Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for Custom Log in Amazon Web Services S3 Data Connector #11697

Closed
miszczu opened this issue Jan 21, 2025 · 6 comments
Closed

Support for Custom Log in Amazon Web Services S3 Data Connector #11697

miszczu opened this issue Jan 21, 2025 · 6 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@miszczu
Copy link

miszczu commented Jan 21, 2025

When running ./ConfigAwsConnector.ps1 script it is possible to create a configuration for custom AWS logs:

To begin you will choose the AWS logs to configure.

Please enter the AWS log type to configure (VPC, CloudTrail, GuardDuty, CloudWatch, CustomLog): CustomLog

The script executes successfully, creating the relevant SQS queue and outputting settings for the Amazon Web Services (AWS) S3 data connector:

Use the values below to configure the Amazon Web Service S3 data connector in the Azure Sentinel portal.

Role Arn: arn:aws:iam::***:role/***
Sqs Url: https://sqs.***.amazonaws.com/***/***

However, when attempting to configure the data connector in Microsoft Sentinel, there is no option available for "CustomLog."

Image

Question:
How can I connect Microsoft Sentinel to AWS custom log data? The available documentation seems to lack guidance for this specific scenario.

@v-sudkharat v-sudkharat self-assigned this Jan 22, 2025
@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label Jan 22, 2025
@v-sudkharat
Copy link
Contributor

Hi @miszczu, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @miszczu,

Sorry for the delayed response.

We had a discussion with the concerned team regarding this issue. The custom logs for the Data Connector blade are currently in private preview. The team is planning to make it GA, but at the moment, we can't provide an exact ETA.

However, since you have reached out, we can share some steps that will help you access those custom logs in the Data Connector, which is still in private preview.
Kindly share your contact email with us so we can reach out to you.

Please note: The connector is still in private preview and may not be supported by the team in case of any issues or consequences that arise.

Closing this issue from GitHub. If you still need support for this issue, feel free to re-open it any time. Thank you for your co-operation.

@miszczu
Copy link
Author

miszczu commented Feb 6, 2025

Hi @v-sudkharat,

please share the steps for setting this up to following email address: <redacted>

@v-sudkharat
Copy link
Contributor

@miszczu, Unable to send steps in your shared mail id, due to org compliance, kindly, share another id.

@miszczu
Copy link
Author

miszczu commented Feb 7, 2025

@v-sudkharat Oh right, please use following address in that case: <redacted>

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

2 participants