diff --git a/cid-redirects.json b/cid-redirects.json index 493adc6bd2e..227a82599e4 100644 --- a/cid-redirects.json +++ b/cid-redirects.json @@ -782,15 +782,18 @@ "/07Sumo-Logic-Apps/01Amazon_and_AWS/CIS_AWS_Foundations_Benchmark_App": "/docs/integrations/amazon-aws/cis-aws-foundations-benchmark", "/07Sumo-Logic-Apps/01Amazon_and_AWS/CIS_AWS_Foundations_Benchmark_App/01Collect-Logs-for-the-CIS-AWS-Foundation-Benchmark-App": "/docs/integrations/amazon-aws/cis-aws-foundations-benchmark", "/07Sumo-Logic-Apps/01Amazon_and_AWS/CIS_AWS_Foundations_Benchmark_App/CIS-AWS-Foundations-Benchmark-App-Dashboards": "/docs/integrations/amazon-aws/cis-aws-foundations-benchmark", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_Amazon_GuardDuty": "/docs/integrations/amazon-aws/global-intelligence-guardduty", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_Amazon_GuardDuty/Configure_Log_Collection_and_Install_the_GI_GuardDuty_App": "/docs/integrations/amazon-aws/global-intelligence-guardduty", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_Amazon_GuardDuty/View_the_GI_GuardDuty_App_Dashboards": "/docs/integrations/amazon-aws/global-intelligence-guardduty", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail_DevOps": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail_DevOps/Collect_Logs_for_the_Global_Intelligence_for_AWS_CloudTrail_DevOps_App": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail_DevOps/Install_the_Global_Intelligence_for_AWS_CloudTrail_DevOps_App_and_View_the_Dashboards": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail/Collect_Logs_for_the_GI_for_AWS_CloudTrail_SecOps_App": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail/Install_the_GI_for_AWS_CloudTrail_SecOps_App_and_view_the_Dashboards": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops", - "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops", + "/docs/integrations/amazon-aws/global-intelligence-guardduty": "/docs/integrations/amazon-aws", + "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops": "/docs/integrations/amazon-aws", + "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_Amazon_GuardDuty": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_Amazon_GuardDuty/Configure_Log_Collection_and_Install_the_GI_GuardDuty_App": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_Amazon_GuardDuty/View_the_GI_GuardDuty_App_Dashboards": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail_DevOps": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail_DevOps/Collect_Logs_for_the_Global_Intelligence_for_AWS_CloudTrail_DevOps_App": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail_DevOps/Install_the_Global_Intelligence_for_AWS_CloudTrail_DevOps_App_and_View_the_Dashboards": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail/Collect_Logs_for_the_GI_for_AWS_CloudTrail_SecOps_App": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail/Install_the_GI_for_AWS_CloudTrail_SecOps_App_and_view_the_Dashboards": "/docs/integrations/amazon-aws", + "/07Sumo-Logic-Apps/01Amazon_and_AWS/Global_Intelligence_for_AWS_CloudTrail": "/docs/integrations/amazon-aws", "/07Sumo-Logic-Apps/01Amazon_and_AWS/Host_Metrics_(EC2)": "/docs/integrations/amazon-aws/ec2-host-metrics", "/07Sumo-Logic-Apps/01Amazon_and_AWS/Host_Metrics_(EC2)/Collect_Metrics_for_the_Host_Metrics_(EC2)_App": "/docs/integrations/amazon-aws/ec2-host-metrics", "/07Sumo-Logic-Apps/01Amazon_and_AWS/Host_Metrics_(EC2)/Install_the_Host_Metrics_(EC2)_App_and_view_the_Dashboards": "/docs/integrations/amazon-aws/ec2-host-metrics", @@ -1995,8 +1998,8 @@ "/cid/10223": "/docs/integrations/saas-cloud/abnormal-security", "/cid/1984": "/docs/integrations/security-threat-detection/crowdstrike-falcon-endpoint-protection", "/cid/1985": "/docs/integrations/saas-cloud/acquia", - "/cid/1986": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops", - "/cid/1988": "/docs/integrations/amazon-aws/global-intelligence-guardduty", + "/cid/1986": "/docs/integrations/amazon-aws", + "/cid/1988": "/docs/integrations/amazon-aws", "/cid/1989": "/docs/observability/aws/integrations/aws-api-gateway", "/cid/1990": "/docs/observability/aws/integrations/aws-application-load-balancer", "/cid/1991": "/docs/integrations/amazon-aws/lambda", @@ -2669,8 +2672,8 @@ "/cid/6022": "/docs/observability/aws/integrations/amazon-ecs", "/cid/6023": "/docs/integrations/microsoft-azure/network-watcher", "/cid/6065": "/docs/integrations/security-threat-detection/threat-intel-quick-analysis", - "/cid/6066": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops", - "/cid/6067": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops", + "/cid/6066": "/docs/integrations/amazon-aws", + "/cid/6067": "/docs/integrations/amazon-aws", "/cid/6068": "/docs/integrations/global-intelligence", "/cid/6100": "/docs/integrations/security-threat-detection/threat-intel-quick-analysis", "/cid/61230": "/docs/manage/manage-subscription/sumo-logic-credits-accounts", @@ -3746,7 +3749,7 @@ "/Release-Notes/Service-Release-Notes": "/release-notes-service", "/Release-Notes/Developer-Release-Notes": "/release-notes-developer", "/Release-Notes/Cloud_SIEM_Enterprise_Release_Notes": "/release-notes-cse", - "/docs/observability/aws/integrations/global-intelligence-cloudtrail-devops": "/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops", + "/docs/observability/aws/integrations/global-intelligence-cloudtrail-devops": "/docs/integrations/amazon-aws", "/docs/releasenotes/cloud-siem": "/release-notes-cse", "/docs/releasenotes/collector": "/release-notes-collector", "/docs/releasenotes/developer": "/release-notes-developer", diff --git a/docs/integrations/account-plans.md b/docs/integrations/account-plans.md index 8133b2165dd..218147789c6 100644 --- a/docs/integrations/account-plans.md +++ b/docs/integrations/account-plans.md @@ -18,22 +18,6 @@ Use this page to determine which apps are available based on your account plan. Enterprise Security Enterprise Suite - - [Global Intelligence for AWS CloudTrail SecOps](/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops) - ✓ - - - - ✓ - - - [Global Intelligence for Amazon GuardDuty](/docs/integrations/amazon-aws/global-intelligence-guardduty) - ✓ - - - ✓ - ✓ - [Enterprise Audit Apps](/docs/integrations/sumo-apps/enterprise-audit) ✓ @@ -79,24 +63,6 @@ Use this page to determine which apps are available based on your account plan. Professional Enterprise - - [Global Intelligence for AWS CloudTrail SecOps](/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops) - ✓ - - ✓ - - - [Global Intelligence for Amazon GuardDuty](/docs/integrations/amazon-aws/global-intelligence-guardduty) - ✓ - - ✓ - - - [Global Intelligence for AWS CloudTrail DevOps](/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops) - ✓ - - ✓ - [Enterprise Audit Apps](/docs/integrations/sumo-apps/enterprise-audit) ✓ diff --git a/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops.md b/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops.md deleted file mode 100644 index cd2a83e2db8..00000000000 --- a/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops.md +++ /dev/null @@ -1,425 +0,0 @@ ---- -id: global-intelligence-cloudtrail-devops -title: Global Intelligence for AWS CloudTrail DevOps -description: Global Intelligence for AWS CloudTrail - DevOps provides insights for on-call engineers, SRE, and DevOps users to help minimize AWS errors and maximize app availability. ---- - -import useBaseUrl from '@docusaurus/useBaseUrl'; - -Global Intelligence Devops icon - -Global Intelligence for AWS CloudTrail - DevOps provides insights for on-call engineers, infrastructure engineers, and DevOps users accelerate root cause analysis for incidents by providing error rate and configuration insights benchmarked from Sumo Logic’s AWS customers for nine AWS services: - -* Amazon EC2 -* Amazon S3 -* AWS Elastic Load Balancing -* Amazon RDS -* Amazon Redshift -* Amazon DynamoDB -* Amazon ElastiCache -* AWS Lambda -* AWS Auto Scaling - -The benchmarks are powered by more than 15 M data points per week from AWS CloudTrail logs for a few thousand Sumo Logic tenants across 27 AWS regions. - -A well-architected modern app running on AWS can experience four types of errors during mission-critical scale-out events leading to an outage or application incident. These include: -* Service Availability errors, where a particular AWS service (For example, EC2) may be unavailable. -* Throttling errors, where AWS rate-limits API traffic from the customer’s application for a given service and API. (For example, PutItem requests for Amazon DynamoDB.) -* Account Quota errors, where a customer may saturate account limits for a particular service and resource. (For example, exceeding the 100 buckets per account limit of Amazon S3.) -* Insufficient capacity/out-of-stock errors where AWS is unable to provide resources of a particular size in a given region, such as EC2 m4.xlarge instances in us-west-1. - -By comparing a given customer’s AWS error rate against other customers by AWS region, service, API, AWS account, and instance types, Global Intelligence for AWS CloudTrail DevOps, helps identify if such errors might be the probable cause of an incident. - -In addition, the app provides configuration guidance for key AWS services based on settings common among other customers. - -* Configuration guidance includes memory and concurrency settings for AWS Lambda, provisioned IOPS for DynamoDB, and min/max sizes of EC2 Auto Scaling groups. -* For throttling-related root causes for some services like AWS Lambda and Amazon DynamoDB, such guidance can help users right-size their apps based on common configuration settings. -* An action plan helps users focus their attention on specific microservices in particular AWS accounts that might be experiencing errors. - -## Prerequisites - -This feature is available in the following account plans. - -| Account Type | Account Level -| :---- | :---- -| Cloud Flex | Trial, Enterprise -| Cloud Flex Credits | Trial, Enterprise Operations, Enterprise Security, Enterprise Suite - -## Log types - -Global Intelligence for CloudTrail DevOps App uses AWS CloudTrail logs. - -The Sumo Logic Global Intelligence for AWS CloudTrail DevOps app provides insight into your key CloudTrail events. You can review the log collection process and start collecting data. - -### Sample log messages - -```json -{ - "eventVersion":"1.05", - "userIdentity":{ - "type":"IAMUser", - "principalId":"AIDAJK3NPEULWYAYYL73U", - "arn":"arn:aws:iam::224064240813:user/username", - "accountId":"224064240808", - "userName":"acme@acme.com" - }, - "eventTime":"2020-01-11 00:42:12+0000", - "eventSource":"signin.amazonaws.com", - "eventName":"ConsoleLogin", - "awsRegion":"us-west-2", - "sourceIPAddress":"115.13.72.133", - "userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) - AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36", - "requestParameters":null, - "responseElements":{ - "ConsoleLogin":"Success" - }, - "additionalEventData":{ - "LoginTo":"https://us-west-2.console.aws.amazon.com/ecs/home?region=us-west-2& -state=hashArgs%23%2Frepositories%2Ftravellogic%3Aproducts&isauthcode=true", - "MobileVersion":"No", - "MFAUsed":"Yes" - }, - "eventID":"8fd88195-8576-49ad-9e14-8330cb492604", - "eventType":"AwsConsoleSignIn", - "recipientAccountId":"224064240808" -} -``` - - - -### Sample queries - -
-Click to expand. - -This sample query is from the **Lambda Configuration: My Company v. Others (Categorical)** panel of **GI CloudTrail DevOps - 05. Configuration Benchmarks** dashboard. - -```sumo -// id=@config_lambda_categorical_values -_sourceCategory=Labs/AWS/CloudTrailDevOps/Analytics -(AwsApiCall lambda !errorCode) -and (Runtime or Mode) -| parse "\"awsRegion\":\"*\"" as awsRegion -| parse "\"eventSource\":\"*\"" as eventSource -| parse "\"eventName\":\"*\"" as eventName -| parse "\"eventType\":\"*\"" as eventType -| parse "\"recipientAccountId\":\"*\"" as recipientAccountId -| parse field=eventSource "*.amazonaws.com" as resourceType -| parse "\"functionName\":\"*\"" as functionName nodrop -// Filter specific to this analysis -| where eventType = "AwsApiCall" and resourceType = "lambda" -// Categorical configuration - Lambda -| parse "\"mode\":\"*\"" as mode nodrop -| parse "\"runtime\":\"*\"" as runtime nodrop -// Now we need to inverse transpose the rows into different rows -| if(!isBlank(mode), mode, "Not-Available") as mode -| if(!isBlank(runtime), runtime, "Not-Available") as runtime -| count_distinct(functionName) by mode, runtime, awsRegion -// Unpack the different configuration options into their own benchmarkname rows -| concat("resourceType=lambda_tracingConfig=", mode, "_awsRegion=", awsRegion, ",", "resourceType=lambda_runtime=", runtime, "_awsRegion=", awsRegion) as benchmarkNames -| parse regex field=benchmarkNames "(?[^,]+)" multi -| where !(benchmarkname matches "*Not-Available*") -| fields benchmarkname, _count_distinct -| sum(_count_distinct) by benchmarkname -| _sum as _count_distinct -| parse field=benchmarkname "resourceType=lambda_*=*_awsRegion=*" as denomGroup, _, awsRegion -| concat(denomGroup, "_", awsRegion) as denomGroup -// Use join to do parallel calculations: -// t1: per-event type (denomGroup) denominators -// t2: per-event value (numerator) counts -| join -(sum(_count_distinct) as denom by denomGroup) as t1, -(sum(_count_distinct) as val by denomGroup, benchmarkName) as t2 -on t1.denomGroup = t2.denomGroup -// Unpack the results and compute the desired percentages -| t2_val as val -| t2_benchmarkname as benchmarkname -| t1_denom as denom -| concat(round(toDouble(val) / denom * 10000) / 100, "%") as my_company_percentage -| infer _category=cloudtraildevops _model=benchmark benchmarktype=categorical -| concat(round(percentage * 10000) / 100, "%") as benchmark_percentage -| parse field=benchmarkname "resourceType=*_*=*_awsRegion=*" as _, configProperty, value, awsRegion -| fields awsRegion, configProperty, value, my_company_percentage, benchmark_percentage -| sort +awsRegion, +configProperty, +value -``` - -
- -## Collecting logs for the Global Intelligence for AWS CloudTrail DevOps App - -If you already have AWS CloudTrail logs flowing into Sumo Logic, you can skip the steps in this section and go to [Installing the App](#installing-the-global-intelligence-for-aws-cloudtrail-devops-app). - -With this graphic, you can see how to collect logs from AWS CloudTrail DevOps and send them to Sumo Logic. - -Collection Process Overview devops - -### Prerequisites - -Before you begin, you must configure AWS CloudTrail logging to an S3 bucket. -1. [Configure CloudTrail](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/getting_started_top_level.html) in your AWS account. -2. [Enable logging using the AWS Management Console](https://docs.aws.amazon.com/AmazonS3/latest/dev/enable-logging-console.html). -3. Confirm that logs are being delivered to the S3 bucket. -4. [Grant Access to an Amazon S3 Bucket](/docs/send-data/hosted-collectors/amazon-aws/grant-access-aws-product). - - -### Configuring Log Collection for AWS Global Intelligence CloudTrail DevOps - -To configure log collection for Global Intelligence for AWS CloudTrail, follow the steps described [here](#collecting-logs-for-the-global-intelligence-for-aws-cloudtrail-devops-app). - - -## Installing the Global Intelligence for AWS CloudTrail DevOps App - -import AppInstall from '../../reuse/apps/app-install.md'; - - - -## Viewing GI CloudTrail DevOps Dashboards - -**Each dashboard has a set of filters** that you can apply to the entire dashboard, as shown in the following example. Click the funnel icon in the top dashboard menu bar to display a scroll-able list of filters that are applied across the entire dashboard. - -You can use filters to drill down and examine the data on a granular level. - -**Each panel has a set of filters** that are applied to the results for that panel only, as shown in the following example. Click the funnel icon in the top panel menu bar to display a list of panel-specific filters. - -### 01. AWS Service Availability - -The **GI CloudTrail DevOps - 01. AWS Service Availability** dashboard tabulates the number of AWS incident-related errors for each minute and compares it to errors your company is facing. If your recent error rate is greater than the AWS baseline, it is a strong signal that an AWS outage or incident is impacting your apps. You can select the awsRegion and recipientAccountId to view results by region and an AWS account. Unlike the [AWS Service Health Dashboard](https://status.aws.amazon.com/), this dashboard computes availability by API for each of the nine AWS services. - -Use this dashboard to: -* Monitor AWS-related incidents in your organization. -* Compare AWS incident and outage rates by region and account to other customers. - -GI CloudTrail DevOps dashboard - - -### 02. My Company’s Throttling Errors - -The **GI CloudTrail DevOps - 02. My Company’s Throttling Errors** dashboard predicts throttling errors per minute based on API requests per minute, for a given AWS API. The panels compare your throttling errors per minute to the predicted value of such errors to assess if throttling is the root cause of application errors. You can select the awsRegion and recipientAccountId to view results by region and account. - -Throttling ensures that calls to the AWS API do not exceed the maximum allowed API request limits. AWS may throttle your AWS usage just when your application experiences load and make additional API requests, leading to an incident. - -For many APIs, the throttling rate per minute as measured by Sumo Logic may indeed be zero. Where sufficient data exists from Sumo Logic customers, the app will show error rate predictions based on API request rates. To illustrate how to use this dashboard below is an example of a single API request for EC2, describeInstances, and how it might encounter one type of throttling error, Request Limit Exceeded. The correlation is not linear for many APIs; the diagram shows a linear relationship for illustration purposes. In the diagram, two hypothetical companies that are experiencing throttling at rates different from that predicted by the model (note that the predicted rate might be zero for many API) for the describeInstances APl. - -Specifically, Company A is experiencing more throttling errors than predicted. This could mean one or more of the following: - -* The latest AWS API usage patterns are different from what the model has learned from the prior 7 days data. -* There are company-specific factors that are not captured in our model. -* There may be periodicity or intricacies related to AWS’ throttling algorithms (For example, steady-state throughput allocation v. burst allocation) not captured in the model. - -GI CloudTrail DevOps dashboard - -On the other hand, Company B is experiencing fewer throttling errors than predicted. This could mean one or more of the following: - -* You may experience higher throttling errors in the future based on our models. -* The latest AWS API usage patterns are different from what the model has learned from the prior 7 days. -* There are company-specific factors that are not captured in our model, such as an increase in API request quota for your company. -* There may be periodicity or intricacies related to AWS’ throttling algorithms (For example, steady-state throughput allocation v. burst allocation) not captured in the model. - -Consult the AWS documentation for the appropriate service to understand best practices to minimize throttling errors including batching requests and adding exponential backoff retries. See [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/query-api-troubleshooting.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/query-api-troubleshooting.html) for suggestions for EC2 throttling errors. - -Use this dashboard to: -* Monitor throttling errors in your AWS environment. -* Compare your throttling errors by AWS service, API name, region and account to other customers. -* Troubleshoot application errors. -* Request greater API request limits through AWS Support if you feel your application is consistently being throttled at a greater rate than other customers. - -GI CloudTrail DevOps dashboard - - -### 03. My Company’s Account Quota Errors - -The **GI CloudTrail DevOps - 03. My Company’s Account Quota Errors** dashboard depicts account quota errors. Service quotas also referred to as limits, are the maximum number of service resources or operations for your AWS account. The panels compare your account quota errors per minute against the error rates seen in all customers. This can help you assess if account quota limits are the root cause of your application errors. You can select the awsRegion and recipientAccountId to view results by region and account. For more information, see [AWS service documentation](https://docs.aws.amazon.com/general/latest/gr/aws-service-information.html). - -Unlike throttling errors, with few exceptions (For example, DynamoDB errors) account quota errors will persist once you experience them at a rate proportional to your API request rate. The diagram below shows three companies that experience account quota errors for EC2 createLaunchConfiguration API. AWS has a limit of 200 launch configurations per region for this EC2 API. Company A is experiencing account quota errors proportional to its API request rate. This is because they are already at their account limit for the given resource. They will continue to see these errors unless they request a quota upgrade through AWS, remove unused resources, or both. - -On the other hand, Company B is experiencing zero account quota errors despite more API requests/min than Company A. This could mean one or more of the following: -* Company B is well under their account quota limits. -* Company B is monitoring their account quotas and removing unused resources to avoid breaching limits. -* Company B is monitoring their account quotas and has upgraded its limits to accommodate their higher API usage. - -Company C is experiencing account quota errors but at higher levels of API requests than Company A. This could mean one or more of the following: -* Company C only recently breached its account quota limits. -* Company C has a higher account quota than Company A. - -GI CloudTrail DevOps dashboard - -To minimize these errors, watch APIs that experience the most errors using the Account Limits API for the appropriate service - for example, [https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_DescribeAccountLimits.html](https://docs.aws.amazon.com/autoscaling/ec2/APIReference/API_DescribeAccountLimits.html). - -Use this dashboard to: -* Monitor account errors in your AWS environment by AWS service, API name, AWS account, and region. -* Compare account quota errors by API name, region, and account to other customers. -* Troubleshoot application errors arising from account quota limits being breached. -* Request an upgrade to account quotas through AWS Support if you experience account quota errors at a higher level than other customers. -* Re-architect your application to consume AWS services in a region with fewer account quota errors based on the benchmark. - -GI CloudTrail DevOps dashboard - -### 04. My Company’s Insufficient Capacity Errors - -The **GI CloudTrail DevOps - 04. My Company’s Insufficient Capacity Errors** dashboard computes the insufficient capacity errors per minute by instance type and region. For some resources like EC2, AWS may run out of on-demand capacity in a particular region (an "out of stock" scenario) just like your application requirements for the capacity spike. The panels compare your insufficient capacity errors per minute against the error rates for all customers to help you assess if insufficient capacity is the root cause of your application errors. You can use the benchmark to re-architect your application to use AWS regions and instanceTypes with the fewest errors. You can select the awsRegion, recipientAccountId and instance type to view results by region, account, and instance type. This dashboard is supported for following AWS service: - -* EC2 -* ElastiCache -* RDS -* Redshift - -Use this dashboard to: -* Monitor insufficient capacity errors in your AWS environment by AWS service, API name, AWS account, and region. -* Compare errors by API name, region, and account to other customers. -* Troubleshoot application errors arising from insufficient capacity errors. -* Re-architect your application to consume instance types or move to a region with fewer errors based on the benchmark. - -GI CloudTrail DevOps dashboard - - -### 05. Configuration Benchmarks - -The **GI CloudTrail DevOps - 05. Configuration Benchmarks** dashboard provides insights for analyzing configuration settings used by AWS customers by region and resource type. This enables you to assess your configuration settings compared to that of other customers. You can select the awsRegion and recipientAccountId to view results by region. The configuration benchmarks are restricted to the following AWS services: - -* AWS Lambda -* AWS Auto Scaling -* AWS Elastic Load Balancing -* Amazon RDS -* Amazon Redshift -* Amazon DynamoDB -* Amazon ElastiCache - -Three types of configurations are benchmarked to help users understand the common values of each setting in the Sumo Logic population for a given AWS service: - -1. **Categorical Configuration.** Users pick a setting from a list of values, for example, database engine brand for RDS. For categorical configurations, the benchmark is the average number of resources with a given setting computed across all resources of a given service. For example, RDS engine type (for example, MySQL) is computed as the percentage of RDS instances across all customers that use MySQL in a given AWS region. -2. **Numerical Configuration.** Users set a numerical value, for example, memory size for an AWS Lambda function. Numerical configurations are expressed as p99 and max values of the setting across all resources of a given service. For example, timeout value is represented as the p99 and max across all Lambda functions discovered by Global Intelligence. -3. **Boolean Configuration.** Users turn a setting on or off, for example, multiAZ setting for RDS. Similar to categorical configuration, this is represented by the percentage of resources with true (or false) value for a given setting. - - -#### AWS Lambda - -For AWS Lambda configuration, consult [https://docs.aws.amazon.com/lambda/latest/dg/gettingstarted-features.html](https://docs.aws.amazon.com/lambda/latest/dg/gettingstarted-features.html) - -Categorial configurations for AWS Lambda include: - -* **Mode (Tracing Configuration).** Active refers to functions that use AWS X-ray to trace requests -* **Runtime.** The runtime refers to the language used by your functions such as python, java, go, and node.js. - -[Numerical configurations ](https://docs.aws.amazon.com/lambda/latest/dg/configuration-console.html) benchmarked include: - -* **Timeout.** Amount of time that Lambda allows a function to run before stopping it. The default is 3 seconds. The maximum allowed value is 900 seconds. -* **Concurrency.** Number of requests that your function is serving at any given time -* **Memory Size.** The amount of memory available to the function during execution. Choose an amount between 128 MB and 3,008 MB in 64-MB increments. -* **Allocated / Provisioned Concurrent Executions.** To enable functions to scale without fluctuations in latency, use _provisioned concurrency_. For functions that take a long time to initialize, or require extremely low latency for all invocations, provisioned concurrency enables you to pre-initialize instances of your function and keep them running at all times. -* **Reserved Concurrent Execution.** A function with reserved concurrency only uses concurrency from its dedicated pool. - - -#### AWS Auto Scaling - -AWS supports two flavors of Auto Scaling: - -* [EC2 Auto Scaling](https://docs.aws.amazon.com/autoscaling/ec2/userguide/asg-capacity-limits.html) -* [Application Auto Scaling](https://docs.aws.amazon.com/autoscaling/application/userguide/application-auto-scaling-target-tracking.html) - -For EC2 Auto Scaling using the Manual Scaling option we benchmark the following: - -* **Min / Max Size.** Minimum / maximum number of EC2 instances in the Auto Scaling Group -* **Desired Capacity.** The optional setting for the desired count of EC2 instances in the Auto Scaling Group - -As explained in AWS documentation, for the EC2 Auto Scaling Manual Scaling option, you configure the size of your Auto Scaling group by setting the minimum, maximum, and desired capacity. The minimum and maximum capacity are required to create an Auto Scaling group, while the desired capacity is optional. If you do not define your desired capacity upfront, it defaults to your minimum capacity. By default, the minimum, maximum, and desired capacity are set to one instance when you create an Auto Scaling group from the console. If you change the desired capacity, the capacity that you specify will be the total number of instances launched right after creating your Auto Scaling group. - -For Application Auto Scaling using Target Tracking Scaling Policies, we benchmark the Min and Max Capacity which refer to the minimum / maximum capacity of the scalable target based on the Scalable Dimension metric. With target tracking scaling policies, you choose a scaling metric and set a target value. Application Auto Scaling creates and manages the CloudWatch alarms that trigger the scaling policy and calculates the scaling adjustment based on the metric and the target value. The scaling policy adds or removes capacity as required to keep the metric at, or close to, the specified target value. In addition to keeping the metric close to the target value, a target tracking scaling policy also adjusts to changes in the metric due to a changing load pattern. - - -#### Elastic Load Balancer - -As explained in AWS documentation, a [load balancer](https://docs.aws.amazon.com/elasticloadbalancing/latest/application/introduction.html) distributes incoming application traffic across multiple targets, such as EC2 instances. This increases the availability of your application. You add one or more listeners to your load balancer. A listener checks for connection requests from clients, using the protocol and port that you configure. The rules that you define for a listener determine how the load balancer routes request to its registered targets. Each rule consists of a priority, one or more actions, and one or more conditions. When the conditions for a rule are met, then its actions are performed. You must define a default rule for each listener, and you can optionally define additional rules. - -Each target group routes requests to one or more registered targets, such as EC2 instances, using the protocol and port number that you specify. You can register a target with multiple target groups. You can configure health checks on a per target group basis. Health checks are performed on all targets registered to a target group that is specified in a listener rule for your load balancer. - -The benchmark tabulates statistics for: -* Listeners Per Load Balancer -* Target Groups Per Load Balancer -* Targets per Target Group -* Target Groups Per Region - - -#### DynamoDB - -The benchmark tabulates the following settings for [Provisioned Tables](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Limits.html#default-limits-throughput-capacity-modes). - -* Read Capacity Units -* Write Capacity Units -* Table Max Write Capacity Units -* Table Max Read Capacity Units - -These are defined as follows: -* One read capacity unit = one strongly consistent read per second, or two eventually consistent reads per second, for items up to 4 KB in size. -* One write capacity unit = one write per second, for items up to 1 KB in size. - - -#### RDS - -For an overview of RDS set up, see [https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_SettingUp.html](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_SettingUp.html) - -The following categorical configurations are benchmarked: - -* **Engine.** The database brand and version -* **Storage Type.** See [https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_Storage.html](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_Storage.html) -* **DB Instance Class.** The CPU/memory specification of the RDS instance. Amazon RDS supports three types of instance classes: Standard, Memory Optimized, and Burstable Performance. See [https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Concepts.DBInstanceClass.html](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Concepts.DBInstanceClass.html) - -The following boolean configurations are benchmarked: - -* [IAM Database Authentication](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAMDBAuth.html). If enabled, database authentication is based on an authentication token issued by AWS Identity and Access Management (IAM) rather than a password. When enabled, the maximum number of connections per second for your database instance may be limited depending on the instance type and your workload. IAM database authentication works with MySQL and PostgreSQL. -* ​​​**​​​​multiAZ.** Failover option for RDS - -The following [numerical configurations](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_CreateDBInstance.html) are benchmarked across RDS instances: -* iops -* Allocated Storage Capacity -* Max Allocated Storage - - -#### ElastiCache - -The following [categorical configurations](https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/GettingStarted.CreateCluster.html) are benchmarked: - -* **Engine.** redis | memcached -* **EngineVersion.** version of redis | memcached in use -* **CacheNodeType.** The compute and memory capacity of the nodes in the node group (shard). For more information, see [Choosing Your Node Size](https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/nodes-select-size.html#CacheNodes.SelectSize). -* **AZMode.** Specifies whether the nodes in this Memcached cluster are created in a single Availability Zone or created across multiple Availability Zones in the cluster's region. - -The following numerical configurations are benchmarked: - -* **Number of CacheNodes by cluster.** The initial node count in a cluster. Always 1 for Redis and between 1-20 for memcached. -* **New Replica Count by cluster.** For Redis (cluster mode disabled) replication groups, this is the number of read replica nodes in the replication group. For Redis (cluster mode enabled) replication groups, this is the number of read replica nodes in each of the replication group's node groups. - - -#### Redshift - -The core infrastructure component of an Amazon Redshift data warehouse is a cluster. - -The following categorical configurations are benchmarked: - -* **Cluster Type.** multi-node | single-node. The type of the cluster. When cluster type is specified as: - * single-node. The NumberOfNodes parameter is not required. - * multi-node. The NumberOfNodes parameter is required. -* **Cluster Version.** The version of the Amazon Redshift engine software that you want to deploy on the cluster. -* **Availability Zone.** The EC2 Availability Zone (AZ) in which you want Amazon Redshift to provision the cluster. For example, if you have several EC2 instances running in a specific Availability Zone, then you might want the cluster to be provisioned in the same zone in order to decrease network latency. -* **Node Type.** The node type to be provisioned for the cluster - -The following numerical configurations are benchmarked: - -* **Number of Nodes.** The number of compute nodes in the cluster. This parameter is required when the ClusterType parameter is specified as multi-node. -* **Target Number Of Nodes.** The number of nodes that the cluster will have after the resize operation is complete. - -Use this dashboard to: -* Understand common configurations for AWS services by categorical, numerical, and boolean values. -* ​​​​​​​Optimize your configuration based on settings common across customers. - -GI CloudTrail DevOps dashboard - - -### 06. Action Plan Dashboard - -The **GI CloudTrail DevOps - 06. Action Plan** dashboard identifies users and services that contribute to AWS errors and potential instability of your applications. Change the awsRegion and recipientAccountID to view results by region and account. Only the Top 3 rows are shown based on error count. - -GI CloudTrail DevOps dashboard - -Use this dashboard to: -* Identify and remediate users or services that are experiencing errors and potentially causing incidents for your applications. \ No newline at end of file diff --git a/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops.md b/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops.md deleted file mode 100644 index b6578ca0636..00000000000 --- a/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops.md +++ /dev/null @@ -1,448 +0,0 @@ ---- -id: global-intelligence-cloudtrail-secops -title: Global Intelligence for AWS CloudTrail SecOps -description: The Global Intelligence for AWS CloudTrail App enables you to detect potentially malicious configuration changes in your AWS account by comparing AWS CloudTrail events in your account against a cohort of AWS customers. ---- - -import useBaseUrl from '@docusaurus/useBaseUrl'; - -Global Intelligence SecOps icon - -The Global Intelligence for AWS CloudTrail App enables you to detect potentially malicious configuration changes in your AWS account by comparing [AWS CloudTrail](https://aws.amazon.com/cloudtrail/) events in your account against a cohort of AWS customers. CloudTrail events are curated from AWS penetration tests and operational best practices. - -This application name is abbreviated to **GI CloudTrail** on these documentation pages, as well as in the application pages. - -The App dashboard displays enable you to determine the following: -* How your attack surface compares to your peers -* [MITRE Attack Framework](https://attack.mitre.org/) tactics that are evident in your organization compared to your peers. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. -* Resources that are impacted -* An action plan to improve security posture in your AWS infrastructure - -The current scope of this application includes the following AWS services and associated resource types: -* **Amazon EC2**: count of compute instances, security groups, route tables and Amazon Machine Images -* **Amazon S3**: count of buckets -* **Amazon RDS**: count of database instances, DB security groups -* **Amazon Redshift**: count of database clusters and parameter groups -* **AWS Lambda**: count of function names -* **AWS IAM**: count of IAM users, roles and groups -* **AWS CloudTrail**: counts of trail instances - - -## Prerequisites - -This feature is available in the following account plans. - -| Account Type | Account level -| :---- | :---- -| Cloud Flex | Trial, Enterprise -| Cloud Flex Credits | Trial, Enterprise Suite, Enterprise Security - - -## Log types - -Global Intelligence for AWS CloudTrail App uses AWS CloudTrail logs. - -When this app is initially installed, the dashboards appear with empty panels until scheduled searches are run and the indices are populated. - -### Important Notes - -This application relies on 45 Scheduled Searches that Save to two different Indexes and one Lookup Table. As a result, they will consume the related quotas for your account. - -
-View the list of Scheduled Searches (click to expand) - -
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
FolderScheduled Search Name (prefixed with gis_benchmarks)Description
Attack Surface QueriesAttack Surface: Create,Delete,UpdateA total number of create, update and delete eventNames during a time period. This represents the velocity dimension for cohorting.
Attack Surface QueriesAttack Surface: EC2,Redshift,S3A total number of EC2, Redshift, and S3 resources during a time period. This represents the volume dimension for cohorting.
Attack Surface QueriesAttack Surface: IAM,KMS,Lambda,RDSA total number of IAM, KMS, Lambda, and RDS resources during a time period. This represents the volume dimension for cohorting.
Attack Surface QueriesAttack Surface: ServiceA total number of distinct AWS services in use during a time period. This represents the variety dimension for cohorting.
Event Priority Computation QueryEvent_Priority_ComputationCompute event priority and saves to a file called "/shared/CloudTrailGIS/EventPriority".
Event Resource Count QueriesCloudTrail_DisableEvents,EncryptWithNewKey_CountEventResourcesCounts the number of trails affected by signals related to disabling trails or encrypting them with a new key.
Event Resource Count QueriesEC2_AuthorizeSecurityGroupIngressToPublic_CountEventResourcesCounts the number of EC2 security groups affected by signals related to allowing public ingress.
Event Resource Count QueriesEC2_DescribeInstanceUserData_CountEventResourcesCounts the number of EC2 instances affected by signals describing EC2 instance metadata.
Event Resource Count QueriesEC2_DisableTerminationProtectionOrListInstances_CountEventResourcesCounts the number of EC2 instances affected by signals describing EC2 instances or disabling Termination Protection.
Event Resource Count QueriesEC2_ListSecurityGroups_ListImage_CountEventResourcesCounts the number of resources affected by signals describing EC2 security groups or describing AMIs.
Event Resource Count QueriesEC2_TrafficMirroringOrDescribeRouteTables_CountEventResourcesCounts the number of resources affected by signals describing route tables or traffic mirroring.
Event Resource Count QueriesIAM_AddUserToGroup,CompromisedUserOrKeys_CountEventResourcesCounts the number of IAM resources affected by signals related to compromised credentials or group membership changes.
Event Resource Count QueriesIAM_AttachPutRoleOrGroupOrUserPolicy_CountEventResourcesCounts the number of IAM resources affected by signals related to IAM policy assignment.
Event Resource Count QueriesIAM_ConsoleLoginsOrNoMfa_CountEventResourcesCount of IAM resources affected by console logins with and without multi-factor authentication.
Event Resource Count QueriesIAM_CreateUpdatePolicy_CountEventResourcesCounts the number of IAM resources affected by signals related to IAM policy changes.
Event Resource Count QueriesIAM_TooManyAccessDenied_CountEventResourcesCounts IAM resources affected by access denied errors.
Event Resource Count QueriesIAM_UpdateAssumeRolePolicy_CountEventResourcesCounts IAM resources affected by IAM Assume Role policy changes.
Event Resource Count QueriesLambda_ExcessPermissions_CountEventResourcesCounts Lambda resources related to privileged use of functions.
Event Resource Count QueriesLambda_InteractWithIam_CountEventResourcesCounts Lambda resources that interact with IAM for any reason.
Event Resource Count QueriesRDS_ModifySecurityGroup_CountEventResourcesCounts RDS resources affected by security group changes.
Event Resource Count QueriesRDS_ModifyingAdminPwd,RestoreFromBackup_CountEventResourcesCounts RDS resources affected by modifying admin password or restores from backup.
Event Resource Count QueriesRedshift_DisableEncryption,DisableAccessLogging_CountEventResourcesCounts Redshift resources affected by disabling encryption or Access Logging signals.
Event Resource Count QueriesRedshift_DisableSSL_CountEventResourcesCounts Redshift resources affected by disabling SSL.
Event Resource Count QueriesS3_AccessDeniedOrBucketConfigChecksFromPublicIp_CountEventResourcesCounts S3 buckets affected by access denied errors or configuration checks from public IP addresses.
Event Resource Count QueriesS3_CrudBucketsFromPublicIp_CountEventResourcesCounts S3 buckets affected by Create, Update or Delete actions from public IP addresses.
Event Resource Count QueriesS3_DisableMfaDeleteOrBucketVersionioningOrAccessLogging_CountEventResourcesCounts S3 buckets affected by disabling MFA delete, bucket versioning or access logging.
Event Resource Count QueriesS3_EnablePublicAccess_CountEventResourcesCounts S3 buckets affected by public ingress risk.
Notable Event Count QueriesAggregate_Event_Count_to_Main_IndexMerge results of many scheduled searches into a single index.
Notable Event Count QueriesCloudTrail_DisableGlobalEventsOrDisableLogOrEncryptWithNewKeyCounts the number of events related to disabling trail configurations or encrypting them with a new key.
Notable Event Count QueriesCloudTrail_DisableTrailsCounts the number of events related to disabling trails.
Notable Event Count QueriesEC2_DescribeInstanceUserDataCounts the number of events related to describing EC2 instance metadata.
Notable Event Count QueriesEC2_EventsCounts events related to DisableTerminationProtection, DescribeRouteTables, AuthorizeSecurityGroupIngressToPublic, ListAMIs, ListInstances, ListSecurityGroups, TrafficMirroring.
Notable Event Count QueriesIAM_ConsoleLoginsNoMfaCount of console logins without multi-factor authentication.
Notable Event Count QueriesIAM_EventsCounts IAM events related to AttachPutUserPolicy, AttachPutRolePolicy, AttachPutGroupPolicy, AddUserToGroup, CompromisedUserOrKeys, CreateUpdatePolicy, ConsoleLoginFailureWithHiddenResponse, ConsoleLoginsTotal, UpdateAssumeRolePolicy.
Notable Event Count QueriesIAM_TooManyAccessDeniedCounts IAM events related to access denied errors.
Notable Event Count QueriesLambda_ExcessPermissionsOrInteractWithIamCounts Lambda events related to any IAM interaction or privileged use of functions
Notable Event Count QueriesRDS_ModifyingAdminPasswordCounts events related to change of admin passwords for RDS resources.
Notable Event Count QueriesRDS_RestoreFromBackupOrModifySecGroupCounts events related to restore from backup or security group changes.
Notable Event Count QueriesRedshift_DisableEncryptionCounts Redshift events related to disabling encryption.
Notable Event Count QueriesRedshift_DisableSSLOrDisableAccessloggingCounts Redshift events related to disabling encryption or SSL.
Notable Event Count QueriesS3_AccessDeniedOrBucketConfigChecksFromPublicIpCounts S3 events related to access denied errors or configuration checks from public IP addresses.
Notable Event Count QueriesS3_CrudBucketsFromPublicIp_CountEventResourcesCounts S3 events related to Create, Update or Delete actions from public IP addresses.
Notable Event Count QueriesS3_DisableMfaDeleteOrBucketVersionioningOrAccessLoggingCounts S3 events related to disabling MFA delete, bucket versioning or access logging.
Notable Event Count QueriesS3_EnablePublicAccessCounts S3 events related to enabling public ingress.
Notable Event Count QueriesS3_ListBucketsCounts S3 events related to listing buckets.
- -
- -* To reduce false positives, the benchmarks and application filter out AWS CloudTrail events from legitimate cloud services including AWS itself and CloudHealth by VMware. -* Security posture requirements may vary between AWS accounts for a given customer. For example, development accounts might have less strict controls than production accounts. The app supports filtering findings by AWS account ID to facilitate AWS account level posture assessment. -* The benchmarking models use cohorts calculated from similar AWS accounts. -* This app relies on scheduled searches that save to an index in order to update AWS CloudTrail events periodically. When you first install the app, these searches will take 24 hours to accumulate sufficient data for meaningful comparisons over a 24-hour duration. As a result, it is important that you wait for at least 24 hours after the app installation before using the insights from the app dashboards. -* Initially, when the app is installed, the dashboards will have empty panels until the scheduled searches have run and the indices are populated. -* Scheduled searches are prefixed with "gis_benchmarks" to allow users to isolate these searches in the Data Volume Index. -* If multiple AWS accounts are referenced in the AWS CloudTrail data, the graphs will show values for each benchmark and AWS account combination. To optimize experience, select one AWS Account ID in the application dropdown. -* Do not modify the 24-hour time range in the dashboards as the benchmark data and comparisons are based on a prior 24-hour comparison only. -* Do not modify the schedule and time range of the scheduled searches. -* Do not modify the lookups in the dashboard search queries. -* The panel “Summary of Notable Events and Recommended Actions” on the dashboard “04 Action Plan” will not work until the scheduled search “Event Priority computation” populates the required lookup. -* The "infer" operator is not intended for direct customer use - modifying the queries will result in unexpected/incorrect results. -* For links to the CloudTrail events in the Action Plan dashboard watchlists to work, please make sure to set your Sumo Logic Region Code by clicking on the dashboard filter icon. -* The `infer` operator is not intended for use outside of Sumo Logic Global Intelligence apps. -* Install the [Sumo Logic Audit app](/docs/integrations/sumo-apps/audit) to monitor the health of scheduled searches. The following two dashboards of the Audit app will help look into details for scheduled searches: - * [User Activity - Scheduled Searches](/docs/integrations/sumo-apps/audit#user-activity---scheduled-search) - * [Scheduled Searches - Triggered Summary](/docs/integrations/sumo-apps/audit#scheduled-search---triggered-summary) - -
- -### Sample log messages - -```json -{ - "eventVersion":"1.05", - "userIdentity":{ - "type":"IAMUser", - "principalId":"AIDAJK3NPEULWEXAMPLE", - "arn":"arn:aws:iam::224064EXAMPLE:user/username", - "accountId":"2240example0808", - "userName":"Pamelia@example.com" - }, - "eventTime":"2020-01-11 00:42:12+0000", - "eventSource":"signin.amazonaws.com", - "eventName":"ConsoleLogin", - "awsRegion":"us-example", - "sourceIPAddress":"10.10.10.10", - "userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36", - "requestParameters":null, - "responseElements":{ - "ConsoleLogin":"Success" - }, - "additionalEventData":{ - "LoginTo":"https://us-example.console.aws.amazon...sauthcode=true", - "MobileVersion":"No", - "MFAUsed":"Yes" - }, - "eventID":"8fd88195-8576-example-8330cb492604", - "eventType":"AwsConsoleSignIn", - "recipientAccountId":"22406424example0808" -} -``` - -### Sample queries - -The following sample query is from the **Unique AWS Resource Types** panel of **Dashboard 01: Attack Surface Benchmark**. -```sumo -_sourceCategory=Labs/AWS/CloudTrail/Analytics -| json "eventSource", "errorCode" nodrop -| where isBlank(errorCode) -| count_distinct(eventSource) as count -| "ResourcesCount_Service" as benchmarkname -| fillmissing values("ResourcesCount_Service") in benchmarkname -| toInt(count) as count -| infer _category=cloudtrail _model=benchmark -| first(count) as MyCompany, first(lower_limit) as cohort_low, first(median) as cohort_median, first(upper_limit) as cohort_high by benchmarkname -``` - -In some cases, your query results may show `"HIDDEN_DUE_TO_SECURITY_REASONS"` as the value of the `userName` field. That's because AWS does not log the user name that was entered when a sign-in failure is caused by an incorrect user name. - - -## Collecting logs for the GI for AWS CloudTrail SecOps App - -This section provides an overview of the log collection process and instructions for configuring log collection for the Sumo Logic App for Gl CloudTrail. - -If you have already AWS CloudTrail logs flowing into Sumo Logic, you can skip the steps in this section and [install the app](#installing-the-gi-for-aws-cloudtrail-secops-app). - -The following illustration is a graphical representation of the process for collecting logs from AWS CloudTrail and delivering them to Sumo Logic. - -Collection_Process_Overview - - -### Configuring Log Collection - -To configure log collection for Global Intelligence for AWS CloudTrail, follow the steps described [here](/docs/integrations/amazon-aws/cloudtrail#collecting-logs-for-the-aws-cloudtrail-app). - - -## Installing the GI for AWS CloudTrail SecOps App - -import AppInstall from '../../reuse/apps/app-install.md'; - - - -## Viewing GI CloudTrail Dashboards - -This section provides descriptions and examples of the Global Intelligence for AWS CloudTrail App dashboards. - - -### 01 Attack Surface Benchmark - -**GI CloudTrail - 01 Attack Surface Benchmark** dashboard provides insights into the volume, variety, and velocity of the AWS infrastructure that are correlated with greater breach risks. The number of distinct AWS services in use measures variety, the number of distinct AWS resources measures volume while CloudTrail events measure velocity. The volume dimension only counts resources from 7 services noted above while the variety dimension includes all services referenced in your AWS CloudTrail data. These factors are also used to cohort customers into peer groups. Configuration changes are baselined by peer group to compare the configuration changes of a company and their related breach risks. - -GI CloudTrail - -Use this dashboard to understand how your company compares to peers with respect to the following: -* Variety: Number of distinct services in use among EC2, S3, KMS, IAM, Lambda, Redshift and RDS -* Volume: Number unique AWS resources within each service -* Velocity: The number of create, update, or delete events across all resources within the company - -### 02 Tactics and Techniques: My Company v. Peers - -**GI CloudTrail - 02 Tactics and Techniques: My Company v. Peers** dashboard uses ATT&CK to organize tactics implied by AWS CloudTrail events that appear in your infrastructure and shows the comparison to other AWS customers in your peer group. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. - -GI CloudTrail - -Use this dashboard to: - -* Understand how attack tactics & techniques in my company differ from peers. -* Analyze findings organized by the following ATT&CK techniques: - * Credential Access - * Defense Evasion - * Discovery - * Execution - * Exfiltration - * Initial Access - * Lateral Movement - * Persistence - * Privilege Escalation - -### 03 Tactics by Resource Type: My Company v. Peers - -**GI CloudTrail - 03 Tactics by Resource Type: My Company v. Peers** dashboard utilizes ATT&CK tactics implied by AWS CloudTrail events and maps them to the resources they impact. It also presents data for comparisons of your company impacted resources against that of your peers. - -GI CloudTrail - -Use this dashboard to: -* Understand tactics and techniques for my company versus peers. -* Analyze results organized by the following AWS services: - * Amazon EC2: count of compute instances, security groups, route tables and Amaon Machine Images - * Amazon S3: count of buckets - * Amazon RDS: count of database instances, DB security groups - * Amazon Redshift: count of database clusters and parameter groups - * AWS Lambda: count of function names - * AWS IAM: count of IAM users, roles and groups - * AWS CloudTrail: counts of trail instances - * S3 Tactics - - -### 04 Action Plan - -**GI CloudTrail - 04 Action Plan** dashboard identifies the affected resources for every notable event. This data then enables you to create a proactive action plan for your environment. - -GI CloudTrail - -Use this dashboard to: - -* Create an action plan from the findings of Global Intelligence for AWS CloudTrail. -* Implement and then review the progress of the plan. diff --git a/docs/integrations/amazon-aws/global-intelligence-guardduty.md b/docs/integrations/amazon-aws/global-intelligence-guardduty.md deleted file mode 100644 index 179eed6b75a..00000000000 --- a/docs/integrations/amazon-aws/global-intelligence-guardduty.md +++ /dev/null @@ -1,226 +0,0 @@ ---- -id: global-intelligence-guardduty -title: Global Intelligence for Amazon GuardDuty -sidebar_label: Global Intelligence for Amazon GuardDuty -description: Global Intelligence for Amazon GuardDuty ---- - -import useBaseUrl from '@docusaurus/useBaseUrl'; - -Global Intelligence GuardDuty icon - -[Amazon GuardDuty](https://aws.amazon.com/guardduty/) is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. The Sumo Logic App for Global Intelligence for Amazon GuardDuty analyzes GuardDuty threats from the Sumo Logic population to create baselines of threats. These baselines enable you to optimize security posture and remediation based on how unusual your GuardDuty findings are compared to Sumo Logic customers. The App includes pre-configured dashboards and searches with visual displays for global threat baselines and real-time threat detection across your AWS environment. - -This application name is abbreviated to **GI GuardDuty** in our documentation and the application pages. - -The App includes pre-configured dashboards and searches with visual displays for global threat baselines and real-time threat detection across your AWS environment, including threat sources and targets by geographic locations. - -:::warning -* Global Intelligence baselines are computed by aggregating data for a given customer across all their source categories defined for Amazon GuardDuty. As result, to enable meaningful comparisons, the app must be provided with all the source categories in your Sumo Logic account that are associated with Amazon GuardDuty. Follow the instructions on the [Custom Data Filters](/docs/get-started/apps-integrations#custom-data-filters) page to set up your app with custom data filters, specifying multiple source categories for Amazon GuardDuty. -* Threat score trends are not meaningful beyond the most recent 24 hours. This is because Global Intelligence baselines are the daily average over the most recent 7 days. As a result, the time range in the panels should not be changed beyond the most recent 24 hours. -* The `infer` operator is not intended for use outside of Sumo Logic Global Intelligence apps. -::: - - -## Prerequisites - -This feature is available in the following account plans. - -| Account Type | Account Level -| :---- | :---- -| Cloud Flex | Trial, Enterprise -| Cloud Flex Credits | Trial, Enterprise Suite, Enterprise Security - - -## Log types - -The Sumo Logic App for GI GuardDuty requires the Amazon GuardDuty findings to be sent through the Amazon CloudWatch Events. For more details on [GuardDuty findings](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings.html). - -### Sample log message - -```json -{ - "schemaVersion":"2.0", - "accountId":"656575676767", - "region":"us-east-1", - "partition":"aws", - "id":"1cb6b9059fa3c8cbb682a9a2501bfb13", - "arn":"arn:aws:guardduty:us-east-1:656575676767:detector/46554yhtu78yuhh5676777787hy06767/finding/1cb6b9059fa3c8cbb682a9a2501bfb13", - "type":"Trojan:EC2/BlackholeTraffic", - "resource":{ - "resourceType":"Instance", - "instanceDetails":{ - "instanceId":"i-99999999", - "instanceType":"m3.xlarge", - "launchTime":"2016-08-02T02:05:06Z", - "platform":null, - "productCodes":[ - { - "productCodeId":"GeneratedFindingProductCodeId", - "productCodeType":"GeneratedFindingProductCodeType" - } - ], - "iamInstanceProfile":{ - "arn":"GeneratedFindingInstanceProfileArn", - "id":"GeneratedFindingInstanceProfileId" - }, - "networkInterfaces":[ - { - "networkInterfaceId":"eni-bfcffe88", - "privateIpAddresses":[ - { - "privateDnsName":"GeneratedFindingPrivateName", - "privateIpAddress":"10.0.0.1" - } - ], - "subnetId":"GeneratedFindingSubnetId", - "vpcId":"GeneratedFindingVPCId", - "privateDnsName":"GeneratedFindingPrivateDnsName", - "securityGroups":[ - { - "groupName":"GeneratedFindingSecurityGroupName", - "groupId":"GeneratedFindingSecurityId" - } - ], - "publicIp":"198.51.100.0", - "ipv6Addresses":[ - - ], - "publicDnsName":"GeneratedFindingPublicDNSName", - "privateIpAddress":"10.0.0.1" - } - ], - "tags":[ - { - "value":"GeneratedFindingInstaceValue1", - "key":"GeneratedFindingInstaceTag1" - }, - { - "value":"GeneratedFindingInstaceTagValue2", - "key":"GeneratedFindingInstaceTag2" - } - ] - } - } -} -``` - - -### Sample queries - -The following query is from the threat score trend line in the **GI GuardDuty: Your Company v. Global Baseline** dashboard. - -```sumo -_sourceCategory=GIS/test/guardduty -| json "accountId", "arn", "type","service.detectorId","service.action","severity","title","description","region" nodrop -| json "type", "severity" -| parse field=type "*:*/*" as threatpurpose, resource, threatname -| toInt(severity) as severity -| count by resource, threatname, severity -| infer _category=guardduty _model=trendline n=7 -| (100.0 - (round(score * 10000) / 100)) as score -// Convert to time chart -| _timestamp as _timeslice -| fields - _timestamp -| max(score) as score by _timeslice -| sort by _timeslice asc -``` - - -## Configuring Log Collection and Deploy the GI GuardDuty App - -This section explains the log collection process and provides instructions for configuring log collection and installing the GI GuardDuty App. - -If you have already Amazon GuardDuty data flowing into Sumo Logic, you can skip these steps and install the App from the Sumo Logic App Catalog. - -### Process overview - -Sumo Logic provides a SAM application based on [AWS Serverless Application Model (SAM) specification](https://docs.aws.amazon.com/lambda/latest/dg/serverless_app.html), and is published in the [AWS Serverless Application Repository](https://aws.amazon.com/serverless/serverlessrepo/). This SAM deployment: -1. Creates a Lambda function and its associated components. -2. Creates collector, and HTTP Source at Sumo Logic. -3. Installs the Sumo Logic GI GuardDuty App. - -After completing this process, logs are ingested into Sumo Logic in the following way: -1. Amazon GuardDuty sends notifications based on CloudWatch events when new findings, or new occurrences of existing findings, are generated. -2. A CloudWatch events rule enables CloudWatch to send events for the GuardDuty findings to the Sumo CloudWatchEventFunction Lambda function. -3. The Lambda function sends the events to an HTTP source on a Sumo Logic hosted collector. - - -This section shows you how to generate an access key and access ID for log collection, and then how to deploy the Amazon GuardDuty Benchmark App. - -These tasks require the Manage Collectors and Manage Access Keys [role capabilities](/docs/manage/users-roles/roles/role-capabilities). - - -#### Step 1: Generate an Access Key and Access ID - -In this step, you need to generate access key and access ID from the Sumo Logic console. To generate an access key and access ID, do the following: - -1. Follow the instructions as described in [Access Keys](/docs/manage/security/access-keys). -2. Copy down both the values as you’ll need them to deploy the Sumo Logic GuardDuty Benchmark SAM App. - - -#### Step 2: Deploy the Sumo Logic GI GuardDuty SAM App - -In this step, you deploy the SAM application, which creates the AWS resources described in the [process overview](#process-overview). - -To deploy the Sumo Logic GuardDuty Benchmark SAM App, do the following: - -1. Go to [https://serverlessrepo.aws.amazon.com/applications](https://serverlessrepo.aws.amazon.com/applications). -2. Search for **sumologic-guardduty-benchmark** and click the app link when it appears. -3. When the page for the Sumo app appears, click **Deploy**. -4. In **Configure application parameters** panel, enter the following parameters: - * Access ID (Required). Sumo Logic Access ID generated from Step 1. - * Access Key (Required). Sumo Logic Access Key generated from Step 1. - * Deployment Name (Required). Deployment name (environment name in lower case as per [docs](/docs/api/about-apis/getting-started#sumo-logic-endpoints-by-deployment-and-firewall-security)). - * Collector Name. Enter the name of the Hosted Collector which will be created in Sumo Logic. - * Source Name. Enter the name of the HTTP Source which will be created within the collector. - * Source Category Name. Enter the name of the Source Category which will be used for writing search queries. -5. Click **Deploy**. -6. When the deployment is successful, click **View CloudFormation Stack**. -7. In the Outputs section, copy the app folder name to search your personal folder in the Sumo Logic console. - - -## Viewing the GI GuardDuty App Dashboards - -**Each dashboard has a set of filters** that you can apply to the entire dashboard, as shown in the following example. Click the funnel icon in the top dashboard menu bar to display a scrollable list of filters that are applied across the entire dashboard. - -**Each panel has a set of filters** that are applied to the results for that panel only, as shown in the following example. Click the funnel icon in the top panel menu bar to display a list of panel-specific filters. - - -### 01. Global Baseline - -**GI GuardDuty - 01. Global Baseline** dashboard provides a high-level baseline of threats across Sumo Logic customers. Panels display graphs for threat and severity distribution, targeted resources, and relative rarity. - -GI GuardDuty - -Use this dashboard to: -* Determine if you are being attacked by a particular region or actor around the globe. -* Assess rare threats found by Amazon GuardDuty in your AWS environment. -* Analyze threat shares targeted resources and severity. - - -### 02. Your Company v. Global Baseline - -**GI GuardDuty - 02. Your Company v. Global Baseline** dashboard compares your AWS environment against all Sumo Logic customers. The threat score (0=LOW RISK, 100=HIGH RISK) is a composite view of risk associated with GuardDuty findings and is impacted by severity, number of findings, deviation from global baseline and rarity of threats within Sumo Logic customers. In addition to the latest score, the trend line panel shows the 7 day trend of the threat score. My Prioritized Action Plan lists the change management actions in order of impact on GuardDuty security posture. - -GI GuardDuty - -Use this dashboard to: -* Understand top level threat score and trends. -* How your company’s GuardDuty findings compare to Sumo Logic customers. -* How your company’s findings severity compares to Sumo Logic customers. -* Understand which threats to remediate prioritized based on the greatest impact to threat score. -* Review a prioritized action plan for your company. - - -### 03. Findings Analysis - -**GI GuardDuty - 03. Findings Analysis** dashboard provides a high-level view of threats to your AWS environment. Panels display information on threats by threat purpose, geography, impacted resource type, account, severity and trends. - -GI GuardDuty - -Use this dashboard to: -* Understand the mix of threats in your environment. -* Identify the source and target of threats in your environment. -* Review your company's threats by severity and resource type. -* Review your company's threats by account, security group, EC2 instances, and threat trends. diff --git a/docs/integrations/amazon-aws/index.md b/docs/integrations/amazon-aws/index.md index c541bda17a9..a87c218c552 100644 --- a/docs/integrations/amazon-aws/index.md +++ b/docs/integrations/amazon-aws/index.md @@ -553,27 +553,6 @@ This guide has documentation for all of the apps that Sumo provides for Amazon a CIS for AWS icon

Cloud Infrastructure Security for AWS

A guide to our Cloud Infrastructure Security for AWS app.

- - -
-
- GuardDuty Benchmark icon -

Global Intelligence for Amazon GuardDuty

-

A guide to the Sumo Logic app for Global Intelligence for Amazon GuardDuty.

-
-
-
-
- Global Intelligence Devops icon -

Global Intelligence for AWS CloudTrail DevOps

-

A guide to the Global Intelligence for AWS CloudTrail DevOps app.

-
-
-
-
- Global Intelligence Secops icon -

Global Intelligence for AWS CloudTrail SecOps

-

A guide to the Global Intelligence for AWS CloudTrail SecOps app.

diff --git a/docs/integrations/amazon-aws/security-quickstart.md b/docs/integrations/amazon-aws/security-quickstart.md index e39227093eb..708c8b4cbc7 100644 --- a/docs/integrations/amazon-aws/security-quickstart.md +++ b/docs/integrations/amazon-aws/security-quickstart.md @@ -14,13 +14,11 @@ The Sumo Logic Amazon Security Quick Start solution helps you automate the colle ## Sumo Logic Security Integrations for AWS Organizations -The Sumo Logic Security Integrations for AWS Organizations solution is based on Amazon’s [Security reference Architecture](https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/welcome.html) and helps you automate the collection of security events from AWS security services from multiple accounts and the installation and configuration of 9 Sumo Logic apps designed for AWS Security including: +The Sumo Logic Security Integrations for AWS Organizations solution is based on Amazon’s [Security reference Architecture](https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/welcome.html) and helps you automate the collection of security events from AWS security services from multiple accounts and the installation and configuration of 7 Sumo Logic apps designed for AWS Security including: * Amazon CloudTrail - Cloud Security Monitoring and Analytics * Amazon GuardDuty - Cloud Security Monitoring and Analytics * CIS AWS foundations Benchmark -* Global Intelligence for Amazon GuardDuty -* Global Intelligence for AWS CloudTrail SecOps * PCI compliance for AWS CloudTrail * AWS Security Hub - Cloud Security Monitoring and Analytics * AWS Network Firewall @@ -29,12 +27,11 @@ The Sumo Logic Security Integrations for AWS Organizations solution is based on ## Sumo Logic Security Integrations for a Single AWS Account -The Sumo Logic AWS Security Quick Start solution helps you automate the collection of security events from AWS security services and the installation and configuration of 16 Sumo Logic apps designed for AWS Security including: +The Sumo Logic AWS Security Quick Start solution helps you automate the collection of security events from AWS security services and the installation and configuration of 13 Sumo Logic apps designed for AWS Security including: * AWS CloudTrail * CIS AWS foundations Benchmark * Amazon GuardDuty -* Global Intelligence for Amazon GuardDuty * Amazon VPC flow logs * PCI DSS compliance for Amazon VPC flow logs * Threat Intel for AWS @@ -44,7 +41,6 @@ The Sumo Logic AWS Security Quick Start solution helps you automate the collecti * AWS Config * Amazon CloudTrail - Cloud Security Monitoring and Analytics * Amazon VPC Flow - Cloud Security Monitoring and Analytics -* Global Intelligence for AWS CloudTrail SecOps * AWS Network Firewall diff --git a/docs/integrations/global-intelligence/index.md b/docs/integrations/global-intelligence/index.md index 21361609a1a..43236d1693b 100644 --- a/docs/integrations/global-intelligence/index.md +++ b/docs/integrations/global-intelligence/index.md @@ -1,37 +1,16 @@ --- slug: /integrations/global-intelligence title: Global Intelligence Service -description: Our Global Intelligence Service apps provide security teams with valuable real-time security intelligence to scale detection, prioritization, investigation, and workflow to prevent potentially harmful service configurations that could lead to a costly data breach. +description: The Global Intelligence Service app provides security teams with valuable real-time security intelligence to scale detection, prioritization, investigation, and workflow to prevent potentially harmful service configurations that could lead to a costly data breach. --- import useBaseUrl from '@docusaurus/useBaseUrl'; Global Intelligence icon -Our Global Intelligence Service apps provide security teams with valuable real-time security intelligence to scale detection, prioritization, investigation, and workflow to prevent potentially harmful service configurations that could lead to a costly data breach. +The Global Intelligence Service app provides security teams with valuable real-time security intelligence to scale detection, prioritization, investigation, and workflow to prevent potentially harmful service configurations that could lead to a costly data breach.
-
-
- Global Intelligence GuardDuty icon -

Global Intelligence for Amazon GuardDuty

-

A guide to the Sumo Logic app for GI for Amazon GuardDuty.

-
-
-
-
- Global Intelligence Devops icon -

Global Intelligence for AWS CloudTrail DevOps

-

A guide to the Sumo Logic app for GI for AWS CloudTrail DevOps.

-
-
-
-
- Global Intelligence Secops icon -

Global Intelligence for AWS CloudTrail SecOps

-

A guide to the Sumo Logic app for GI for AWS CloudTrail SecOps.

-
-
Cloud SIEM icon @@ -40,4 +19,3 @@ Our Global Intelligence Service apps provide security teams with valuable real-t
- diff --git a/docs/integrations/product-list/product-list-a-l.md b/docs/integrations/product-list/product-list-a-l.md index cf8a8cf4b98..dbe61b2b1a7 100644 --- a/docs/integrations/product-list/product-list-a-l.md +++ b/docs/integrations/product-list/product-list-a-l.md @@ -52,7 +52,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [ | Amazon Emr icon | [Amazon EMR](https://aws.amazon.com/emr/) | App: [Amazon EMR](/docs/integrations/amazon-aws/amazon-emr/) | | Amazon Eventbridge icon | [Amazon EventBridge](https://aws.amazon.com/eventbridge/) | App: [Amazon EventBridge](/docs/integrations/amazon-aws/amazon-eventbridge/) | | Amazon Gamelift icon | [Amazon GameLift](https://aws.amazon.com/gamelift/) | App: [Amazon GameLift](/docs/integrations/amazon-aws/amazon-gamelift/) | -| GuardDuty icon | [Amazon GuardDuty](https://aws.amazon.com/guardduty/) | Apps:
- [Amazon GuardDuty](/docs/integrations/amazon-aws/guardduty/)
- [Amazon GuardDuty - Cloud Security Monitoring and Analytics](/docs/integrations/cloud-security-monitoring-analytics/amazon-guardduty/)
- [Global Intelligence for Amazon GuardDuty](/docs/integrations/amazon-aws/global-intelligence-guardduty/)
- [Amazon GuardDuty Benchmark](/docs/integrations/amazon-aws/guardduty-benchmark/)
Automation integration: [AWS GuardDuty](/docs/platform-services/automation-service/app-central/integrations/aws-guardduty/)
Cloud SIEM integration: [Amazon AWS - GuardDuty](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/2ca0adcf-7616-4474-8557-a3773515aa6d.md) | +| GuardDuty icon | [Amazon GuardDuty](https://aws.amazon.com/guardduty/) | Apps:
- [Amazon GuardDuty](/docs/integrations/amazon-aws/guardduty/)
- [Amazon GuardDuty - Cloud Security Monitoring and Analytics](/docs/integrations/cloud-security-monitoring-analytics/amazon-guardduty/)
- [Amazon GuardDuty Benchmark](/docs/integrations/amazon-aws/guardduty-benchmark/)
Automation integration: [AWS GuardDuty](/docs/platform-services/automation-service/app-central/integrations/aws-guardduty/)
Cloud SIEM integration: [Amazon AWS - GuardDuty](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/2ca0adcf-7616-4474-8557-a3773515aa6d.md) | | Inspector Classic icon | [Amazon Inspector](https://aws.amazon.com/inspector/) | Apps:
- [Amazon Inspector](/docs/integrations/amazon-aws/inspector/)
- [Amazon Inspector Classic](/docs/integrations/amazon-aws/inspector-classic/)
Automation integration: [AWS Inspector](/docs/platform-services/automation-service/app-central/integrations/aws-inspector/)
Cloud SIEM integration: [Amazon AWS - Inspector](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/ab4056ab-305e-4362-add8-c15c1f7b8afc.md) | | Kinesis icon | [Amazon Kinesis](https://aws.amazon.com/kinesis/) | App: [Amazon Kinesis - Streams](/docs/integrations/amazon-aws/kinesis-streams/)
Collectors:
- [AWS Kinesis Firehose for Logs Source](/docs/send-data/hosted-collectors/amazon-aws/aws-kinesis-firehose-logs-source/)
- [AWS Kinesis Firehose for Metrics Source](/docs/send-data/hosted-collectors/amazon-aws/aws-kinesis-firehose-metrics-source/) | | Amazon Prometheus icon | [Amazon Prometheus](https://aws.amazon.com/prometheus/) | Collector: [Amazon MSK Prometheus metrics collection](/docs/send-data/collect-from-other-data-sources/amazon-msk-prometheus-metrics-collection/) | @@ -99,7 +99,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [ | AWS Client Vpn icon | [AWS Client VPN](https://aws.amazon.com/vpn/client-vpn/) | App: [AWS Client VPN](/docs/integrations/amazon-aws/aws-client-vpn/) | | AWS Cloudformation icon | [AWS CloudFormation](https://aws.amazon.com/cloudformation/) | Collector: [Configuring Your AWS Source with CloudFormation](/docs/send-data/hosted-collectors/amazon-aws/configure-your-aws-source-cloudformation/) | | AWS Cloudhsm icon | [AWS CloudHSM](https://aws.amazon.com/cloudhsm/) | App: [AWS CloudHSM](/docs/integrations/amazon-aws/aws-cloudhsm/) | -| CloudTrail icon | [AWS CloudTrail](https://aws.amazon.com/pm/cloudtrail/) | Apps:
- [Amazon CloudTrail - Cloud Security Monitoring and Analytics](/docs/integrations/cloud-security-monitoring-analytics/aws-cloudtrail/)
- [AWS CloudTrail](/docs/integrations/amazon-aws/cloudtrail/)
- [Global Intelligence for AWS CloudTrail DevOps](/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops/)
- [Global Intelligence for AWS CloudTrail SecOps](/docs/integrations/amazon-aws/global-intelligence-cloudtrail-secops/)
- [PCI Compliance For AWS CloudTrail](/docs/integrations/amazon-aws/cloudtrail-pci-compliance/)
- [Threat Intel for AWS](/docs/integrations/amazon-aws/threat-intel/)
Automation integration: [AWS CloudTrail](/docs/platform-services/automation-service/app-central/integrations/aws-cloudtrail/)
Cloud SIEM integration: [Amazon AWS - CloudTrail](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/033624b0-218e-4dcb-b93f-0f1fb1806c56.md)
Collector:
- [AWS CloudTrail Source](/docs/send-data/hosted-collectors/amazon-aws/aws-cloudtrail-source/)
Community app: [Sumo Logic for AWS CloudTrail User Activity](https://github.com/SumoLogic/sumologic-content/tree/master/Amazon_Web_Services/AWS_CloudTrail) | +| CloudTrail icon | [AWS CloudTrail](https://aws.amazon.com/pm/cloudtrail/) | Apps:
- [Amazon CloudTrail - Cloud Security Monitoring and Analytics](/docs/integrations/cloud-security-monitoring-analytics/aws-cloudtrail/)
- [AWS CloudTrail](/docs/integrations/amazon-aws/cloudtrail/)
- [PCI Compliance For AWS CloudTrail](/docs/integrations/amazon-aws/cloudtrail-pci-compliance/)
- [Threat Intel for AWS](/docs/integrations/amazon-aws/threat-intel/)
Automation integration: [AWS CloudTrail](/docs/platform-services/automation-service/app-central/integrations/aws-cloudtrail/)
Cloud SIEM integration: [Amazon AWS - CloudTrail](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/033624b0-218e-4dcb-b93f-0f1fb1806c56.md)
Collector:
- [AWS CloudTrail Source](/docs/send-data/hosted-collectors/amazon-aws/aws-cloudtrail-source/)
Community app: [Sumo Logic for AWS CloudTrail User Activity](https://github.com/SumoLogic/sumologic-content/tree/master/Amazon_Web_Services/AWS_CloudTrail) | | AWS Codebuild icon | [AWS CodeBuild](https://aws.amazon.com/codebuild/) | App: [AWS CodeBuild](/docs/integrations/amazon-aws/aws-codebuild/) | | Config icon | [AWS Config](https://aws.amazon.com/config/) | App: [AWS Config](/docs/integrations/amazon-aws/config/)
Cloud SIEM integration: [Amazon AWS - Config](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/f3c04c88-2543-41d5-ab5d-cf0198d695f7.md) | | AWS Cost Explorer icon | [AWS Cost Explorer](https://aws.amazon.com/aws-cost-management/aws-cost-explorer/) | App: [AWS Cost Explorer](/docs/integrations/amazon-aws/cost-explorer/)
Collector: [AWS Cost Explorer Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-cost-explorer-source/) | diff --git a/docs/observability/aws/deploy-use-aws-observability/changelog.md b/docs/observability/aws/deploy-use-aws-observability/changelog.md index 529c465004c..e4e18c21d85 100644 --- a/docs/observability/aws/deploy-use-aws-observability/changelog.md +++ b/docs/observability/aws/deploy-use-aws-observability/changelog.md @@ -81,7 +81,11 @@ Updates: - sumologic-s3-logging-auto-enable → 1.0.18 Deprecation: -* The Global Intelligence for AWS CloudTrail DevOps app is scheduled for deprecation in the near future and, as a result, has been removed from the AWS Observability Solution. +* The following Global Intelligence Service apps are scheduled for deprecation in the near future: + * Global Intelligence for Amazon GuardDuty. + * Global Intelligence for AWS CloudTrail DevOps. + * Global Intelligence for AWS CloudTrail SecOps. +* The Global Intelligence for AWS CloudTrail DevOps app has been removed from the AWS Observability Solution. * AWS Observability Solution versions that rely on deprecated AWS Lambda runtimes are also considered deprecated. Since Nodejs18.x was deprecated on September 1st, 2025, all AWS Observability versions up to and including 2.8.0 are now deprecated. ## v2.12.0, 01-Apr-2025 diff --git a/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md b/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md index 0b303b20ebe..1645decedb0 100644 --- a/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md +++ b/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md @@ -45,8 +45,7 @@ AWS Observability integrates with the [AWS Observability view](/docs/dashboards/ Download this or other versions of this template from [Changelog](../changelog.md).  ::: :::note - - To change the Collector Name and Source Categories of Sumo Logic sources, you must download CloudFormation template version 2.12.0 or greater and follow the instructions in the [Modify the source categories](#modify-the-source-categories) section. - - The Global Intelligence for AWS CloudTrail DevOps app is planned for deprecation in the near future and has therefore been removed from the AWS Observability Solution. With this removal, the app will no longer be backed up or maintained during future solution upgrades. + To change the Collector Name and Source Categories of Sumo Logic sources, you must download CloudFormation template version 2.12.0 or greater and follow the instructions in the [Modify the source categories](#modify-the-source-categories) section. ::: 1. Select the AWS Region where you want to deploy the AWS CloudFormation template. :::danger diff --git a/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md b/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md index cbef317af84..d9f38d23091 100644 --- a/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md +++ b/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md @@ -31,11 +31,6 @@ If you've previously set up our AWS Observability Solution with CloudFormation a ::: -:::note -The [Global Intelligence for AWS CloudTrail DevOps](/docs/integrations/amazon-aws/global-intelligence-cloudtrail-devops/) app is planned for deprecation in the near future and has therefore been removed from the AWS Observability Solution. With this removal, the app will no longer be backed up or maintained during future solution upgrades. -::: - - For this setup, complete the following: 1. Set up the [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-install.html). diff --git a/docs/security/index.md b/docs/security/index.md index a7bf512868b..3bdb03e6339 100644 --- a/docs/security/index.md +++ b/docs/security/index.md @@ -37,7 +37,7 @@ Following are features available with our security solutions. If you have any qu | App catalog (out-of-the-box analytics) | ✓ | ✓ | ✓ | | Dashboard | ✓ | ✓ | ✓ | | Deep search (Sumo Logic Search Query Language) | ✓ | ✓ | ✓ | -| Advanced analytics with machine learning (Global Intelligence Service for GuardDuty and CloudTrail) | ✓ | ✓ | ✓ | +| Advanced analytics with machine learning (Global Intelligence Service) | ✓ | ✓ | ✓ | | Monitoring | ✓ | ✓ | ✓ | | Alerts | ✓ | ✓ | ✓ | | Threat Intelligence (threat intel feed and threat analysis app) | ✓ | ✓ | ✓ | diff --git a/sidebars.ts b/sidebars.ts index fb892077849..bc08d5e8740 100644 --- a/sidebars.ts +++ b/sidebars.ts @@ -2255,9 +2255,6 @@ integrations: [ 'integrations/amazon-aws/waf', 'integrations/amazon-aws/cis-aws-foundations-benchmark', 'security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws', - 'integrations/amazon-aws/global-intelligence-guardduty', - 'integrations/amazon-aws/global-intelligence-cloudtrail-devops', - 'integrations/amazon-aws/global-intelligence-cloudtrail-secops', 'integrations/amazon-aws/vpc-flow-logs-pci-compliance', 'integrations/amazon-aws/cloudtrail-pci-compliance' ], @@ -2602,9 +2599,6 @@ integrations: [ collapsed: true, link: {type: 'doc', id: 'integrations/global-intelligence/index'}, items: [ - 'integrations/amazon-aws/global-intelligence-guardduty', - 'integrations/amazon-aws/global-intelligence-cloudtrail-devops', - 'integrations/amazon-aws/global-intelligence-cloudtrail-secops', 'cse/records-signals-entities-insights/global-intelligence-security-insights', ], }, diff --git a/static/img/integrations/amazon-aws/Collection_Process_Overview-devops.png b/static/img/integrations/amazon-aws/Collection_Process_Overview-devops.png deleted file mode 100644 index c8d590e7500..00000000000 Binary files a/static/img/integrations/amazon-aws/Collection_Process_Overview-devops.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/Collection_Process_Overview.png b/static/img/integrations/amazon-aws/Collection_Process_Overview.png deleted file mode 100644 index c8d590e7500..00000000000 Binary files a/static/img/integrations/amazon-aws/Collection_Process_Overview.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-01Attack.png b/static/img/integrations/amazon-aws/GI-CloudTrail-01Attack.png deleted file mode 100644 index d7e5d6e0546..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-01Attack.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-02-Tactics.png b/static/img/integrations/amazon-aws/GI-CloudTrail-02-Tactics.png deleted file mode 100644 index 4e4f6cb243a..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-02-Tactics.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-03-Tactics.png b/static/img/integrations/amazon-aws/GI-CloudTrail-03-Tactics.png deleted file mode 100644 index 8d640dd1fe7..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-03-Tactics.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-04-Action-Plan.png b/static/img/integrations/amazon-aws/GI-CloudTrail-04-Action-Plan.png deleted file mode 100644 index bb852e5a5f7..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-04-Action-Plan.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-AWS-Service-Availability.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-AWS-Service-Availability.png deleted file mode 100644 index de808e8732b..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-AWS-Service-Availability.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-Action-Plan.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-Action-Plan.png deleted file mode 100644 index 731a5c8a245..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-Action-Plan.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-Configuration-Benchmarks.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-Configuration-Benchmarks.png deleted file mode 100644 index 6d891323042..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-Configuration-Benchmarks.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-My-Companys-Account-Quota-Errors.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-My-Companys-Account-Quota-Errors.png deleted file mode 100644 index c67b7135755..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-My-Companys-Account-Quota-Errors.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-My-Companys-Throttling-Errors.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-My-Companys-Throttling-Errors.png deleted file mode 100644 index a9129dc4b24..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOps-My-Companys-Throttling-Errors.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOpsDB_1.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOpsDB_1.png deleted file mode 100644 index 6b464f4eac9..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOpsDB_1.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOpsDB_2.png b/static/img/integrations/amazon-aws/GI-CloudTrail-DevOpsDB_2.png deleted file mode 100644 index b56e6817f68..00000000000 Binary files a/static/img/integrations/amazon-aws/GI-CloudTrail-DevOpsDB_2.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI_GuardDuty_Findings_Analysis.png b/static/img/integrations/amazon-aws/GI_GuardDuty_Findings_Analysis.png deleted file mode 100644 index 4dd142d6bdf..00000000000 Binary files a/static/img/integrations/amazon-aws/GI_GuardDuty_Findings_Analysis.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI_GuardDuty_Global_Baseline.png b/static/img/integrations/amazon-aws/GI_GuardDuty_Global_Baseline.png deleted file mode 100644 index 834dd635266..00000000000 Binary files a/static/img/integrations/amazon-aws/GI_GuardDuty_Global_Baseline.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/GI_GuardDuty_Your_Company_v_Baseline.png b/static/img/integrations/amazon-aws/GI_GuardDuty_Your_Company_v_Baseline.png deleted file mode 100644 index bbe6ed6f8c9..00000000000 Binary files a/static/img/integrations/amazon-aws/GI_GuardDuty_Your_Company_v_Baseline.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/gi-devops.png b/static/img/integrations/amazon-aws/gi-devops.png deleted file mode 100644 index 754c110ce44..00000000000 Binary files a/static/img/integrations/amazon-aws/gi-devops.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/gi-guardduty.png b/static/img/integrations/amazon-aws/gi-guardduty.png deleted file mode 100644 index 1e35344ce8e..00000000000 Binary files a/static/img/integrations/amazon-aws/gi-guardduty.png and /dev/null differ diff --git a/static/img/integrations/amazon-aws/gi-secops.png b/static/img/integrations/amazon-aws/gi-secops.png deleted file mode 100644 index 443b0b34579..00000000000 Binary files a/static/img/integrations/amazon-aws/gi-secops.png and /dev/null differ