Unauthorized attempts
SELECT *
FROM "amazon_security_lake_table_us_east_1_cloud_trail_mgmt_1_0"
where eventday >= '20231012'
AND eventday <= '20231112'
and actor.user.type != 'AWSService'
and actor.user.uuid LIKE '%iam%'
and status != 'Success'
and api.response.error IN ('Client.UnauthorizedOperation','Client.InvalidPermission.NotFound','Client.OperationNotPermitted','AccessDenied')
ORDER BY eventday desc最后更新于