CloudTrail events do not appear on Microsoft Sentinel

0

My organization is ingesting its CloudTrail logs into a Sentinel workspace. I recently updated our current LogTrail by adding S3 in the data events but when I performed some specific operations to test, like "CopyObject", they do not appear on Sentinel. We use the legacy connector and expected that we would be able to see such events

Nov
demandé il y a 6 mois259 vues
1 réponse
0

Here some ideas to dig for the root cause.

  • Make sure you update the AWS CloudTrail connector configuration in Azure Sentinel to account for these changes.
  • Ensure that S3 data events are enabled and configured in your CloudTrail settings.
  • Check if the specific "CopyObject" events are included in the CloudTrail logs you are sending to Azure Sentinel. These events might be categorized differently or may have specific attributes that need to be parsed and queried.
  • Check for any errors or issues related to log ingestion. You may need to troubleshoot and resolve any connectivity problems.
répondu il y a 6 mois

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions