLogging,UpdateTrail"
AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups EventName in "ApplySecurityGroupsToLoadBalancer,SetSecurityGroups"
AWSCloudTrail - Changes to AWS Security Group ingress and egress settings EventName in "AuthorizeSecurityGroupEgress,AuthorizeSecurityGroupIngress,RevokeSecurityGroupEgress,RevokeSecurityGroupIngress"
AWSCloudTrail - Changes to Amazon VPC settings EventName in "CreateInternetGateway,CreateNatGateway,CreateNetworkAclEntry,CreateRoute,CreateRouteTable"
EventSource != "apigateway.amazonaws.com"
AWSCloudTrail - Changes to internet facing AWS RDS Database instances EventName in "AuthorizeDBSecurityGroupIngress,CreateDBSecurityGroup,DeleteDBSecurityGroup,RevokeDBSecurityGroupIngress"
AWSCloudTrail - CloudFormation policy created then used for privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Config Service Resource Deletion Attempts EventName in "DeleteEventBus,DeleteFlowLogs,DeleteTrail,StopLogging,UpdateTrail"
AWSCloudTrail - Created CRUD S3 policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creating keys with encrypt policy without MFA EventName in "CreateKey,PutKeyPolicy"
AWSCloudTrail - Creation of Access Key for IAM User EventName == "CreateAccessKey"
AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creation of DataPipeline policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creation of EC2 policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creation of Glue policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Creation of Lambda policy and then privilege escalation
AWSCloudTrail - Creation of SSM policy and then privilege escalation
AWSCloudTrail - Creation of new CRUD IAM policy and then privilege escalation EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - EC2 Startup Shell Script Changed EventName in "CreateLaunchTemplate,ModifyInstanceAttribute"
AWSCloudTrail - ECR image scan findings high or critical EventName == "DescribeImageScanFindings"
AWSCloudTrail - Full Admin policy created and then attached to Roles, Users or Groups EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion"
AWSCloudTrail - Login to AWS Management Console without MFA EventName == "ConsoleLogin"
SessionIssuerUserName !contains "AWSReservedSSO"
AWSCloudTrail - Monitor AWS Credential abuse or hijacking EventName == "GetCallerIdentity"
UserIdentityType == "AssumedRole"
AWSCloudTrail - NRT Login to AWS Management Console without MFA EventName == "ConsoleLogin"
SessionIssuerUserName !contains "AWSReservedSSO"
AWSCloudTrail - Network ACL with all the open ports to a specified CIDR EventName in "CreateNetworkAclEntry,ReplaceNetworkAclEntry"
AWSCloudTrail - Policy version set to default EventName == "SetDefaultPolicyVersion"
AWSCloudTrail - Privilege escalation via CRUD DynamoDB policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via CRUD IAM policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via CRUD KMS policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via CRUD Lambda policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via CRUD S3 policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via CloudFormation policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via DataPipeline policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via EC2 policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via Glue policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via Lambda policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation via SSM policy EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy"
AWSCloudTrail - Privilege escalation with AdministratorAccess managed policy EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy"
AWSCloudTrail - Privilege escalation with FullAccess managed policy EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy"
AWSCloudTrail - Privilege escalation with admin managed policy EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy"
AWSCloudTrail - RDS instance publicly exposed EventName in "CreateDBInstance,ModifyDBInstance"
AWSCloudTrail - S3 Object Exfiltration from Anonymous User EventName == "GetObject"
UserIdentityPrincipalid == "Anonymous"
AWSCloudTrail - S3 bucket access point publicly exposed EventName == "PutAccessPointPolicy"
AWSCloudTrail - S3 bucket exposed via ACL EventName == "PutBucketAcl"
AWSCloudTrail - S3 bucket exposed via policy EventName == "PutBucketPolicy"
AWSCloudTrail - S3 bucket suspicious ransomware activity EventName in "GetObject,PutObject"
AWSCloudTrail - S3 object publicly exposed EventName == "PutObjectAcl"
AWSCloudTrail - SAML update identity provider EventName == "UpdateSAMLProvider"
AWSCloudTrail - SSM document is publicly exposed EventName == "ModifyDocumentPermission"
AWSCloudTrail - Successful API executed from a Tor exit node
AWSCloudTrail - Successful brute force attack on S3 Bucket EventName == "GetObject"
AWSCloudTrail - Suspicious AWS CLI Command Execution UserAgent startswith "aws-cli"
AWSCloudTrail - Suspicious AWS EC2 Compute Resource Deployments EventName == "RunInstances"
AWSCloudTrail - Suspicious command sent to EC2 EventName in "CreateAssociation,PutObject,SendCommand"
Resources contains "accountId"
AWSCloudTrail - Suspicious overly permissive KMS key policy created EventName in "CreateKey,PutKeyPolicy"
AWSCloudTrail - Tampering to AWS CloudTrail logs EventName in "DeleteEventBus,DeleteFlowLogs,DeleteLogGroup,DeleteTrail,StopLogging,UpdateTrail"
AWSCloudTrail - Unauthorized EC2 Instance Setup Attempt ErrorCode == "Client.UnauthorizedOperation"
EventName == "RunInstances"
AWSCloudTrail - User IAM Enumeration EventName in "ListAccessKeys,ListAttachedRolePolicies,ListAttachedUserPolicies,ListGroupsForUser,ListRoles,ListUsers"

In solution Apache Log4j Vulnerability Detection:

Analytic Rule Selection Criteria
Log4j vulnerability exploit aka Log4Shell IP IOC
User agent search for log4j exploitation attempt

In solution Business Email Compromise - Financial Fraud:

Analytic Rule Selection Criteria
Suspicious access of BEC related documents in AWS S3 buckets

In solution Cloud Identity Threat Protection Essentials:

Analytic Rule Selection Criteria
Multi-Factor Authentication Disabled for a User

In solution Multi Cloud Attack Coverage Essentials - Resource Abuse:

Analytic Rule Selection Criteria
Cross-Cloud Password Spray detection EventName == "ConsoleLogin"
High-Risk Cross-Cloud User Impersonation EventName in "AddUserToGroup,ChangePassword,CreateAccessKey,CreateGroup,CreateMailUser,CreateOrganization,CreateRole,CreateServiceSpecificCredential,CreateUser,CreateVirtualMFADevice,DeleteAccessKey,DeleteGroup,DeleteGroupPolicy,DeleteLoginProfile,DeleteRole,DeleteServiceSpecificCredential,DeleteUser,DisableMailUsers,EnableMailUsers,RegisterToWorkMail,RemoveUserFromGroup,ResetPassword,SetDefaultMailDomain,SetMailUserDetails,UpdateAccountEmailAddress,UploadServerCertificate"
EventSource in "iam.amazonaws.com,identitystore.amazonaws.com,workdocs.amazonaws.com,workmail.amazonaws.com"
Successful AWS Console Login from IP Address Observed Conducting Password Spray EventName == "ConsoleLogin"
Suspicious AWS console logins by credential access alerts EventName == "ConsoleLogin"
User impersonation by Identity Protection alerts EventName in "AddUserToGroup,ChangePassword,CreateAccessKey,CreateGroup,CreateRole,CreateUser,CreateVirtualMFADevice,DeleteAccessKey,DeleteGroup,DeleteLoginProfile,DeleteRole,DeleteUser,RemoveUserFromGroup"

In solution Network Threat Protection Essentials:

Analytic Rule Selection Criteria
New UserAgent observed in last 24 hours

In solution Threat Intelligence:

Analytic Rule Selection Criteria
TI map IP entity to AWSCloudTrail

In solution Threat Intelligence (NEW):

Analytic Rule Selection Criteria
TI map IP entity to AWSCloudTrail

Hunting Queries (37)

In solution Amazon Web Services:

Hunting Query Selection Criteria
AWSCloudTrail - AWS STS token suspicious activity from EC2
AWSCloudTrail - Activity in unused or unsupported cloud regions
AWSCloudTrail - EC2 Instance Launched Without Key Pair EventName == "RunInstances"
RequestParameters contains "userData"
AWSCloudTrail - ECR Container Image Low Severity Findings EventName == "DescribeImageScanFindings"
AWSCloudTrail - ECR Container Image Medium Severity Findings EventName == "DescribeImageScanFindings"
AWSCloudTrail - Failed Brute Force on S3 Bucket EventName == "GetObject"
UserIdentityAccountId == "ANONYMOUS_PRINCIPAL"
AWSCloudTrail - High Volume of Enumeration Events EventName startswith "Describe"
EventName startswith "Get"
EventName startswith "List"
UserAgent has "aws-cli"
AWSCloudTrail - IAM AccessDenied discovery events ErrorMessage in "Access Denied,AccessDenied"
UserAgent !endswith ".amazonaws.com"
UserIdentityType == "IAMUser"
AWSCloudTrail - IAM Assume Role Brute Force ErrorMessage == "AccessDenied"
EventName == "AssumeRole"
AWSCloudTrail - IAM CreateLoginProfile Activity EventName == "CreateLoginProfile"
AWSCloudTrail - IAM New Access Key Created for User EventName == "CreateAccessKey"
AWSCloudTrail - IAM Policy Change Activity EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion,DeleteGroupPolicy,DeletePolicy,DeletePolicyVersion,DeleteRolePolicy,DeleteUserPolicy,DetachGroupPolicy,DetachRolePolicy,PutGroupPolicy,PutUserPolicy"
AWSCloudTrail - IAM Policy with Excessive Wildcard Permissions EventName == "CreatePolicyVersion"
AWSCloudTrail - IAM Privilege Escalation by Instance Profile Attachment EventName in "AddRoleToInstanceProfile,RemoveRoleFromInstanceProfile"
AWSCloudTrail - IAM Privileged Role Attached to Instance EventName in "AddRoleToInstanceProfile,AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy"
AWSCloudTrail - IAM Risky Role Name Created EventName == "CreateRole"
AWSCloudTrail - IAM login profile updated EventName == "UpdateLoginProfile"
AWSCloudTrail - IAM suspicious STS AssumeRole from unseen identity EventName == "AssumeRole"
AWSCloudTrail - IAM user and group object changes EventName in "CreateUser,DeleteGroup,DeleteUser"
AWSCloudTrail - Lambda function code updated EventName startswith "UpdateFunctionCode"
EventSource == "lambda.amazonaws.com"
AWSCloudTrail - Lambda function throttled EventName startswith "PutFunctionConcurrency"
AWSCloudTrail - Lambda layer imported from external account EventName startswith "CreateFunction"
EventName startswith "UpdateFunctionConfiguration"
AWSCloudTrail - Multiple Failed Login Attempts Without MFA EventName == "ConsoleLogin"
AWSCloudTrail - Network ACL entry deleted EventName == "DeleteNetworkAclEntry"
AWSCloudTrail - RDS Master Password Changed EventName == "ModifyDBCluster"
AWSCloudTrail - Root User New Access Key Created EventName == "CreateAccessKey"
AWSCloudTrail - Route table attribute modifications EventName in "CreateRoute,DeleteRoute,ReplaceRoute"
AWSCloudTrail - S3 Bucket Deleted EventName == "DeleteBucket"
AWSCloudTrail - S3 Bucket Encryption Configuration Modified EventName in "DeleteBucketEncryption,PutBucketEncryption"
AWSCloudTrail - S3 Bucket Versioning Suspended EventName == "PutBucketVersioning"
AWSCloudTrail - STS Token Suspicious Activity from Kubernetes Worker Node
AWSCloudTrail - STS Token Suspicious Activity from Lambda
AWSCloudTrail - STS token suspicious activity from ECS
AWSCloudTrail - STS token suspicious activity from Glue
AWSCloudTrail - Subnet attribute modifications EventName == "ModifySubnetAttribute"
AWSCloudTrail - VPC attribute modifications EventName == "ModifyVpcAttribute"

In solution Network Threat Protection Essentials:

Hunting Query Selection Criteria
Exploit and Pentest Framework User Agent

Workbooks (8)

In solution Amazon Web Services:

Workbook Selection Criteria
AmazonWebServicesNetworkActivities EventName in "AllocateAddress,AssociateAddress,AuthorizeSecurityGroupEgress,AuthorizeSecurityGroupIngress,CreateNetworkAcl,CreateSecurityGroup,DeleteNetworkAcl,DeleteSecurityGroup,DisassociateAddress,ReleaseAddress,ReplaceNetworkAclEntry,RevokeSecurityGroupEgress,RevokeSecurityGroupIngress"
EventName !contains "Image"
EventName !contains "KeyPair"
EventName !contains "LaunchTemplate"
EventName !contains "Tags"
EventName !contains "Volume"
EventName startswith "authorize"
EventName startswith "create"
EventName startswith "delete"
EventName startswith "replace"
EventName startswith "revoke"
EventSource == "ec2.amazonaws.com"
AmazonWebServicesUserActivities EventName == "GetCallerIdentity"
EventName contains "Login"
EventName contains "login"
EventName contains "signin"
UserIdentityType in "AssumedRole,IAMUser"

In solution Apache Log4j Vulnerability Detection:

Workbook Selection Criteria
Log4jPostCompromiseHunting

In solution ContinuousDiagnostics&Mitigation:

Workbook Selection Criteria
ContinuousDiagnostics&Mitigation

In solution MaturityModelForEventLogManagementM2131:

Workbook Selection Criteria
MaturityModelForEventLogManagement_M2131

In solution NISTSP80053:

Workbook Selection Criteria
NISTSP80053

In solution SOC Handbook:

Workbook Selection Criteria
InvestigationInsights

In solution ZeroTrust(TIC3.0):

Workbook Selection Criteria
ZeroTrustTIC3

Parsers Using This Table (3)

ASIM Parsers (3)

Parser Schema Product Selection Criteria
ASimAuthenticationAWSCloudTrail Authentication AWS EventName == "ConsoleLogin"
ASimFileEventAWSCloudTrail FileEvent AWS Cloud Trail EventSource == "s3.amazonaws.com"
ASimUserManagementAWSCloudTrail UserManagement AWS Cloud Trail EventSource in "cognito-idp.amazonaws.com,iam.amazonaws.com"

Selection Criteria Summary (67 criteria, 99 total references)

References by type: 1 connectors, 95 content items, 3 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
EventName in "PutGroupPolicy,PutRolePolicy,PutUserPolicy" - 11 - - 11
EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion" - 10 - - 10
EventName == "ConsoleLogin" - 4 1 - 5
EventName == "DescribeImageScanFindings" - 3 - - 3
EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy" - 3 - - 3
EventName == "CreateAccessKey" - 3 - - 3
EventName in "DeleteEventBus,DeleteFlowLogs,DeleteTrail,StopLogging,UpdateTrail" - 2 - - 2
EventName == "ConsoleLogin"
SessionIssuerUserName !contains "AWSReservedSSO"
- 2 - - 2
EventName in "CreateKey,PutKeyPolicy" - 2 - - 2
EventName == "CreateUser" 1 - - - 1
EventName in "AuthorizeDBSecurityGroupIngress,CreateDBSecurityGroup,DeleteDBSecurityGroup,RevokeDBSecurityGroupIngress" - 1 - - 1
EventName in "CreateInternetGateway,CreateNatGateway,CreateNetworkAclEntry,CreateRoute,CreateRouteTable"
EventSource != "apigateway.amazonaws.com"
- 1 - - 1
EventName == "GetCallerIdentity"
UserIdentityType == "AssumedRole"
- 1 - - 1
EventName in "CreateLaunchTemplate,ModifyInstanceAttribute" - 1 - - 1
EventName == "PutImageScanningConfiguration" - 1 - - 1
EventName in "DeleteDetector,UpdateDetector" - 1 - - 1
EventName in "AuthorizeSecurityGroupEgress,AuthorizeSecurityGroupIngress,RevokeSecurityGroupEgress,RevokeSecurityGroupIngress" - 1 - - 1
EventName in "ApplySecurityGroupsToLoadBalancer,SetSecurityGroups" - 1 - - 1
EventName in "DeleteEventBus,DeleteFlowLogs,DeleteLogGroup,DeleteTrail,StopLogging,UpdateTrail" - 1 - - 1
EventName in "CreateNetworkAclEntry,ReplaceNetworkAclEntry" - 1 - - 1
EventName in "CreateDBInstance,ModifyDBInstance" - 1 - - 1
EventName == "GetObject" - 1 - - 1
EventName == "PutAccessPointPolicy" - 1 - - 1
EventName == "PutBucketAcl" - 1 - - 1
EventName == "PutBucketPolicy" - 1 - - 1
EventName == "GetObject"
UserIdentityPrincipalid == "Anonymous"
- 1 - - 1
EventName == "PutObjectAcl" - 1 - - 1
EventName in "GetObject,PutObject" - 1 - - 1
EventName == "UpdateSAMLProvider" - 1 - - 1
EventName == "SetDefaultPolicyVersion" - 1 - - 1
EventName == "ModifyDocumentPermission" - 1 - - 1
EventName in "CreateAssociation,PutObject,SendCommand"
Resources contains "accountId"
- 1 - - 1
ErrorCode == "Client.UnauthorizedOperation"
EventName == "RunInstances"
- 1 - - 1
EventName in "ListAccessKeys,ListAttachedRolePolicies,ListAttachedUserPolicies,ListGroupsForUser,ListRoles,ListUsers" - 1 - - 1
UserAgent startswith "aws-cli" - 1 - - 1
EventName == "RunInstances" - 1 - - 1
EventName in "AddUserToGroup,ChangePassword,CreateAccessKey,CreateGroup,CreateRole,CreateUser,CreateVirtualMFADevice,DeleteAccessKey,DeleteGroup,DeleteLoginProfile,DeleteRole,DeleteUser,RemoveUserFromGroup" - 1 - - 1
EventName in "AddUserToGroup,ChangePassword,CreateAccessKey,CreateGroup,CreateMailUser,CreateOrganization,CreateRole,CreateServiceSpecificCredential,CreateUser,CreateVirtualMFADevice,DeleteAccessKey,DeleteGroup,DeleteGroupPolicy,DeleteLoginProfile,DeleteRole,DeleteServiceSpecificCredential,DeleteUser,DisableMailUsers,EnableMailUsers,RegisterToWorkMail,RemoveUserFromGroup,ResetPassword,SetDefaultMailDomain,SetMailUserDetails,UpdateAccountEmailAddress,UploadServerCertificate"
EventSource in "iam.amazonaws.com,identitystore.amazonaws.com,workdocs.amazonaws.com,workmail.amazonaws.com"
- 1 - - 1
ErrorMessage == "AccessDenied"
EventName == "AssumeRole"
- 1 - - 1
EventName == "PutBucketVersioning" - 1 - - 1
EventName == "CreateLoginProfile" - 1 - - 1
EventName == "RunInstances"
RequestParameters contains "userData"
- 1 - - 1
EventName startswith "Describe"
EventName startswith "Get"
EventName startswith "List"
UserAgent has "aws-cli"
- 1 - - 1
EventName == "GetObject"
UserIdentityAccountId == "ANONYMOUS_PRINCIPAL"
- 1 - - 1
ErrorMessage in "Access Denied,AccessDenied"
UserAgent !endswith ".amazonaws.com"
UserIdentityType == "IAMUser"
- 1 - - 1
EventName in "CreateUser,DeleteGroup,DeleteUser" - 1 - - 1
EventName in "AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy,CreatePolicy,CreatePolicyVersion,DeleteGroupPolicy,DeletePolicy,DeletePolicyVersion,DeleteRolePolicy,DeleteUserPolicy,DetachGroupPolicy,DetachRolePolicy,PutGroupPolicy,PutUserPolicy" - 1 - - 1
EventName in "AddRoleToInstanceProfile,RemoveRoleFromInstanceProfile" - 1 - - 1
EventName startswith "PutFunctionConcurrency" - 1 - - 1
EventName startswith "CreateFunction"
EventName startswith "UpdateFunctionConfiguration"
- 1 - - 1
EventName startswith "UpdateFunctionCode"
EventSource == "lambda.amazonaws.com"
- 1 - - 1
EventName == "UpdateLoginProfile" - 1 - - 1
EventName in "CreateRoute,DeleteRoute,ReplaceRoute" - 1 - - 1
EventName == "ModifySubnetAttribute" - 1 - - 1
EventName == "ModifyVpcAttribute" - 1 - - 1
EventName == "DeleteNetworkAclEntry" - 1 - - 1
EventName == "CreatePolicyVersion" - 1 - - 1
EventName in "AddRoleToInstanceProfile,AttachGroupPolicy,AttachRolePolicy,AttachUserPolicy" - 1 - - 1
EventName == "ModifyDBCluster" - 1 - - 1
EventName == "CreateRole" - 1 - - 1
EventName == "DeleteBucket" - 1 - - 1
EventName in "DeleteBucketEncryption,PutBucketEncryption" - 1 - - 1
EventName == "AssumeRole" - 1 - - 1
EventName in "AllocateAddress,AssociateAddress,AuthorizeSecurityGroupEgress,AuthorizeSecurityGroupIngress,CreateNetworkAcl,CreateSecurityGroup,DeleteNetworkAcl,DeleteSecurityGroup,DisassociateAddress,ReleaseAddress,ReplaceNetworkAclEntry,RevokeSecurityGroupEgress,RevokeSecurityGroupIngress"
EventName !contains "Image"
EventName !contains "KeyPair"
EventName !contains "LaunchTemplate"
EventName !contains "Tags"
EventName !contains "Volume"
EventName startswith "authorize"
EventName startswith "create"
EventName startswith "delete"
EventName startswith "replace"
EventName startswith "revoke"
EventSource == "ec2.amazonaws.com"
- 1 - - 1
EventName == "GetCallerIdentity"
EventName contains "Login"
EventName contains "login"
EventName contains "signin"
UserIdentityType in "AssumedRole,IAMUser"
- 1 - - 1
EventSource == "s3.amazonaws.com" - - 1 - 1
EventSource in "cognito-idp.amazonaws.com,iam.amazonaws.com" - - 1 - 1
Total 1 95 3 0 99

ErrorCode

Value Connectors Content Items ASIM Parsers Other Parsers Total
Client.UnauthorizedOperation - 1 - - 1

ErrorMessage

Value Connectors Content Items ASIM Parsers Other Parsers Total
AccessDenied - 2 - - 2
Access Denied - 1 - - 1

EventName

Value Connectors Content Items ASIM Parsers Other Parsers Total
AttachGroupPolicy - 15 - - 15
AttachRolePolicy - 15 - - 15
AttachUserPolicy - 15 - - 15
CreatePolicyVersion - 12 - - 12
PutGroupPolicy - 12 - - 12
PutUserPolicy - 12 - - 12
CreatePolicy - 11 - - 11
PutRolePolicy - 11 - - 11
ConsoleLogin - 6 1 - 7
CreateAccessKey - 5 - - 5
CreateUser 1 3 - - 4
GetObject - 4 - - 4
DeleteEventBus - 3 - - 3
DeleteFlowLogs - 3 - - 3
DeleteTrail - 3 - - 3
StopLogging - 3 - - 3
UpdateTrail - 3 - - 3
DescribeImageScanFindings - 3 - - 3
RunInstances - 3 - - 3
CreateRole - 3 - - 3
DeleteGroup - 3 - - 3
DeleteUser - 3 - - 3
CreateNetworkAclEntry - 2 - - 2
CreateRoute - 2 - - 2
CreateKey - 2 - - 2
PutKeyPolicy - 2 - - 2
GetCallerIdentity - 2 - - 2
AuthorizeSecurityGroupEgress - 2 - - 2
AuthorizeSecurityGroupIngress - 2 - - 2
RevokeSecurityGroupEgress - 2 - - 2
RevokeSecurityGroupIngress - 2 - - 2
ReplaceNetworkAclEntry - 2 - - 2
PutObject - 2 - - 2
AddUserToGroup - 2 - - 2
ChangePassword - 2 - - 2
CreateGroup - 2 - - 2
CreateVirtualMFADevice - 2 - - 2
DeleteAccessKey - 2 - - 2
DeleteLoginProfile - 2 - - 2
DeleteRole - 2 - - 2
RemoveUserFromGroup - 2 - - 2
DeleteGroupPolicy - 2 - - 2
AssumeRole - 2 - - 2
AddRoleToInstanceProfile - 2 - - 2
AuthorizeDBSecurityGroupIngress - 1 - - 1
CreateDBSecurityGroup - 1 - - 1
DeleteDBSecurityGroup - 1 - - 1
RevokeDBSecurityGroupIngress - 1 - - 1
CreateInternetGateway - 1 - - 1
CreateNatGateway - 1 - - 1
CreateRouteTable - 1 - - 1
CreateLaunchTemplate - 1 - - 1
ModifyInstanceAttribute - 1 - - 1
PutImageScanningConfiguration - 1 - - 1
DeleteDetector - 1 - - 1
UpdateDetector - 1 - - 1
ApplySecurityGroupsToLoadBalancer - 1 - - 1
SetSecurityGroups - 1 - - 1
DeleteLogGroup - 1 - - 1
CreateDBInstance - 1 - - 1
ModifyDBInstance - 1 - - 1
PutAccessPointPolicy - 1 - - 1
PutBucketAcl - 1 - - 1
PutBucketPolicy - 1 - - 1
PutObjectAcl - 1 - - 1
UpdateSAMLProvider - 1 - - 1
SetDefaultPolicyVersion - 1 - - 1
ModifyDocumentPermission - 1 - - 1
CreateAssociation - 1 - - 1
SendCommand - 1 - - 1
ListAccessKeys - 1 - - 1
ListAttachedRolePolicies - 1 - - 1
ListAttachedUserPolicies - 1 - - 1
ListGroupsForUser - 1 - - 1
ListRoles - 1 - - 1
ListUsers - 1 - - 1
CreateMailUser - 1 - - 1
CreateOrganization - 1 - - 1
CreateServiceSpecificCredential - 1 - - 1
DeleteServiceSpecificCredential - 1 - - 1
DisableMailUsers - 1 - - 1
EnableMailUsers - 1 - - 1
RegisterToWorkMail - 1 - - 1
ResetPassword - 1 - - 1
SetDefaultMailDomain - 1 - - 1
SetMailUserDetails - 1 - - 1
UpdateAccountEmailAddress - 1 - - 1
UploadServerCertificate - 1 - - 1
PutBucketVersioning - 1 - - 1
CreateLoginProfile - 1 - - 1
startswith Describe - 1 - - 1
startswith Get - 1 - - 1
startswith List - 1 - - 1
DeletePolicy - 1 - - 1
DeletePolicyVersion - 1 - - 1
DeleteRolePolicy - 1 - - 1
DeleteUserPolicy - 1 - - 1
DetachGroupPolicy - 1 - - 1
DetachRolePolicy - 1 - - 1
RemoveRoleFromInstanceProfile - 1 - - 1
startswith PutFunctionConcurrency - 1 - - 1
startswith CreateFunction - 1 - - 1
startswith UpdateFunctionConfiguration - 1 - - 1
startswith UpdateFunctionCode - 1 - - 1
UpdateLoginProfile - 1 - - 1
DeleteRoute - 1 - - 1
ReplaceRoute - 1 - - 1
ModifySubnetAttribute - 1 - - 1
ModifyVpcAttribute - 1 - - 1
DeleteNetworkAclEntry - 1 - - 1
ModifyDBCluster - 1 - - 1
DeleteBucket - 1 - - 1
DeleteBucketEncryption - 1 - - 1
PutBucketEncryption - 1 - - 1
AllocateAddress - 1 - - 1
AssociateAddress - 1 - - 1
CreateNetworkAcl - 1 - - 1
CreateSecurityGroup - 1 - - 1
DeleteNetworkAcl - 1 - - 1
DeleteSecurityGroup - 1 - - 1
DisassociateAddress - 1 - - 1
ReleaseAddress - 1 - - 1
!contains Image - 1 - - 1
!contains KeyPair - 1 - - 1
!contains LaunchTemplate - 1 - - 1
!contains Tags - 1 - - 1
!contains Volume - 1 - - 1
startswith authorize - 1 - - 1
startswith create - 1 - - 1
startswith delete - 1 - - 1
startswith replace - 1 - - 1
startswith revoke - 1 - - 1
contains Login - 1 - - 1
contains login - 1 - - 1
contains signin - 1 - - 1

EventSource

Value Connectors Content Items ASIM Parsers Other Parsers Total
iam.amazonaws.com - 1 1 - 2
!= apigateway.amazonaws.com - 1 - - 1
identitystore.amazonaws.com - 1 - - 1
workdocs.amazonaws.com - 1 - - 1
workmail.amazonaws.com - 1 - - 1
lambda.amazonaws.com - 1 - - 1
ec2.amazonaws.com - 1 - - 1
s3.amazonaws.com - - 1 - 1
cognito-idp.amazonaws.com - - 1 - 1

RequestParameters

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains userData - 1 - - 1

Resources

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains accountId - 1 - - 1

SessionIssuerUserName

Value Connectors Content Items ASIM Parsers Other Parsers Total
!contains AWSReservedSSO - 2 - - 2

UserAgent

Value Connectors Content Items ASIM Parsers Other Parsers Total
startswith aws-cli - 1 - - 1
has aws-cli - 1 - - 1
!endswith .amazonaws.com - 1 - - 1

UserIdentityAccountId

Value Connectors Content Items ASIM Parsers Other Parsers Total
ANONYMOUS_PRINCIPAL - 1 - - 1

UserIdentityPrincipalid

Value Connectors Content Items ASIM Parsers Other Parsers Total
Anonymous - 1 - - 1

UserIdentityType

Value Connectors Content Items ASIM Parsers Other Parsers Total
AssumedRole - 2 - - 2
IAMUser - 2 - - 2

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index