Forum Discussion
sneakypanda
Jul 30, 2023Copper Contributor
Loading Cloudfront logs into Sentinel
Hi, I am after suggestions on the best way of loading AWS Cloudfront logs into Microsoft Sentinel. I have the Sentinel AWS connector deployed and it is ingesting Cloudtrail events. The connector do...
Lzng3r
Aug 06, 2023Copper Contributor
Did you manage to find a solution? I am starting to explore this now as well.
sneakypanda
Aug 09, 2023Copper Contributor
Not as of yet.
Passing the logs through Cloudwatch looks to be the easiest way. The Sentinel connector can pick these up natively. My concern with this is that it would bill for ingested data twice.
Passing the logs through Cloudwatch looks to be the easiest way. The Sentinel connector can pick these up natively. My concern with this is that it would bill for ingested data twice.
- Lzng3rSep 12, 2023Copper ContributorI didn't think about the data possibly being ingested twice.