S3 Access logs queries
Find the DISTINCT IP addresses communicating with an S3 bucket and rank
SELECT
remoteip,
count(1) AS total_rows
FROM panther_logs.public.aws_s3serveraccess
WHERE
p_occurs_between('2021-01-01', '2021-02-01')
AND
bucket='somebucket'
GROUP BY remoteip
ORDER BY total_rows DESCLast updated
Was this helpful?

