AWS VPC Flow¶
Cyderes supports the ingestion of AWS VPC Flow logs via a S3 Bucket.
Chronicle Data Types¶
- AWS_VPC_FLOW
Configuration¶
- Create a new S3 bucket to store VPC Flow Logs. A pre-existing S3 bucket may also be used. This guide AWS Guide can be followed.
- Follow AWS Guide for instructions on how to setup VPC Flow Logging to an S3 Bucket
- Confirm VPC Flow Logs are flowing into the S3 bucket
- Follow the AWS S3 Bucket guide to create an IAM user for Cyderes that can access the S3 bucket
- Provide the authentication information to Cyderes per the AWS S3 Bucket Guide