38
loading...
This website collects cookies to deliver better user experience
AttachRolePolicy
API call)CreateDefaultVpc
API call)CreateSubnet
API call)CreateTrail
API call)DescribeSubnets
), and Write - any modification requests (for example, TerminateInstances
), see Read and write events.GetObject
, DeleteObject
, and PutObject
AuthorizeSecurityGroupIngress
.{ ($.eventName = ConsoleLogin) && ($.sourceIPAddress != "8.8.8.8") }
{ ($.eventName = ConsoleLogin) && ($.userIdentity.type = "Root") }
{ ($.eventName = ConsoleLogin) && ($.errorMessage = "Failed authentication") }
{ ($.errorCode = "\*UnauthorizedOperation") || ($.errorCode = "AccessDenied\*") }
{ ($.eventName = RunInstances) && (($.requestParameters.instanceType = \*.8xlarge) || ($.requestParameters.instanceType = \*.4xlarge)) }
{ $.eventName="CreateUser" }
ConsoleLogin
:{ ($.eventName = ConsoleLogin) }
:Message.extract()
call:{{Message.extract(/AlarmDescription":"(.+)","AWSAccountId"/)}}
AWS account ID: {{Message.extract(/AWSAccountId":"(.+)","NewStateValue"/)}}
AWS region: {{Message.extract(/Region":"(.+)","AlarmArn"/)}}
AlarmDescription
, AWSAccountId
, and Region
, and as result, we will see in Slack alarm's message in the next form:38