Cloud Compute Instance Started In Previously Unused Region
This search looks at cloud-infrastructure events where an instance is created in any region within the last hour and then compares it to a lookup file of previously seen regions where instances have been created.
This content is not mapped to any local saved search. Add mapping
Cloud Compute Instance Started In Previously Unused Region Help
You must be ingesting the appropriate cloud-infrastructure logs and have the Security Research cloud data model (https://github.com/splunk/cloud-datamodel-security-research/) installed. Run the \"Previously Seen Cloud Compute Instance Types\" support search to create a baseline of previously seen regions.
Open in Search