CloudTrail logs queries
Find all records for a particular AWS Access Key ID (AKID) in CloudTrail
SELECT
*
FROM panther_logs.public.aws_cloudtrail
WHERE p_occurs_since('1 day')
AND array_contains('ASIAVHOW5LG5FQ4R74ZZ'::variant, p_any_trace_ids)
ORDER BY p_event_time ASC
LIMIT 100Find all console "root" sign-ins in CloudTrail
SELECT
*
FROM panther_logs.public.aws_cloudtrail
WHERE
p_occurs_between('2021-01-01', '2021-01-02')
AND
eventtype = 'AwsConsoleSignIn'
AND
useridentity:arn LIKE '%root%'
ORDER BY p_event_time ASC
LIMIT 100Find all the sourceIPAddresses for console logins in CloudTrail and rank
Show CloudTrail activity related to an AWS instance
Show CloudTrail activity related to an AWS role
Show CloudTrail activity related to an AWS account id
Show all instance launches in CloudTrail
Last updated
Was this helpful?

