551252099d
* [Rule Tuning] AWS User Created Access Key For Another User Telemetry looks good for this rule, no way to change this from ESQL as we need to be able to compare fields. - added event.dataset to query - added source.ip, cloud.account.id, event.dataset, aws.cloudtrail.user_identity.access_key_id, and source.geo.* fields to `keep` - added to highlighted fields - updated IG * toml-lint