အကြောင်းအရာသို့ ကရန်

ခွဲခြမ်းစိတ်ဖြာ ညွှန်ကြားချက်များ (Analysis Commands)

aws-ct-metrics command

AWS CloudTrail logs များအတွင်းရှိ fields များအပေါ် metrics များ ဖန်တီးရန် ဤ command ကို အသုံးပြုပါ။ ပုံသေအားဖြင့် ၎င်းသည် eventName field ကို scan လုပ်ပါမည်။ မည်သည့် API calls များ အများဆုံးဖြစ်သည်ကို သိရှိနိုင်ရန်နှင့် detection rules ရေးသားခြင်းကို ဦးစားပေးနိုင်ရန်အတွက် ဤ command ကို ကျွန်ုပ်တို့ လက်ရှိ အသုံးပြုနေပါသည်။

Command usage

Usage: suzaku aws-ct-metrics <INPUT> [OPTIONS]

Input:
  -d, --directory <DIR>  Directory of multiple gz/json files
  -f, --file <FILE>      File path to one gz/json file

Filtering:
  -s, --include-sts-keys       Include temporary AWS STS access key IDs
      --timeline-start <DATE>  Start time of the events to load (ex: "2022-02-22T23:59:59Z)
      --timeline-end <DATE>    End time of the events to load (ex: "2020-02-22T00:00:00Z")
      --time-offset <OFFSET>   Scan recent events based on an offset (ex: 1y, 3M, 30d, 24h, 30m)
      --file-date-from <DATE>  Filter files by start date based on AWSLogs S3 path date structure (ex: "20240101")
      --file-date-to <DATE>    Filter files by end date based on AWSLogs S3 path date structure (ex: "20241231")

Output:
  -F, --field-name <FIELD_NAME,...>  The field(s) to generate metrics for. Comma-separate or repeat to aggregate several in a single scan, e.g. -F sourceIPAddress,userAgent [default: eventName]
  -C, --clobber                      Overwrite files when saving
  -G, --geo-ip <MAXMIND-DB-DIR>      Add GeoIP (ASN, city, country) info to IP addresses [alias: --GeoIP]
  -o, --output <FILE>                Save the results to a file
  -t, --output-type <FORMAT,...>     Output format(s) (only used with -o): csv (default), json, jsonl, duckdb. Comma-separate or repeat to write several at once, e.g. -t csv,duckdb [default: csv] [possible values: csv, json, jsonl, duckdb]

General Options:
  -h, --help  Show the help menu

Display Settings:
  -K, --no-color  Disable color output
  -q, --quiet     Quiet mode: do not display the launch banner

aws-ct-metrics command ဥပမာများ

  • eventName API calls များ၏ ဇယားကို မျက်နှာပြင်ပေါ်တွင် ထုတ်ပြရန်: ./suzaku aws-ct-metrics -d ../suzaku-sample-data
  • CSV file တစ်ခုသို့ သိမ်းဆည်းရန်: ./suzaku aws-ct-metrics -d ../suzaku-sample-data -o sample-metrics.csv