Abnormally High AWS Instances Launched by User
This search looks for CloudTrail events where a user successfully launches an abnormally high number of instances.
This content is not mapped to any local saved search. Add mapping
Abnormally High AWS Instances Launched by User Help
In this search, we query CloudTrail logs to look for events where an instance is successfully launched by a particular user. Since we want to detect a high number of instances launched within a short period, we create event buckets for 10-minute windows. We then calculate the total number of instances launched by a particular user, as well as the average and standard deviation values. Assign a