Splunk Enterprise Security

What should be the source type for AWS KMS logs to be CIM mapped fed to Splunk HEC through Kinesis Firehose connector?

arangineni
Explorer

We have a setup where the AWS KMS logs are sent to Splunk HEC through below flow. We are getting JSON event format but don't see the data to be doing necessary field aliasing and tagging on SH to be CIM compatible for Authentication & Change Datamodel. I already installed Splunk_TA_aws on both SH & HF.

KMS -> Kinesis Firehosse -> logstash function -> Splunk HEC (using aws:cloudtrail sourcetype)

Should I be using a different source type for this data source and data format sent through my flow? Can anyone advise if worked with KMS data for AWS.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...