Identifies when a Route53 private hosted zone has been associated with VPC.
Rule type: query
Risk score: 21
Runs every: 10 minutes
Maximum alerts per execution: 100
- Continuous Monitoring
- Asset Visibility
Added (Elastic Stack release): 7.16.0
Rule authors: Austin Songer
Rule license: Elastic License v2
A private hosted zone may be asssociated with a VPC by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. If known behavior is causing false positives, it can be exempted from the rule.
## Config The AWS Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule.
event.dataset:aws.cloudtrail and event.provider:route53.amazonaws.com and event.action:AssociateVPCWithHostedZone and event.outcome:success