<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS LOGS for SIEM in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546973#M9855</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/165827"&gt;@vikkysplunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sourcetype for the security content in AWS are:&lt;/P&gt;&lt;P&gt;aws:cloudtrail&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;aws:cloudwatchlogs:vpcflow&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;&lt;SPAN&gt;aws:config:rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also I suggest guardduty logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-panel lia-panel-standard LabelsForMessage Chrome lia-component-message-view-widget-labels"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-heading-bar-wrapper"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 07 Apr 2021 07:19:13 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-04-07T07:19:13Z</dc:date>
    <item>
      <title>AWS LOGS for SIEM</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546971#M9854</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All, I am getting below AWS logs from customer but below logs are taking more than 50 % of license, so please could you find the below AWS sourcetype details and let me know which are required for security perspective ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;aws:cloudtrail&lt;BR /&gt;aws:cloudwatchlogs:vpcflow&lt;BR /&gt;aws:config&lt;BR /&gt;aws:config:notification&lt;BR /&gt;aws:config:rule&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 06:51:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546971#M9854</guid>
      <dc:creator>vikkysplunk</dc:creator>
      <dc:date>2021-04-07T06:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LOGS for SIEM</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546973#M9855</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/165827"&gt;@vikkysplunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sourcetype for the security content in AWS are:&lt;/P&gt;&lt;P&gt;aws:cloudtrail&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;aws:cloudwatchlogs:vpcflow&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;&lt;SPAN&gt;aws:config:rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also I suggest guardduty logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-panel lia-panel-standard LabelsForMessage Chrome lia-component-message-view-widget-labels"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-heading-bar-wrapper"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Apr 2021 07:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546973#M9855</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-07T07:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LOGS for SIEM</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546978#M9856</link>
      <description>&lt;P&gt;Hi, thanks for the below details..pls could you let me know have you created any use cases fir aws logs.. if yes please can you provide me that use case details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 08:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546978#M9856</guid>
      <dc:creator>vikkysplunk</dc:creator>
      <dc:date>2021-04-07T08:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LOGS for SIEM</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546979#M9857</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/165827"&gt;@vikkysplunk&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;please check this blog for the security use-cases, it is awesome!&lt;/P&gt;&lt;P&gt;&amp;nbsp;this page is for the guardduty use-cases&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.chrisfarris.com/post/reinforce-threat-hunting/" target="_blank"&gt;https://www.chrisfarris.com/post/reinforce-threat-hunting/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and this link&amp;nbsp; is for the cloudtrail&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.chrisfarris.com/post/reinvent2019-sec339/" target="_blank"&gt;https://www.chrisfarris.com/post/reinvent2019-sec339/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;confirmation solution or karma given is appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 08:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/546979#M9857</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-07T08:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LOGS for SIEM</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/547284#M9860</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the below use case details and same way do you have any document for&amp;nbsp;&lt;SPAN&gt;aws:cloudwatchlogs:vpcflow?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 02:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/AWS-LOGS-for-SIEM/m-p/547284#M9860</guid>
      <dc:creator>vikkysplunk</dc:creator>
      <dc:date>2021-04-09T02:18:23Z</dc:date>
    </item>
  </channel>
</rss>

