1 個回答
- 最新
- 最多得票
- 最多評論
0
No, GuardDuty doesn't directly inspect AWS Firewall logs, enabling VPC flow logs in the inspection VPC can provide comprehensive monitoring without duplicating costs across all spoke VPCs. However, GuardDuty primarily analyzes CloudTrail logs, DNS logs, and VPC flow logs. In a hub-and-spoke topology, enabling VPC flow logs in the inspection VPC can provide comprehensive monitoring without duplicating costs across all spoke VPCs.
Refrence:
https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_integrations.html
