aws-opensearch-serverless-collection-document-data

Serverless collection documents may contain plaintext credentials and sensitive application or log data.

awscritical service: aws:opensearch emits CanReadData

Where it sits

locationOpenSearch Serverless _search response _source fields
location kinddata_record
data kindscredential password api_key customer_data pii
emits edgeCanReadData
serviceOpenSearch (aws:opensearch)

Collection recipe

access modedata_plane
operationOpenSearch Serverless HTTP _search
response pathhits.hits[]._source
encodingjson
params{"CollectionEndpoint": "\u003cendpoint\u003e", "Index": "\u003cindex\u003e"}

Required permissions

aoss:APIAccessAll
aoss:DashboardsAccessAll

References

move · open · esc close