Splunk SOAR (f.k.a. Phantom)

AWS Guardduty App S3 Details Issue

splkphntmuser
New Member

The AWS Gaurdduty app from Splunk is not pulling in S3 details, when they normally are included in Gaurdduty alerts.

Normally, there would be a section for S3 details, when it is a part of an AWS Gaurdduty finding. AWS documentation can be seen here: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings-summary.html.

Wanted to see if anyone else is experiencing this same issue. This occurs with on-poll/ingestion or if using the action to go get the findings.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...