Detect S3 Access From A New IP


This search looks at S3 bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed an S3 bucket.


Detect S3 Access From A New IP Help

You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your S3 access logs' inputs. This search works best when you run the "Previously Seen S3 Bucket Access by Remote IP" support search once to create a history of previously seen remote IPs and bucket names.


   Baseline Generation Searches

This detection relies on the following search to generate the baseline lookup.

  • Previously seen S3 bucket access by remote IP