AWS CloudTrail¶
Cyderes supports the ingestion of AWS CloudTrail logs via an S3 Bucket
Chronicle Data Types¶
- AWS_CLOUDTRAIL
Configuration¶
- Create a new S3 bucket for the CloudTrail logs to be stored in. A pre-existing S3 bucket may also be used. This guide AWS Guide can be followed.
- Follow this AWS Guide to set up CloudTrail logging to the S3 bucket
- Confirm CloudTrail logs are flowing into the S3 bucket
- Follow the AWS S3 Bucket guide to create an IAM user for Cyderes that can access this S3 bucket
- Provide the authentication information to Cyderes as directed by the AWS S3 Bucket Guide