Cloud Compute Instance Created With Previously Unseen Instance Type

Description

Find EC2 instances being created with previously unseen instance types.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Security Monitoring

Category

Cloud Security

Alert Volume

Find EC2 instances being created with previously unseen instance types.

SPL Difficulty

None

Journey

Stage 3

Data Sources

Cloud Infrastructure Data

   Help

Cloud Compute Instance Created With Previously Unseen Instance Type Help

You must be ingesting your cloud infrastructure logs from your cloud provider. You should run the baseline search Previously Seen Cloud Compute Instance Types - Initial to build the initial table of instance types observed and times. You must also enable the second baseline search Previously Seen Cloud Compute Instance Types - Update to keep this table up to date and to age out old data. You can also provide additional filtering for this search by customizing the cloud_compute_instance_created_with_previously_unseen_instance_type_filter macro.

   Search

Open in Search