Skip to content

Commit

Permalink
Add data events detection to AWSID infra (#331)
Browse files Browse the repository at this point in the history
  • Loading branch information
jayjb authored Jan 12, 2024
1 parent ca1e028 commit 105ee0a
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions aws-token-infra/awsid.tf
Original file line number Diff line number Diff line change
Expand Up @@ -248,6 +248,20 @@ resource "aws_cloudtrail" "canarytoken_logs" {
s3_key_prefix = ""
cloud_watch_logs_group_arn = "${aws_cloudwatch_log_group.process_user_api_tokens_logs.arn}:*"
cloud_watch_logs_role_arn = aws_iam_role.process_user_api_tokens_logs_cloudtrail.arn
event_selector {
read_write_type = "All"
include_management_events = true

data_resource {
type = "AWS::S3::Object"
values = ["arn:aws:s3:::"]
}

data_resource {
type = "AWS::Lambda::Function"
values = ["arn:aws:lambda"]
}
}
}

# ProcessUserAPITokensLogs
Expand Down

0 comments on commit 105ee0a

Please sign in to comment.