Amazon Security Lake - CloudTrail - Successful API Operation "" by user . · api.response.error = null, api.operation = \.*
Description
Amazon Security Lake - CloudTrail - Successful API Operation "$(api.operation)" by user $(identity.user.name).
Query · wazuh
field api.response.error="null" AND field api.operation="\.*" AND field identity.user.name="null" AND field src_endpoint.ip="null"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field activity_id="\.+" AND field category_uid="\.+" -
field metadata.product.name="CloudTrail" -
99025Amazon Security Lake - CloudTrail - Successful API Operation "" by user . · api.response.error = null, api.operation = \.* anchor level 3 this rulefield api.response.error="null" AND field api.operation="\.*" AND field identity.user.name="null" AND field src_endpoint.ip="null"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
99001