EC2 Instance Started In Previously Unseen Region


This search looks for CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file of previously seen regions where an instance was started


EC2 Instance Started In Previously Unseen Region Help

You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Run the "Previously seen AWS Regions" support search only once to create of baseline of previously seen regions. This search is deprecated and have been translated to use the latest Change Datamodel.


   Baseline Generation Searches

This detection relies on the following search to generate the baseline lookup.

  • Previously Seen AWS Regions