1 Answer
- Newest
- Most votes
- Most comments
0
No, GuardDuty doesn't directly inspect AWS Firewall logs, enabling VPC flow logs in the inspection VPC can provide comprehensive monitoring without duplicating costs across all spoke VPCs. However, GuardDuty primarily analyzes CloudTrail logs, DNS logs, and VPC flow logs. In a hub-and-spoke topology, enabling VPC flow logs in the inspection VPC can provide comprehensive monitoring without duplicating costs across all spoke VPCs.
Refrence:
https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_integrations.html
answered a month ago
Relevant content
- asked 7 months ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 9 months ago
- AWS OFFICIALUpdated 2 years ago