Cloud Compute Instance Created With Previously Unseen Instance Type

Description

Find EC2 instances being created with previously unseen instance types.

   Help

Cloud Compute Instance Created With Previously Unseen Instance Type Help

You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search Previously Seen Cloud Compute Instance Types - Initial to build the initial table of instance types observed and times. You must also enable the second baseline search Previously Seen Cloud Compute Instance Types - Update to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the cloud_compute_instance_created_with_previously_unseen_instance_type_filter macro.

   Search

Open in Search

   Baseline Generation Searches

This detection relies on the following searches to generate the baseline lookup.

  • Previously Seen Cloud Compute Instance Types - Initial
  • Previously Seen Cloud Compute Instance Types - Update