AwsCloudWatch - AWS Security Hub

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AwsCloudWatch

以下是AwsCloudWatch资源 AWS 的安全调查结果格式的示例。

AwsCloudWatchAlarm

AwsCloudWatchAlarm对象提供有关 Amazon CloudWatch 警报的详细信息,这些警报会监视指标或在警报状态发生变化时执行操作。

以下示例显示了AwsCloudWatchAlarm对象 AWS 的安全调查结果格式 (ASFF)。要查看AwsCloudWatchAlarm属性的描述,请参阅 “AWS Security Hub API参考AwsCloudWatchAlarmDetails中的。

示例

"AwsCloudWatchAlarm": { "ActonsEnabled": true, "AlarmActions": [ "arn:aws:automate:region:ec2:stop", "arn:aws:automate:region:ec2:terminate" ], "AlarmArn": "arn:aws:cloudwatch:us-west-2:012345678910:alarm:sampleAlarm", "AlarmConfigurationUpdatedTimestamp": "2022-02-18T15:31:53.161Z", "AlarmDescription": "Alarm Example", "AlarmName": "Example", "ComparisonOperator": "GreaterThanOrEqualToThreshold", "DatapointsToAlarm": 1, "Dimensions": [{ "Name": "InstanceId", "Value": "i-1234567890abcdef0" }], "EvaluateLowSampleCountPercentile": "evaluate", "EvaluationPeriods": 1, "ExtendedStatistic": "p99.9", "InsufficientDataActions": [ "arn:aws:automate:region:ec2:stop" ], "MetricName": "Sample Metric", "Namespace": "YourNamespace", "OkActions": [ "arn:aws:swf:region:account-id:action/actions/AWS_EC2.InstanceId.Stop/1.0" ], "Period": 1, "Statistic": "SampleCount", "Threshold": 12.3, "ThresholdMetricId": "t1", "TreatMissingData": "notBreaching", "Unit": "Kilobytes/Second" }