Network Firewall logs unusable

0

Hi, we are looking at Network Firewall logs but they are almost unusable, as it logs every packet and not sessions. Is it possible to define some 'alert' rule or run a query to "group" logs of same session?

mimmus
질문됨 2년 전950회 조회
1개 답변
1

If you are sending network firewall logs to CloudWatch Logs, you can use Amazon Athena to query the logs. Athena lets you use SQL type queries over CloudWatch logs in S3.

Here is a link to some more details on using Athena with network firewall logs: https://docs.aws.amazon.com/athena/latest/ug/querying-network-firewall-logs.html

For even more analysis, you can also use Contributor Insights or CloudWatch Insights to get metrics on common events and themes in your logs:

https://aws.amazon.com/blogs/mt/use-contributor-insights-to-analyze-aws-network-firewall/ https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AnalyzingLogData.html

AWS
axa
답변함 2년 전
AWS
전문가
Hernito
검토됨 2년 전
  • Creating custom dashboards and metrics is really a madness! Especially at enterprise level, coming from advanced tools like Checkpoint firewall or Imperva WAF, this is like goiing back to stone age!

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠