|  | 
|  | 1 | +{ | 
|  | 2 | +    "expected": [ | 
|  | 3 | +        { | 
|  | 4 | +            "@timestamp": "2024-10-10T15:07:03.000Z", | 
|  | 5 | +            "actor": { | 
|  | 6 | +                "entity": { | 
|  | 7 | +                    "id": [ | 
|  | 8 | +                        "arn:aws:iam::000000000:user/[email protected]" | 
|  | 9 | +                    ] | 
|  | 10 | +                } | 
|  | 11 | +            }, | 
|  | 12 | +            "aws": { | 
|  | 13 | +                "cloudtrail": { | 
|  | 14 | +                    "event_category": "Management", | 
|  | 15 | +                    "event_type": "AwsApiCall", | 
|  | 16 | +                    "event_version": "1.08", | 
|  | 17 | +                    "flattened": { | 
|  | 18 | +                        "request_parameters": { | 
|  | 19 | +                            "action": "lambda:InvokeFunction", | 
|  | 20 | +                            "functionName": "cloudtrail-events-test", | 
|  | 21 | +                            "principal": "sns.amazonaws.com", | 
|  | 22 | +                            "statementId": "sns" | 
|  | 23 | +                        }, | 
|  | 24 | +                        "response_elements": { | 
|  | 25 | +                            "statement": "{\"Sid\":\"sns\",\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"sns.amazonaws.com\"},\"Action\":\"lambda:InvokeFunction\",\"Resource\":\"arn:aws:lambda:us-east-1:000000000:function:cloudtrail-events-test\"}" | 
|  | 26 | +                        } | 
|  | 27 | +                    }, | 
|  | 28 | +                    "read_only": false, | 
|  | 29 | +                    "recipient_account_id": "000000000", | 
|  | 30 | +                    "request_id": "84a87304-e9d7-4a99-ae71-dfc74faf5f12", | 
|  | 31 | +                    "request_parameters": "{principal=sns.amazonaws.com, functionName=cloudtrail-events-test, statementId=sns, action=lambda:InvokeFunction}", | 
|  | 32 | +                    "response_elements": "{statement={\"Sid\":\"sns\",\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"sns.amazonaws.com\"},\"Action\":\"lambda:InvokeFunction\",\"Resource\":\"arn:aws:lambda:us-east-1:000000000:function:cloudtrail-events-test\"}}", | 
|  | 33 | +                    "user_identity": { | 
|  | 34 | +                        "access_key_id": "ACCESSKEYID", | 
|  | 35 | +                        "arn": "arn:aws:iam::000000000:user/[email protected]" , | 
|  | 36 | +                        "type": "IAMUser" | 
|  | 37 | +                    } | 
|  | 38 | +                } | 
|  | 39 | +            }, | 
|  | 40 | +            "cloud": { | 
|  | 41 | +                "account": { | 
|  | 42 | +                    "id": "000000000" | 
|  | 43 | +                }, | 
|  | 44 | +                "region": "us-east-1" | 
|  | 45 | +            }, | 
|  | 46 | +            "ecs": { | 
|  | 47 | +                "version": "8.11.0" | 
|  | 48 | +            }, | 
|  | 49 | +            "event": { | 
|  | 50 | +                "action": "AddPermission20150331v2", | 
|  | 51 | +                "created": "2021-11-11T01:02:03.123456789Z", | 
|  | 52 | +                "id": "98675cf5-df23-4169-8411-58429782c464", | 
|  | 53 | +                "kind": "event", | 
|  | 54 | +                "original": "{\"awsRegion\":\"us-east-1\",\"eventCategory\":\"Management\",\"eventID\":\"98675cf5-df23-4169-8411-58429782c464\",\"eventName\":\"AddPermission20150331v2\",\"eventSource\":\"lambda.amazonaws.com\",\"eventTime\":\"2024-10-10T15:07:03Z\",\"eventType\":\"AwsApiCall\",\"eventVersion\":\"1.08\",\"readOnly\":false,\"recipientAccountId\":\"000000000\",\"requestID\":\"84a87304-e9d7-4a99-ae71-dfc74faf5f12\",\"requestParameters\":{\"action\":\"lambda:InvokeFunction\",\"functionName\":\"cloudtrail-events-test\",\"principal\":\"sns.amazonaws.com\",\"statementId\":\"sns\"},\"responseElements\":{\"statement\":\"{\\\"Sid\\\":\\\"sns\\\",\\\"Effect\\\":\\\"Allow\\\",\\\"Principal\\\":{\\\"Service\\\":\\\"sns.amazonaws.com\\\"},\\\"Action\\\":\\\"lambda:InvokeFunction\\\",\\\"Resource\\\":\\\"arn:aws:lambda:us-east-1:000000000:function:cloudtrail-events-test\\\"}\"},\"sourceIPAddress\":\"216.160.83.56\",\"tlsDetails\":{\"cipherSuite\":\"TLS_AES_128_GCM_SHA256\",\"clientProvidedHostHeader\":\"lambda.us-east-1.amazonaws.com\",\"tlsVersion\":\"TLSv1.3\"},\"userAgent\":\"aws-cli/2.17.60 md/awscrt#0.21.2 ua/2.0 os/macos#23.6.0 md/arch#x86_64 lang/python#3.12.6 md/pyimpl#CPython exec-env/grimoire_8ce3f005-c362-4713-912a-4d6f5c122258 cfg/retry-mode#standard md/installer#exe md/prompt#off md/command#lambda.add-permission\",\"userIdentity\":{\"accessKeyId\":\"ACCESSKEYID\",\"accountId\":\"000000000\",\"arn\":\"arn:aws:iam::000000000:user/[email protected] \",\"principalId\":\"PRINCIPALID\",\"type\":\"IAMUser\",\"userName\":\"[email protected] \"}}", | 
|  | 55 | +                "outcome": "success", | 
|  | 56 | +                "provider": "lambda.amazonaws.com", | 
|  | 57 | +                "type": [ | 
|  | 58 | +                    "info" | 
|  | 59 | +                ] | 
|  | 60 | +            }, | 
|  | 61 | +            "related": { | 
|  | 62 | +                "entity": [ | 
|  | 63 | + | 
|  | 64 | +                    "ACCESSKEYID", | 
|  | 65 | +                    "arn:aws:iam::000000000:user/[email protected]", | 
|  | 66 | +                    "cloudtrail-events-test" | 
|  | 67 | +                ], | 
|  | 68 | +                "user": [ | 
|  | 69 | + | 
|  | 70 | +                ] | 
|  | 71 | +            }, | 
|  | 72 | +            "source": { | 
|  | 73 | +                "address": "216.160.83.56", | 
|  | 74 | +                "as": { | 
|  | 75 | +                    "number": 209 | 
|  | 76 | +                }, | 
|  | 77 | +                "geo": { | 
|  | 78 | +                    "city_name": "Milton", | 
|  | 79 | +                    "continent_name": "North America", | 
|  | 80 | +                    "country_iso_code": "US", | 
|  | 81 | +                    "country_name": "United States", | 
|  | 82 | +                    "location": { | 
|  | 83 | +                        "lat": 47.2513, | 
|  | 84 | +                        "lon": -122.3149 | 
|  | 85 | +                    }, | 
|  | 86 | +                    "region_iso_code": "US-WA", | 
|  | 87 | +                    "region_name": "Washington" | 
|  | 88 | +                }, | 
|  | 89 | +                "ip": "216.160.83.56" | 
|  | 90 | +            }, | 
|  | 91 | +            "tags": [ | 
|  | 92 | +                "preserve_original_event", | 
|  | 93 | +                "actor_target_mapping" | 
|  | 94 | +            ], | 
|  | 95 | +            "target": { | 
|  | 96 | +                "entity": { | 
|  | 97 | +                    "id": [ | 
|  | 98 | +                        "cloudtrail-events-test" | 
|  | 99 | +                    ] | 
|  | 100 | +                } | 
|  | 101 | +            }, | 
|  | 102 | +            "tls": { | 
|  | 103 | +                "cipher": "TLS_AES_128_GCM_SHA256", | 
|  | 104 | +                "client": { | 
|  | 105 | +                    "server_name": "lambda.us-east-1.amazonaws.com" | 
|  | 106 | +                }, | 
|  | 107 | +                "version": "1.3", | 
|  | 108 | +                "version_protocol": "tls" | 
|  | 109 | +            }, | 
|  | 110 | +            "user": { | 
|  | 111 | +                "id": "PRINCIPALID", | 
|  | 112 | + | 
|  | 113 | +            }, | 
|  | 114 | +            "user_agent": { | 
|  | 115 | +                "device": { | 
|  | 116 | +                    "name": "Other" | 
|  | 117 | +                }, | 
|  | 118 | +                "name": "aws-cli", | 
|  | 119 | +                "original": "aws-cli/2.17.60 md/awscrt#0.21.2 ua/2.0 os/macos#23.6.0 md/arch#x86_64 lang/python#3.12.6 md/pyimpl#CPython exec-env/grimoire_8ce3f005-c362-4713-912a-4d6f5c122258 cfg/retry-mode#standard md/installer#exe md/prompt#off md/command#lambda.add-permission", | 
|  | 120 | +                "version": "2.17.60" | 
|  | 121 | +            } | 
|  | 122 | +        } | 
|  | 123 | +    ] | 
|  | 124 | +} | 
0 commit comments