aws-networkfirewall-alert-flow-log-destination

Firewall alert and flow records can reveal application metadata and, depending on rule/log content, fragments of packet data.

awshigh service: aws:networkfirewall emits ContainsSecret

Where it sits

locationCloudWatch Logs/S3/Firehose Network Firewall log record
location kindlog_field
data kindscredential api_key bearer_token customer_data pii sensitive_data
emits edgeContainsSecret
serviceNetwork Firewall (aws:networkfirewall)

Collection recipe

access modeindirect_destination
operationlogs:FilterLogEvents or s3:GetObject
response pathlog event message or object body
encodingstring
params{"Destination": "\u003clogging-destination\u003e"}

Required permissions

network-firewall:DescribeLoggingConfiguration
logs:FilterLogEvents

References

move · open · esc close