调查GuardDuty的发现
--resources[1].type , resources[1].uid,
SELECT region, accountid, finding.desc, finding.types, resources[1].region, resources[1].details, unmapped
FROM "amazon_security_lake_table_us_east_1_sh_findings_1_0"
where metadata.product.feature.name = 'GuardDuty'
and eventday >= '20230731' AND eventday <= '20230831'
and severity = 'Critical'
and state = 'New'

最后更新于