AWS EventBridge Cloudtrail 日志 ResponeElement 标签

问题描述

我正在尝试获取用户无法登录 AWS 控制台的警报。 我根据云跟踪日志编写了事件桥接规则。 原始日志

{
    "eventVersion": "1.08","userIdentity": {
        "type": "IAMUser","principalId": "XXXXXXXXXXXXX","accountId": "XXXXXXXXXXX","accessKeyId": "","userName": "XXXXXXXX"
    },"eventTime": "XXXXXXXXXXXXXXX","eventSource": "signin.amazonaws.com","eventName": "ConsoleLogin","awsRegion": "us-east-1","sourceIPAddress": "XXXXXXXXX","userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,like Gecko) Chrome/92.0.4515.107 Safari/537.36","errorMessage": "Failed authentication","requestParameters": null,"responseElements": {
        "ConsoleLogin": "Failure"
    },

这里我想把 Input 作为 ConsoleLogin": "Failure" 如何在 Eventbridge 中创建规则。

EventBridge 规则。

{
  "detail-type": [
    "AWS Console Sign In via CloudTrail"
  ],"detail": {
    "eventSource": [
      "signin.amazonaws.com"
    ],"eventName": [
      "ConsoleLogin"
    ],"type": [
      "Root","AssumedRole","IAMUser"
    ],"responseElements": {
      "ConsoleLogin": [
        "Failure"
      ]
    }
  }
}

这是正确的规则吗。

解决方法

暂无找到可以解决该程序问题的有效方法,小编努力寻找整理中!

如果你已经找到好的解决方法,欢迎将解决方案带上本链接一起发送给小编。

小编邮箱:dio#foxmail.com (将#修改为@)