Amazon Inspector events
Amazon Inspector sends service events directly to EventBridge, as well as via Amazon CloudTrail.
Amazon Inspector service events
Amazon Inspector sends the following events directly to EventBridge:
Inspector Finding
Inspector Scan
Inspector2 Finding
Inspector2 Scan
Inspector2 Coverage
Inspector2 AutoEnable
Delivery type: Best effort
To match against all events from this service, create an event pattern that matches against the following event attribute:
source
: aws.inspector2
{ "source": ["aws.inspector2"] }
To match against specific events, include a detail-type
attribute
specifying an array of event names to match. For example:
{ "source": ["aws.inspector2"], "detail-type": ["
Inspector Finding
"] }
For more information, see Creating event patterns in the Amazon EventBridge User Guide.
Amazon Inspector events delivered via Amazon CloudTrail
Amazon CloudTrail sends events originating from Amazon Inspector to EventBridge. Amazon services deliver events to CloudTrail on a best effort basis. For more information, see Amazon service events delivered via Amazon CloudTrail in the Amazon EventBridge User Guide.
To match events from this service delivered by Amazon CloudTrail, create an event pattern that matches against the following event attributes:
source
: aws.inspector2eventSource
: inspector2.amazonaws.com
{ "source": ["aws.inspector2"], "detail-type": ["Amazon API Call via CloudTrail"], "detail": { "eventSource": ["inspector2.amazonaws.com"] } }
To match against a specific API calls from this service, include an
eventName
attribute specifying an array of API calls to match:
{ "source": ["aws.inspector2"], "detail-type": ["Amazon API Call via CloudTrail"], "detail": { "eventSource": ["inspector2.amazonaws.com"], "eventName": ["
api-action-name
"] } }