aws-emr-cluster-log-object-content

EMR logs can expose full command lines, configuration values, sampled records, and application errors.

awscritical service: aws:emr emits ContainsCredential

Where it sits

locationS3 or CloudWatch EMR step/bootstrap/application log
location kindlog_field
data kindscredential password api_key access_key secret_key customer_data pii
emits edgeContainsCredential
serviceEMR (aws:emr)

Collection recipe

access modeindirect_destination
operations3:GetObject or logs:FilterLogEvents
response pathlog object or event message
encodingstring
params{"ClusterId": "\u003ccluster-id\u003e", "Destination": "\u003clog-uri\u003e"}

Required permissions

elasticmapreduce:DescribeCluster
s3:GetObject

References

move · open · esc close