Skip to content

Commit b4664f0

Browse files
authored
Merge pull request #476 from splunk/aws_cross_account_activity_fix
minor tweak
2 parents 8c4fb32 + 0b1adab commit b4664f0

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

detections/aws_cross_account_activity_from_previously_unseen_account.yml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,7 @@ author: David Dorsey, Splunk
1515
search: '`cloudtrail` eventName=AssumeRole | spath output=requestingAccountId path=userIdentity.accountId
1616
| spath output=requestedAccountId path=resources{}.accountId | search requestingAccountId=*
1717
| where requestingAccountId != requestedAccountId | inputlookup append=t previously_seen_aws_cross_account_activity
18-
| multireport [| stats min(eval(coalesce(firstTime, _time)))
19-
as firstTime max(eval(coalesce(lastTime, _time)))
18+
| multireport [| stats min(eval(coalesce(firstTime, _time))) as firstTime max(eval(coalesce(lastTime, _time)))
2019
as lastTime by requestingAccountId, requestedAccountId | outputlookup previously_seen_aws_cross_account_activity
2120
| where fact=fiction] [| eventstats min(eval(coalesce(firstTime, _time))) as firstTime,
2221
max(eval(coalesce(lastTime, _time))) as lastTime by requestingAccountId, requestedAccountId | where firstTime

0 commit comments

Comments
 (0)