in detection-ml-wksp/aws_lambda/cloudtrail_ingest.py [0:0]
def get_tuple(record):
"""
Turns a CloudTrail record into a tuple of <principal ID, IP address>.
:param record: a CloudTrail record for a single API event
:return: <principal ID, IP address> tuple
"""
ip = record['sourceIPAddress']
principal = record['userIdentity']['principalId'].split(':')[0]
return principal, ip