Page tree

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 24 Next »


Armor Knowledge Base


Feedback

Have a suggestion for the Armor Knowledge Base?

Send a message to kb@armor.com.









Error rendering macro 'excerpt-include'

No link could be created for 'Armor Anywhere users (snippet)'.

In your AMP account, you must have the following permissions:

  • Delete Log Management
  • Read Log Endpoints

In your AWS account, you must have read privileges for S3 buckets and CloudTrail.  


Overview

You can use this document to add a remote log collector to a CloudTrail remote device (log source). 


Step 1: Gather AWS account information

  1. Access your AWS console. 
  2. In the top, right corner, locate and copy your account number and corresponding region. You will need this information later. 

Step 2: Create a remote log source 

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security.
  2. Click Log & Data Management.
  3. Click External Sources.
  4. Click the plus ( + ) sign. 
    • If you do not have any log sources already created, then click Add a New Log Source
  5. Complete the missing fields:
    • In Endpoint, select the available Armor Endpoint.
    • In Log Source Type, select Amazon AWS CloudTrail
    • In Log Source Identifier, confirm that the listed system hostname matches the system for log collection.
      • The hostname is case-sensitive and must match the exact same letters casing as the logs that are sent into this log source.
      • This field will populate after you complete the Account Number field. 
    • In Protocol, confirm that Amazon AWS S3 REST API is selected. 
    • In Account Number, paste the AWS account number that you copied early. You must remove any dashes or hyphens ( - ). 
    • In Region to Monitor, select the region that corresponds to the account number. 
  6. Click Save Log Source
  7. In the pop-up window, copy and paste the URL text. You will need this information in the AWS console. 
  8. Click Return to the Log Source List. You will be redirected to the External Sources screen. 
  9. In the External Sources screen, refresh the screen until the log source reaches an Online status. 

Step 3: Create a new trail and sync your S3 bucket

  1. In the AWS console, navigate to the CloudTrail section. 
  2. Update your account's region settings to match the region previously selected in AMP.
  3. Click Create
  4. In Trail name, enter a descriptive name. 
  5. For Apply trail to all regions, mark No
  6. For Create a new S3 bucket, mark No
  7. In S3 bucket, paste the bolded URL text that you copied earlier from AMP. 
  8. Click Create

Step 4: Verify configurations

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security
  2. Click Log & Data Management, and then select External Sources.
    • If Log & Data Management does not appear, then click Log Management, and then select Sources
  3. Locate the newly created remote log source. 
  4. Under Last Event, verify that a recent activity took place. 
    • This status will indicate that the configurations were successful. 
    • After you update your AWS account, it may take 30 minutes for AMP to display the updates.  

Additionally, you can view the actual logs to confirm that the configuration was successful. 

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security
  2. Click Log & Data Management, and then select Search.
    • If Log & Data Management does not appear, then click Log Management, and then select Search
  3. In the search field, enter your AWS account number surrounded by asterisks wildcards.
    • For example, you can enter *123456789123*
    • This action will display collected CloudTrail logs. 

Troubleshooting

If you are having issues adding a remote log collector to a CloudTrail remote device, consider that: 

  • You need to update your permissions in AMP and in AWS.
    • In AMP, you must have the Delete Log Management and Read Log Endpoints permissions assigned to your account. 

      To add permissions to your account:

      1. In the Armor Management Portal (AMP), in the left-side navigation, click Account
      2. Click Roles + Permissions
      3. Locate and select your role.
      4. Mark Delete Log Management and Read Log Endpoints.
      5. Click Save Role in the bottom of the screen. 
    • In AWS, you must have read privileges for S3 buckets and for CloudTrail.  
  • Ensure that the region you entered in AMP matches your AWS account's region.