cloudtrail_analyze
Analyze AWS CloudTrail logs to extract event timelines, identify unique users, categorize event types, and track source IPs for security auditing.
Instructions
Parse and analyze AWS CloudTrail logs.
Extracts event timeline, unique users, event types, and source IPs.
Returns: {"event_count": int, "unique_users": [str], "event_types": [str], "source_ips": [str], "timeline": str}.
Side effects: Read-only file analysis. Requires jq.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| log_dir | Yes | Directory containing CloudTrail JSON log files |