aws-cloudwatch-metric-dimension-values
Custom metric dimension values are plaintext and may accidentally encode usernames, account identifiers, or tokens.
Where it sits
| location | ListMetrics.Metrics[].Dimensions[].Value |
|---|---|
| location kind | metadata |
| data kinds | credential sensitive_data pii |
| emits edge | ContainsSecret |
| service | CloudWatch/Logs (aws:cloudwatch) |
Collection recipe
| access mode | read_api |
|---|---|
| operation | ListMetrics |
| response path | Metrics[].Dimensions[].Value |
| encoding | string |
| params | {"Namespace": "\u003cnamespace\u003e"} |
Required permissions
cloudwatch:ListMetrics