i tried two solutions but it does not work :
- an arn with the wilcard
`{
"source": ["aws.signin"],
"detail-type": ["AWS Console Sign In via CloudTrail"],
"detail": {
"userIdentity": {
"type": ["AssumedRole"],
"arn": ["arn:aws:sts::1234567890:assumed-role/Role1/*"]
},
"eventName": ["SwitchRole"]
}
}`
- and the prefix, but it doesn't work :
`{
"source": ["aws.signin"],
"detail-type": ["AWS Console Sign In via CloudTrail"],
"detail": {
"userIdentity": {
"type": ["AssumedRole"],
"arn": [{
"prefix": "arn:aws:sts::1234567890:assumed-role/Role1/"
}]
},
"eventName": ["SwitchRole"]
}
}
`
It only works with a specific arn with a username known in advance like this :
`{
"source": ["aws.signin"],
"detail-type": ["AWS Console Sign In via CloudTrail"],
"detail": {
"userIdentity": {
"type": ["AssumedRole"],
"arn": ["arn:aws:sts::1234567890:assumed-role/Role1/banza.caleb"]
},
"eventName": ["SwitchRole"]
}
}`
Can anyone have a solution please?