Cloudwatch Filters

From Federal Burro of Information
Revision as of 21:06, 7 December 2017 by David (talk | contribs) (Created page with " http://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/FilterAndPatternSyntax.html { $.mfaAuthenticated = "false" } { $.userIdentity.type != "AssumedRole" } { ( $.even...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

http://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/FilterAndPatternSyntax.html

{ $.mfaAuthenticated = "false" }
{ $.userIdentity.type != "AssumedRole" }
{ ( $.eventSource != "iam.amazonaws.com" ) && ( $.eventSource != "cloudtrail.amazonaws.com" ) && ( $.eventSource != "elasticfilesystem.amazonaws.com" )}
{ ( $.eventSource = "ec2.amazonaws.com" ) && ( $.eventName != "DescribeInstanceStatus" ) }
{ $.userIdentity.sessionContext.attributes.mfaAuthenticated != "true" }