🔎

CloudTrailログ検索時に使うAthenaクエリ例

2022/03/15に公開

仕事でよく使うクエリ

EC2インスタンス新規作成

SELECT *
FROM sample_table
WHERE eventName='RunInstances'
 AND region = 'ap-northeast-1'
 AND date = '2022/03/05';

CloudFormationスタック作成

SELECT *
FROM sample_table
WHERE eventName='CreateStack'
 AND region = 'ap-northeast-1'
 AND date = '2022/03/05';

IAMロールが使用したAPI、呼び出し数の集計

SELECT DISTINCT(eventname),COUNT(*)
FROM sample_table
WHERE useridentity.sessioncontext.sessionissuer.arn =
'arn:aws:iam::000000000000:role/SampleRole'
 AND region = 'ap-northeast-1'
 AND date = '2022/03/05'
 GROUP BY eventname
 ORDER BY 2 desc;

Discussion