1 réponse
- Le plus récent
- Le plus de votes
- La plupart des commentaires
1
Your almost there.. You need to monitor EC2 as the source and not cloudtrail and use this pattern as the match. I have tested and this works. It only picks up if the IP Route Target changes and not the destination. If you want to detect if the destination changes, you need to also filter CreateRoute and DeleteRoute also.
Event Pattern
{
"source": [
"aws.ec2"
],
"detail-type": [
"AWS API Call via CloudTrail"
],
"detail": {
"eventSource": [
"ec2.amazonaws.com"
],
"eventName": [
"ReplaceRoute"
]
}
}
Side Note for terraform, instead of blowing it away, you could have imported the resource also of which it would tell you any differences from code to infrastructure
Contenus pertinents
- demandé il y a un an
- demandé il y a 7 mois
- AWS OFFICIELA mis à jour il y a 10 mois
- AWS OFFICIELA mis à jour il y a 2 ans
- AWS OFFICIELA mis à jour il y a 2 ans
- AWS OFFICIELA mis à jour il y a 8 mois
Thank you for this, much appreciated.