Wednesday, October 5, 2016

CloudTrail and Splunk


1) Navigate to CloudTrail > Add new trail
    Trail: my-cloudtrail
    Apply trail to all regions: Yes
    Create new S3 bucket: Yes
    S3 bucket: my-cloudtrail
    Advanced
      Send SNS notification for every log file delivery: Yes
      Create a new SNS topic: my-sns-topic-cloudtrail
    Create
   
2) Create SQS Queue
      Services > SQS > Create New Queue > Create
        Queue Name: my-sqs-cloudtrail

3) Subscribe SQS Queue to SNS Topic
      Services > SQS > my-sqs-cloudtrail > Queue Actions > Subscribe Queue to SNS Topic
      > Choose a Topic >  my-sns-topic-cloudtrail > Subscribe

4) Setup AWS permissions

5) Setup Data Inputs
       Settings > Data Inputs > CloudTrial >