AWS VPC Flow
CYDERES supports the ingestion of AWS VPC Flow logs via a S3 Bucket.
Chronicle Data Types
- AWS_VPC_FLOW
Configuration
- Create a new S3 bucket to store VPC Flow Logs. Feel free to follow this AWS Guide. If you already have a S3 bucket setup you can use the existing bucket.
- Follow this AWS Guide on how to setup VPC Flow Logs into your S3 Bucket.
- Confirm VPC Flow Logs are flowing into your S3 bucket.
- Follow the AWS S3 Bucket guide to create a IAM user for CYDERES that can access this S3 bucket.
- Provide the authentication information to CYDERES as directed by the AWS S3 Bucket Guide.