Files
splunk-security_content/macros/securityGroupAPIs.yml
2019-10-16 16:38:05 +02:00

8 lines
536 B
YAML

definition: (eventName=AuthorizeSecurityGroupIngress OR eventName=CreateSecurityGroup
OR eventName=DeleteSecurityGroup OR eventName=DescribeClusterSecurityGroups OR eventName=DescribeDBSecurityGroups
OR eventName=DescribeSecurityGroupReferences OR eventName=DescribeSecurityGroups
OR eventName=DescribeStaleSecurityGroups OR eventName=RevokeSecurityGroupIngress
OR eventName=UpdateSecurityGroupRuleDescriptionsIngress)
description: This macro is a list of AWS event names associated with security groups
name: securityGroupAPIs