August 21, 2026
EventTimeline
Convert AWS CloudTrail saved-search alerts into chronological investigation timelines with normalized context, MITRE mapping, entity pivots, manual searches, and exportable evidence.Built by anish upadhyaSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
EventTimeline turns AWS CloudTrail alerts from Splunk saved searches into structured, chronological investigations. When a saved search triggers, EventTimeline creates a normalized finding containing the alert context, actor, resource, source IP, account, API action, severity, and event timestamp. Analysts can then fetch related CloudTrail activity for a selected investigation window and review what happened before, during, and after the alert. EventTimeline includes chronological evidence views, MITRE ATT&CK and kill-chain context, identity and resource pivots, raw-event access, timeline filtering, Markdown export, a manual timeline generator, and timeline health diagnostics. The app does not include proprietary detection content or require an AI provider. It works with your existing CloudTrail saved searches and allows teams to retain control over their detection logic and investigation workflow.
Log in to report this app listing.