🔎
CloudTrailログ検索時に使うAthenaクエリ例
仕事でよく使うクエリ
EC2インスタンス新規作成
SELECT *
FROM sample_table
WHERE eventName='RunInstances'
AND region = 'ap-northeast-1'
AND date = '2022/03/05';
CloudFormationスタック作成
SELECT *
FROM sample_table
WHERE eventName='CreateStack'
AND region = 'ap-northeast-1'
AND date = '2022/03/05';
IAMロールが使用したAPI、呼び出し数の集計
SELECT DISTINCT(eventname),COUNT(*)
FROM sample_table
WHERE useridentity.sessioncontext.sessionissuer.arn =
'arn:aws:iam::000000000000:role/SampleRole'
AND region = 'ap-northeast-1'
AND date = '2022/03/05'
GROUP BY eventname
ORDER BY 2 desc;
Discussion