CloudTrail events do not appear on Microsoft Sentinel

0

My organization is ingesting its CloudTrail logs into a Sentinel workspace. I recently updated our current LogTrail by adding S3 in the data events but when I performed some specific operations to test, like "CopyObject", they do not appear on Sentinel. We use the legacy connector and expected that we would be able to see such events

Nov
質問済み 7ヶ月前260ビュー
1回答
0

Here some ideas to dig for the root cause.

  • Make sure you update the AWS CloudTrail connector configuration in Azure Sentinel to account for these changes.
  • Ensure that S3 data events are enabled and configured in your CloudTrail settings.
  • Check if the specific "CopyObject" events are included in the CloudTrail logs you are sending to Azure Sentinel. These events might be categorized differently or may have specific attributes that need to be parsed and queried.
  • Check for any errors or issues related to log ingestion. You may need to troubleshoot and resolve any connectivity problems.
回答済み 6ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ