From acd855474bb39ffd5f4e4fe1df826e1b69ffdf4b Mon Sep 17 00:00:00 2001 From: bpatel Date: Wed, 13 Jan 2021 15:49:03 -0800 Subject: [PATCH] minor --- .../cloud/detect_aws_console_login_by_user_from_new_region.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index 26eb690c54..10b5d3d619 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -7,7 +7,7 @@ description: This search looks for CloudTrail events wherein a console login eve file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour -how_to_implement:You must install and configure the Splunk Add-on for AWS (version +how_to_implement: You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Run the `Previously Seen Users in CloudTrail - Initial` support search only once to create a baseline of previously seen IAM users within the last 30 days. Run `Previously Seen Users in CloudTrail - Update`