This guide explains how SOCFortress collects logs from your Amazon Web Services (AWS) environment, which AWS services you can send us, and how to create the read-only access we need.
Start here. Every AWS integration begins with this article. You'll set up log delivery for the services you choose (using the service guides linked below), then come back to finish the access setup and test it yourself before sending anything to us.
We never delete, modify or write anything in your AWS account. The access you create in this guide is read-only.
⭐ Recommended baseline: start with CloudTrail + GuardDuty. Together they cover the large majority of what matters for security monitoring in AWS. You can add more services later.
Some services add to your AWS bill (for example CloudTrail data events, VPC Flow Logs and GuardDuty). Talk to us if you're unsure which to enable.
Follow the guide for each service you chose:
While you work through it, note down:
Keep the bucket private. Block all public access should stay enabled.
Come back here once logs have started appearing in the bucket.
YOUR_LOG_BUCKET
{ "Version": "2012-10-17", "Statement": [ { "Sid": "SOCFortressReadLogBucket", "Effect": "Allow", "Action": [ "s3:GetObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::YOUR_LOG_BUCKET", "arn:aws:s3:::YOUR_LOG_BUCKET/*" ] } ] }
Add these extra statements if they apply to you. Add them inside the "Statement": [ ... ] list, separated by commas.
"Statement": [ ... ]
If your logs are encrypted with a KMS key (always the case for GuardDuty, and for CloudTrail if SSE-KMS is enabled). Add one KMS key ARN per key:
{ "Sid": "SOCFortressDecryptLogs", "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "arn:aws:kms:REGION:ACCOUNT_ID:key/KEY_ID" }
If you enabled VPC Flow Logs:
{ "Sid": "SOCFortressDescribeFlowLogs", "Effect": "Allow", "Action": "ec2:DescribeFlowLogs", "Resource": "*" }
Click Next, name the policy SOCFortress-Wazuh-ReadOnly, and click Create policy.
SOCFortress-Wazuh-ReadOnly
Don't add delete permissions (s3:DeleteObject). SOCFortress only needs to read your logs.
s3:DeleteObject
socfortress-wazuh
Treat the access key like a password. Don't email it or paste it into a chat or ticket.
Before sending anything to us, confirm the new user can read your logs. You'll need the AWS CLI installed on your computer, or you can use AWS CloudShell (the >_ icon in the console).
>_
Create a temporary test profile with the new user's key:
aws configure --profile socfortress-test
Enter the Access key ID, the Secret access key, and your default region (for example us-east-1). Leave the output format blank.
us-east-1
Confirm the key is valid:
aws sts get-caller-identity --profile socfortress-test
Expected: JSON showing your account ID and "Arn": "arn:aws:iam::ACCOUNT_ID:user/socfortress-wazuh".
"Arn": "arn:aws:iam::ACCOUNT_ID:user/socfortress-wazuh"
Confirm the user can list your logs:
aws s3 ls s3://YOUR_LOG_BUCKET/ --recursive --profile socfortress-test --page-size 10
You should see log files (for CloudTrail, under AWSLogs/ACCOUNT_ID/CloudTrail/...). Press Ctrl+C once you've seen a few lines.
AWSLogs/ACCOUNT_ID/CloudTrail/...
Confirm the user can download a log file. Copy one file name from the previous output:
aws s3 cp s3://YOUR_LOG_BUCKET/PATH/TO/ONE/LOG/FILE.json.gz ./socfortress-test.json.gz --profile socfortress-test
If your logs are KMS-encrypted (GuardDuty, or CloudTrail with SSE-KMS), test one of those files too. This confirms the KMS permission works.
Clean up. Delete the downloaded test file, and remove the [socfortress-test] section from your AWS credentials file (~/.aws/credentials on Mac/Linux, %USERPROFILE%\.aws\credentials on Windows).
[socfortress-test]
~/.aws/credentials
%USERPROFILE%\.aws\credentials
InvalidClientTokenId
SignatureDoesNotMatch
AccessDenied
ls
cp
kms:Decrypt
Upload the following to your OneHub folder (not email):
We'll configure the integration and let you know once your AWS logs are visible in your SIEM.
Wazuh
AWS
Questions? Reply to your support case and we'll help.
Was this article helpfu?
Thank you for voting
You are related to multiple companies. Please select the company you wish to login as.