Runpanther incident

CloudTrail Classification Issues

Minor Resolved View vendor source →

Runpanther experienced a minor incident on May 13, 2025 affecting Data Ingestion into Panther (Log Processing), lasting 2h 4m. The incident has been resolved; the full update timeline is below.

Started
May 13, 2025, 08:55 PM UTC
Resolved
May 13, 2025, 10:59 PM UTC
Duration
2h 4m
Detected by Pingoru
May 13, 2025, 08:55 PM UTC

Affected components

Data Ingestion into Panther (Log Processing)

Update timeline

  1. identified May 13, 2025, 08:55 PM UTC

    Panther has identified an issue with the AWS.CloudTrail schema that is causing a small percentage of CloudTrail logs to raise classification errors and fail to ingest into Panther. We have identified the root cause of the issue and are in the process of deploying a fix. We will update this incident as our remediation process continues.

  2. resolved May 13, 2025, 10:59 PM UTC

    We have reverted the changes to the AWS.CloudTrail schema that were causing classification errors. At this time, you should not see any additional errors related to this issue. If you’d like to view the classification errors in your Panther Console, in Search, select the Monitor database and Classification Failures table. If you are interested in re-ingesting the logs that failed to ingest, please reach out to the Panther support team.