In your AWS account, you must have read privileges for AWS S3 buckets and AWS CloudTrail.  

You can use this document to add a remote log collector to a AWS CloudTrail remote device (log source). 


Pre-Deployment Considerations


AWS Account Information

  1. Access your AWS console. 
  2. In the top, right corner, locate and copy your account number and corresponding region. You will need this information later. 


Create a remote log source


  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security.
  2. Click Log & Data Management.
  3. Click External Sources.
  4. Click the plus ( + ) sign. 
  5. Complete the missing fields:
  6. Click Save Log Source
  7. In the pop-up window, copy and paste the URL text. You will need this information in the AWS console. 
  8. Click Return to the Log Source List. You will be redirected to the External Sources screen. 
  9. In the External Sources screen, refresh the screen until the log source reaches an Online status. 


Create a new trail and sync your AWS S3 bucket


  1. In the AWS console, navigate to the AWS CloudTrail section. 
  2. Update your account's region settings to match the region previously selected in AMP.
  3. Click Create trail. (You may first need to click View trails, and then click Create trail.)  



  4. In Trail name, enter a descriptive name. 



  5. For Apply trail to all regions, mark No
  6. For Create a new S3 bucket, mark No



  7. In S3 bucket, paste the bolded URL text that you copied earlier from AMP. 
  8. Click Create


Verify Connection in AMP


  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security
  2. Click Log & Data Management, and then select External Sources.
  3. Locate the newly created remote log source. 
  4. Under Last Event, verify that a recent activity took place. 

Additionally, you can view the actual logs to confirm that the configuration was successful. 

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security
  2. Click Log & Data Management, and then select Search.
  3. In the search field, enter your AWS account number surrounded by asterisks wildcards.

Troubleshooting

If you are having issues adding a remote log collector to an AWS CloudTrail remote device, consider that: 

  • You need to update your permissions in AWS.
    • You must have read privileges for S3 buckets and write privileges for AWS CloudTrail. 
      • Your account must be assigned to the AWSCloudTrailFullAccess policy. To learn more the permissions (policies) for AWS CloudTrail, please see the documentation in AWS
  • Ensure that the region you entered in AMP matches your AWS account's region.
  • If you are having difficult searching for your logs, consider entering you AWS account number surrounded by asterisks wildcards, such as *123456789123*.



Was this helpful?