Step1:创建 Cloud watch Rule 以通知创建。根据按下 lauch 按钮时 EC2 实例的生命周期。实例从 Pending 状态变为 Running 状态。所以创建待处理状态的规则
Create a Cloud watch Rule as specified in the image screenshot
Step2:创建一个 Step 函数。因为 cloud Trail 以至少 20 分钟的延迟记录帐户中的所有事件。如果您想要创建实例的用户的名称,此步骤功能很有用。
{
"StartAt": "Wait",
"States": {
"Wait": {
"Type": "Wait",
"Seconds": 1800,
"Next": "Ec2-Alert"
},
"Ec2-Alert":{
"Type": "Task",
"Resource":"arn:aws:lambda:ap-south-1:321039853697:function:EC2-Creation-Alert",
"End": true
}
}
}
Step3 : 创建通知的 SNS 主题
Step4 : 编写一个 lambda 函数从云跟踪中获取日志并获取创建实例的用户名。
import json
import os
import subprocess
import boto3
def lambda_handler(event, context):
client = boto3.client('cloudtrail')
client1 = boto3.client('sns')
Instance=event["detail"]["instance-id"]
response = client.lookup_events(
LookupAttributes=[
{
'AttributeKey': 'ResourceName',
'AttributeValue': Instance
},
],
MaxResults=1)
test=response['Events']
st="".join(str(x) for x in test)
print(st)
user=st.split("Username")[1]
finalname=user.split(",")
Creator=finalname[0]
#print(st[st.find("Username")])
Email= "Hi All ,\n\n\n The User%s has created new EC2-Instance in QA account and the Instance id is %s \n\n\n Thank you \n\n\n Regard's lamda"%(Creator,Instance)
response = client1.publish(
TopicArn='arn:aws:sns:ap-south-1:321039853697:Ec2-Creation-Alert',
Message=Email
)
# TODO implement
return {
'statusCode': 200,
}
注意:如果实例从停止状态更改为运行状态,此代码会触发通知。