This documentation contains work-in-progress information for future Elastic Stack and Cloud releases. Use the version selector to view supported release docs. It also contains some Elastic Cloud serverless information. Check out our serverless docs for more details.
AWS RDS Instance/Cluster Stoppage
editAWS RDS Instance/Cluster Stoppage
editIdentifies that an Amazon Relational Database Service (RDS) cluster or instance has been stopped.
Rule type: query
Rule indices:
- filebeat-*
- logs-aws*
Severity: medium
Risk score: 47
Runs every: 10m
Searches indices from: now-60m (Date Math format, see also Additional look-back time
)
Maximum alerts per execution: 100
References:
- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/rds/stop-db-cluster.html
- https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_StopDBCluster.html
- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/rds/stop-db-instance.html
- https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_StopDBInstance.html
Tags:
- Elastic
- Cloud
- AWS
- Continuous Monitoring
- SecOps
- Asset Visibility
Version: 7
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editRule query
editevent.dataset:aws.cloudtrail and event.provider:rds.amazonaws.com and event.action:(StopDBCluster or StopDBInstance) and event.outcome:success
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Impact
- ID: TA0040
- Reference URL: https://attack.mitre.org/tactics/TA0040/
-
Technique:
- Name: Service Stop
- ID: T1489
- Reference URL: https://attack.mitre.org/techniques/T1489/