AWS Cloudtrail: - . Error: . · aws.errorCode = \.+
Description
AWS Cloudtrail: $(aws.eventSource) - $(aws.eventName). Error: $(aws.errorCode).
Query · wazuh
field aws.errorCode="\.+"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field integration="aws" -
field aws.source="cloudtrail" AND list aws.eventName lookup=match_key etc/lists/amazon/aws-eventnames -
field aws.errorCode="\.+"
Refined by
1 rule chains off this one, narrowing it further.
Rule dependencies
Depends on
-
composes · Wazuh if_sid
80202