How can I configure an EventBridge rule for GuardDuty to send custom SNS notifications if specific AWS service event types trigger?

Last updated: 2022-10-31

I created an Amazon EventBridge rule to trigger on service event types for Amazon GuardDuty, but the responses are in JSON format. How can I receive an email response with a custom notification?

Short description

Use a custom event pattern with the EventBridge rule to match a specific finding type. Then, route the response to an Amazon Simple Notification Service (Amazon SNS) topic.

Resolution

This example uses an Amazon GuardDuty event type UnauthorizedAccess:EC2/MaliciousIPCaller.Custom.

Note: You can replace the service name and event type for your specific AWS service.

1.    If you haven't already created an Amazon SNS topic, follow the instructions for Getting started with Amazon SNS.

Note: The Amazon SNS topic must be in the same Region as your Amazon GuardDuty service.

2.    Open the EventBridge console.

3.    Select Create rule.

4.    Enter a Name for your rule. You can optionally enter a Description.

5.    Select the bus that the event applies to.

6.    In Rule type, select Rule with an event pattern. Then, select Next.

7.    Under Event pattern, choose AWS services for the Event source. Then, choose GuardDuty for the AWS service.

8.    For Event type, choose GuardDuty Finding.

9.    In the Event pattern preview section, select Edit pattern.

10.    Copy the following code, paste it in Event pattern preview section, and then choose Save.

{
  "source": [
    "aws.guardduty"
  ],
  "detail": {
    "type": [
      "UnauthorizedAccess:EC2/MaliciousIPCaller.Custom"
     ]
  }
}

11.    Select Next.

12.    For Target types, select AWS service.

13.    For Select a target, choose SNS topic. Then, select your topic from the drop-down menu.

14.    Select Next.

        (Optional) Add tags to your rule, and then select Next.

15.    Review the rule's details, and then select Create rule.

16.    Select Create at the bottom of the page.

17.    If an event type is triggered, then you receive an SNS notification on the SNS endpoint.