aws-cloudwatch-log-event-message

CloudWatch Logs event messages are arbitrary application and service output and are one of the broadest plaintext credential exposure surfaces in AWS.

awscritical service: aws:cloudwatch emits CanReadData

Where it sits

locationlogs:FilterLogEvents.events[].message
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token bearer_token private_key connection_string customer_data pii
emits edgeCanReadData
serviceCloudWatch/Logs (aws:cloudwatch)

Collection recipe

access moderead_api
operationFilterLogEvents
response pathevents[].message
encodingstring
params{"logGroupName": "\u003clog-group\u003e"}

Required permissions

logs:FilterLogEvents

References

move · open · esc close