mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
minor
This commit is contained in:
@@ -7,7 +7,7 @@ description: This search looks for CloudTrail events wherein a console login eve
|
||||
file of previously seen users (by ARN values) who have logged into the console.
|
||||
The alert is fired if the user has logged into the console for the first time within
|
||||
the last hour
|
||||
how_to_implement:You must install and configure the Splunk Add-on for AWS (version
|
||||
how_to_implement: You must install and configure the Splunk Add-on for AWS (version
|
||||
5.1.0 or later) and Enterprise Security 6.2, which contains the required updates
|
||||
to the Authentication data model for cloud use cases. Run the `Previously Seen Users in CloudTrail - Initial` support search only once to create a baseline of previously seen
|
||||
IAM users within the last 30 days. Run `Previously Seen Users in CloudTrail - Update`
|
||||
|
||||
Reference in New Issue
Block a user