Received SNS Notification, but No findings in Console?

0

We received a notification via SNS of New Findings, but upon visiting the Guard Duty page, we don't see any findings reported. Also, the SNS notification does not mention the instance which generated the findings - Any pointers on how to find out the instance/service which generated these findings?

{"type": "NEW_FINDINGS",
"version": "1",
"findingDetails":[
{
"link": "https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-maliciousipcaller",
"findingType": "Impact:EC2/MaliciousDomainRequest.Reputation",
"findingDescription": "An EC2 instance is querying a low reputation domain that is associated with known malicious domains."
},...
}

drl
已提问 3 年前257 查看次数
1 回答
1

Figured out that we had subscribed to "GuardDuty Feature Announcements" - The language in documentation was bit unclear.

For folks who run into this issue:
The right way to configure this via a rule in Cloudwatch -https://aws.amazon.com/premiumsupport/knowledge-center/guardduty-cloudwatch-sns-rule/

drl
已回答 3 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则