Skip to main content

Cloud Activity Anomaly Alerts

Lacework generates cloud-activity-based alerts when there are cloud-activity-related vulnerabilities detected. You can define alert rules to trigger alerts when cloud-activity-related vulnerabilities are found. See Alert Rules.

AWS Activity Alerting

The following polygraph changes result in node alerts or edge alerts as listed below:

Google Cloud Activity Alerting

The following polygraph changes result in node alerts or edge alerts as listed below:

Alert Name Alert Type Alert Subcategory
New GCP API callNewGcpApiCallCloud Activity
New GCP organizationNewGcpOrganizationCloud Activity
New GCP regionNewGcpRegionCloud Activity
New GCP serviceNewGcpServiceCloud Activity
New GCP sourceNewGcpSource
NewGcpSourceForServiceAccount
Cloud Activity
New GCP userNewGcpUserCloud Activity
New API invoked for Google Cloud service

Note:
Legacy name: Service called GCP API
ServiceCalledGcpApiCloud Activity
Note: GKE Kubernetes logs do not contain populated request fields so they will display as NULL in the dossiers.

Azure Activity Alerting

The following polygraph changes result in node alerts or edge alerts as listed below:

Suppress an Alert

Suppressing specific cloud-activity alerts reduces the number of alerts and allows you to focus on the assets that are most important to you. For details, see Suppress Behavior Anomaly Alerts.