-
Notifications
You must be signed in to change notification settings - Fork 21.8k
Automate AWS log collection for Microsoft Sentinel with AWS CloudFormation #127963
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Automate AWS log collection for Microsoft Sentinel with AWS CloudFormation #127963
Conversation
|
Learn Build status updates of commit a9f7929:
|
|
If you approve the new content in this PR, the commits must be moved to the private repository for automated checks and publishing. After you move the commits, close this PR ( #label:"aq-pr-triaged" |
|
Learn Build status updates of commit 373eb33:
|
|
Learn Build status updates of commit fd49ebb:
|
|
Learn Build status updates of commit 8608c1e:
|
|
Learn Build status updates of commit 1829a89:
|
Added a guide for deploying AWS GuardDuty log collection using CloudFormation, including detailed steps for stack creation and log export configuration.
This document provides a step-by-step guide for deploying AWS CloudWatch log collection for Microsoft Sentinel using AWS CloudFormation. It includes configuration steps for Microsoft Sentinel and detailed instructions for creating the CloudFormation stack.
This document provides a step-by-step guide on deploying AWS CloudTrail log collection for Microsoft Sentinel using AWS CloudFormation. It includes configuration details for both Microsoft Sentinel and AWS CloudFormation.
|
Learn Build status updates of commit ae87157:
|
|
Learn Build status updates of commit 7dce43c:
|
fix warnings
|
Learn Build status updates of commit 051402b:
|
|
Learn Build status updates of commit c106835: 💡 Validation status: suggestionsThis comment lists only the first 25 files in the pull request. articles/sentinel/aws-cloudformation/aws-cloudformation-overview.md
articles/sentinel/aws-cloudformation/cloudtrail/aws-cloudformation-cloudtrail.md
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-1.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-14.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-15.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-16.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-17.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-2.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-3.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-4.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-5.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-6.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-7.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-8.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-9.png
articles/sentinel/aws-cloudformation/cloudwatch/aws-cloudformation-cloudwatch.md
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-1.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-10.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-11.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-2.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-3.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-4.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-5.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-6.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-7.png
This comment lists only the first 25 errors (including error/warning/suggestion) in the pull request. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
PRMerger Results
|
|
Hello Team, I hope you are all doing well. I have updated the CloudFormation onboarding articles to address all warnings reported by the OPS validator, including: Adding the missing alt-text for all images Let me know if anything else needs to be adjusted! |
|
Learn Build status updates of commit 521cecf: 💡 Validation status: suggestionsThis comment lists only the first 25 files in the pull request. articles/sentinel/aws-cloudformation/aws-cloudformation-overview.md
articles/sentinel/aws-cloudformation/cloudtrail/aws-cloudformation-cloudtrail.md
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-1.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-14.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-15.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-16.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-17.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-2.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-3.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-4.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-5.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-6.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-7.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-8.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-9.png
articles/sentinel/aws-cloudformation/cloudwatch/aws-cloudformation-cloudwatch.md
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-1.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-10.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-11.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-2.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-3.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-4.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-5.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-6.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-7.png
This comment lists only the first 25 errors (including error/warning/suggestion) in the pull request. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
PRMerger Results
|
|
@orspod This content requires automated and human checks available only in the private repository. Please close this PR ( |
Updated the AWS CloudFormation overview documentation for Microsoft Sentinel, including clarifications on OIDC roles, log types, and repository structure.
|
Learn Build status updates of commit c3c42f5: 💡 Validation status: suggestionsThis comment lists only the first 25 files in the pull request. articles/sentinel/aws-cloudformation/aws-cloudformation-overview.md
articles/sentinel/aws-cloudformation/cloudtrail/aws-cloudformation-cloudtrail.md
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-1.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-14.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-15.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-16.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-17.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-2.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-3.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-4.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-5.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-6.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-7.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-8.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-9.png
articles/sentinel/aws-cloudformation/cloudwatch/aws-cloudformation-cloudwatch.md
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-1.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-10.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-11.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-2.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-3.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-4.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-5.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-6.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-7.png
This comment lists only the first 25 errors (including error/warning/suggestion) in the pull request. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit d8a1fe7: 💡 Validation status: suggestionsThis comment lists only the first 25 files in the pull request. articles/sentinel/aws-cloudformation/aws-cloudformation-overview.md
articles/sentinel/aws-cloudformation/cloudtrail/aws-cloudformation-cloudtrail.md
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-1.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-14.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-15.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-16.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-17.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-2.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-3.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-4.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-5.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-6.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-7.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-8.png
articles/sentinel/aws-cloudformation/cloudtrail/images/cloudtrail-step-9.png
articles/sentinel/aws-cloudformation/cloudwatch/aws-cloudformation-cloudwatch.md
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-1.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-10.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-11.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-2.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-3.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-4.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-5.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-6.png
articles/sentinel/aws-cloudformation/cloudwatch/images/cloudwatch-step-7.png
This comment lists only the first 25 errors (including error/warning/suggestion) in the pull request. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
PRMerger Results
|
|
Hello Team, |
@KanenasCS - That was a comment for the author of the article, there's nothing else you need to do. @rkarlin If you approve the new content in this PR, the commits must be moved to the private repository for automated checks and publishing. After you move the commits, close this PR ( #label:"aq-pr-triaged" |
|
#reassign: @guywi-ms |
|
#assign: @EdB-MSFT |
Use AWS CloudFormation templates to deploy the AWS S3–based data connector for Microsoft Sentinel, creating the same AWS resources as the PowerShell onboarding scripts so you can collect CloudTrail, GuardDuty, VPC Flow Logs, CloudWatch, from Amazon Web Services.