AWS guardduty: Fix EventBridge notification template to valid single-line JSON
Summary
Replaces the multi-line bare-string EventBridge input template with a single-line JSON object using a `message` key and `\n` escapes, and adds an Important note warning that unescaped control characters in finding fields can produce invalid JSON and cause EventBridge to reject the event.
Security assessment
This corrects a configuration example that could silently break security notification delivery (EventBridge rejecting events), which has security-monitoring impact, but it is a documentation/format fix rather than a vulnerability remediation.
Evidence
+Provide the template as a single-line JSON object with the message wrapped in a key such as `message`, as shown in the preceding example, and use `\n` to add line breaks. GuardDuty finding fields such as `description` can contain unescaped control characters, including newlines. If you provide the template as a bare quoted string, or place such a field into a multi-line template (one that uses separate quoted strings on separate lines), the substituted value can produce invalid JSON, which causes EventBridge to reject the event and fail to deliver the notification.
Diff
diff --git a/guardduty/latest/ug/guardduty_findings_eventbridge.md b/guardduty/latest/ug/guardduty_findings_eventbridge.md index 407bf6a7e..56f96813c 100644 --- a//guardduty/latest/ug/guardduty_findings_eventbridge.md +++ b//guardduty/latest/ug/guardduty_findings_eventbridge.md @@ -327,4 +327 @@ On the **Select target(s)** page, do the following: - "You have a severity <severity> GuardDuty finding type <Finding_Type> in the <region> Region." - "Finding Description:" - "<Finding_Description>. " - "For more details open the GuardDuty console at https://console.aws.amazon.com/guardduty/home?region=<region>#/findings?search=id%3D<Finding_ID>" + {"message":"You have a severity <severity> GuardDuty finding type <Finding_Type> in the <region> Region.\n\nFinding Description:\n<Finding_Description>.\n\nFor more details open the GuardDuty console at https://console.aws.amazon.com/guardduty/home?region=<region>#/findings?search=id%3D<Finding_ID>"} @@ -332,0 +330,4 @@ On the **Select target(s)** page, do the following: +###### Important + +Provide the template as a single-line JSON object with the message wrapped in a key such as `message`, as shown in the preceding example, and use `\n` to add line breaks. GuardDuty finding fields such as `description` can contain unescaped control characters, including newlines. If you provide the template as a bare quoted string, or place such a field into a multi-line template (one that uses separate quoted strings on separate lines), the substituted value can produce invalid JSON, which causes EventBridge to reject the event and fail to deliver the notification. +