bcgov / bcgov/cloud-pathfinder

Enable Account Activity in CloudGuard CSPM

Open
#1,986 0 comments 0 reactions 0 assignees View on GitHub
CSP: AWS Security Technology
Dominant language
Jinja
Stars
2
Forks
7
PR merge metrics
No merged PRs in 30d

Description

**Describe the issue**
To onboard your CloudTrail for Intelligence analysis, select the S3 buckets that hold the logs. For centralized S3 buckets, you can select the accounts you want to analyze.
CloudGuard creates a CloudFormation template (CFT) to run in your AWS environment to handle the required configuration easier.
The process can take a few minutes to complete.
Important Prerequisites
Existing CloudTrail configured to store log files on an AWS S3 bucket.
The S3 bucket has to reside:
In the same AWS account with the CloudTrail.
In an AWS account onboarded to the same CloudGuard account as the logs account.
Note: In case of a trail for specific regions, only partial insights will be gained - for the full value, each account should have a multi-region trail.
Note:
CloudGuard does not fix, edit, or delete existing bucket's event notifications or SNS topic policies.
CFT and Accounts steps are skipped in some onboarding scenarios.

**Additional context**
Add any other context, attachments or screenshots

**Definition of done**
Identify acceptance criteria for this to be completely done

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.