aws-route53-query-log-event

DNS query logs reveal queried names; applications that place credentials or user identifiers in hostnames leak them into logs.

awshigh service: aws:route53 emits ContainsSecret

Where it sits

locationCloudWatch Logs Route 53 query log event.message
location kindlog_field
data kindspii sensitive_data credential
emits edgeContainsSecret
serviceRoute 53 (aws:route53)

Collection recipe

access modeindirect_destination
operationlogs:FilterLogEvents
response pathEvents[].Message
encodingstring
params{"LogGroupName": "\u003croute53-query-log-group\u003e"}

Required permissions

logs:FilterLogEvents
route53:GetQueryLoggingConfig

References

move · open · esc close