CYDERES supports the ingestion of AWS CloudTrail logs via a S3 Bucket.
Chronicle Data Types
- Create a new S3 bucket for the CloudTrail logs to be stored in. Feel free to follow this AWS Guide. If you already have a S3 bucket setup you can use the existing bucket.
- Follow this AWS Guide on how to setup CloudTrail Logs into your S3 bucket.
- Confirm CloudTrail logs are flowing into your S3 bucket.
- Follow the AWS S3 Bucket guide to create a IAM user for CYDERES that can access this S3 bucket.
- Provide the authentication information to CYDERES as directed by the AWS S3 Bucket Guide.