Slide 23
Slide 23 text
AWS CloudTrail LakeがAWS Config連携に対応
検証(5/5)
23
SELECT
config.eventTime, config.eventData.configuration, config.eventData.resourceId, config.eventData.resourceName,
config.eventData.resourceType, userIdentity.username, trail.eventName, trail.eventSource
FROM
AS config JOIN AS trail ON config.eventData.resourceName =
element_at(trail.requestParameters, 'groupName')
WHERE
config.eventTime > '2022-12-02 17:00:00' AND config.eventTime < '2022-12-02 18:00:00'
ORDER
AWS CloudTrail用のイベントデータストアと結合することで、
より詳細な調査が可能