Network Firewall logs unusable

0

Hi, we are looking at Network Firewall logs but they are almost unusable, as it logs every packet and not sessions. Is it possible to define some 'alert' rule or run a query to "group" logs of same session?

1回答
1

If you are sending network firewall logs to CloudWatch Logs, you can use Amazon Athena to query the logs. Athena lets you use SQL type queries over CloudWatch logs in S3.

Here is a link to some more details on using Athena with network firewall logs: https://docs.aws.amazon.com/athena/latest/ug/querying-network-firewall-logs.html

For even more analysis, you can also use Contributor Insights or CloudWatch Insights to get metrics on common events and themes in your logs:

https://aws.amazon.com/blogs/mt/use-contributor-insights-to-analyze-aws-network-firewall/ https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AnalyzingLogData.html

AWS
axa
回答済み 2年前
AWS
エキスパート
Hernito
レビュー済み 2年前
  • Creating custom dashboards and metrics is really a madness! Especially at enterprise level, coming from advanced tools like Checkpoint firewall or Imperva WAF, this is like goiing back to stone age!

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ