how_to_implement:You must install Splunk Add-on for Amazon Web Services and Splunk App for AWS. This search works with cloudwatch logs. known_false_positives:Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. References: drilldown_searches:
: tags: analytic_story: - 'Kubernetes Sensitive Object Access Activity' asset_type:AWS EKS Kubernetes cluster product: - 'Splunk Enterprise' - 'Splunk Enterprise Security' - 'Splunk Cloud' security_domain:threat