Forum Discussion

abon13's avatar
abon13
Brass Contributor
Oct 24, 2023
Solved

AWS web server log ingestion to Sentinel

HI,

 

I have an AWS web server and would like to ingest the access logs from this web server to Sentinel.

Based on research, I see there is Azure AWS connector but looks like the connector is useful to pull only service logs

 

Wanted to check what is the best way to get the logs from the web server to Sentinel ?

 

Thanks !!

  • Hey abon13 

     

    There are a few ways to go about this, depending on what you have available and setup within your Azure Tenancy

     

    You could do any number of the following

     

    Defender for Endpoint Agent

    Azure Monitoring Agent

    AWS CloudTrail and Cloudwatch

     

    Really depends what you want to get out of monitoring your web server and what for?

     

     

  • Hey abon13 

     

    There are a few ways to go about this, depending on what you have available and setup within your Azure Tenancy

     

    You could do any number of the following

     

    Defender for Endpoint Agent

    Azure Monitoring Agent

    AWS CloudTrail and Cloudwatch

     

    Really depends what you want to get out of monitoring your web server and what for?

     

     

    • abon13's avatar
      abon13
      Brass Contributor
      Thanks !! I was able to get the job done via Azure Arc that ends up installing AMA

Resources