This topic tells you how to configure the AWS collection protocol, which collects events from Amazon Web Services (AWS) CloudTrail.
How AWS Collection Works
The Log Collector service collects events from Amazon Web Services (AWS) CloudTrail. CloudTrail records AWS API calls for an account. The events contain the identity of the API caller, the time of the API call, the source IP address of the API caller, the request parameters, and the response elements returned by the AWS service. The AWS API call history provided by CloudTrail events enables security analysis, resource change tracking, and compliance auditing. CloudTrail uses Amazon S3 for log file storage and delivery. NetWitness Suite copies the log files from the cloud (S3 bucket), and sends the events contained in the files to the Log Collector.
The following figure illustrates how you deploy the AWS Collection Protocol in NetWitness Suite.
To configure an AWS (CloudTrail) Event Source:
- Go to ADMIN > Services from the NetWitness Suite menu.
- Select a Log Collection service.
- Under Actions, select > View > Config to display the Log Collection configuration parameter tabs.
Click the Event Sources tab.
- In the Event Sources tab, select Plugins/Config from the drop-down menu.
The Available Event Source Types dialog is displayed.
Select cloudtrail) and click OK.
The newly added event source type is displayed in the Event Categories panel.
The Add Source dialog is displayed.
- Define parameter values. For details, see Configure AWS (CloudTrail) Event Sources in NetWitness Suite below.
Click Test Connection.
The result of the test is displayed in the dialog box. If the test is unsuccessful, edit the device or service information and retry.
Log Collector takes approximately 60 seconds to return the test results. If it exceeds the time limit, the test times out and the NetWitness Suite displays an error message.
If the test is successful, click OK.
The new event source is displayed in the Sources panel.
The following table describes the available configuration parameter for AWS collection.