Detect New Open S3 Buckets
This search looks for CloudTrail events where a user has created an open/public S3 bucket.
This content is not mapped to any local saved search. Add mapping
Detect New Open S3 Buckets Help
You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), and then configure your CloudTrail inputs. The threshold value should be tuned to your environment.
Open in Search