Send WAF logs to rSysLog (direct connection to 514 port over UDP) through Amazon Kinesis Data Firehouse

0

We are required to send WAF logs to an external server running rSysLog with several tools already set and configured for traffic analysis.

I perceived that externalization of log data streams are made with the option of using Kinesis Data Firehouse for logging in the WebACL settings.

However, when I tried to create a delivery data stream, I don't see any option for common SysLog protocol.

Is it not really possible to do that? I didn't see mention in Amazon AWS official documentation and tricks around the internet seem to be in the opposite side, from rSysLog to Kinesis services and using an intermediate software that doesn't seem to work in another way.

1개 답변
0

Hello,

There are a few documents that may be helpful in accomplishing this.

This article on setting up Kinesis Firehose as a logging destination, and this one on managing webACL logging.

Additionally, this guide walks through setting up syslog integration w/ Kinesis. That last link also outlines testing procedures, which may come in handy.

Hope that helps!

mraml
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠