调查可疑用户
SELECT metadata.uid, type_name, api.service.name, eventday, actor.user.uuid
FROM "amazon_security_lake_table_us_east_1_cloud_trail_mgmt_1_0"
WHERE eventday > '20231001' AND eventday < '20231118'
and actor.user.uuid like '%SCSyncUser%'SELECT api.operation, api.service.name, src_endpoint.ip, severity, status
FROM "amazon_security_lake_table_us_east_1_cloud_trail_mgmt_1_0"
WHERE
accountid = '<Account Id number>'
AND actor.user.credential_uid = 'AKIAY625JPUY55PBUEWT'
AND eventday >= '20231008'
AND eventday <= '20231008'
GROUP BY api.operation, api.service.name, src_endpoint.ip, severity, status
ORDER BY src_endpoint.ip最后更新于