Skip to content

Commit 7ba4dc0

Browse files
authored
Merge pull request #3405 from splunk/risk_message
update spl
2 parents df44136 + 2f12803 commit 7ba4dc0

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/cloud/aws_saml_update_identity_provider.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ data_source:
1717
- AWS CloudTrail UpdateSAMLProvider
1818
search: '`cloudtrail` eventName=UpdateSAMLProvider
1919
| rename user_name as user
20-
| stats count min(_time) as firstTime max(_time) as lastTime values(request_parameters) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product
20+
| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.sAMLProviderArn) as request_parameters by signature dest user user_agent src vendor_account vendor_region vendor_product
2121
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
2222
|`aws_saml_update_identity_provider_filter`'
2323
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This

0 commit comments

Comments
 (0)