AWS VPN monitor

0

so far my company uses the aws client vpn, which is authenticated through the google workspace saml. the user's vpn access is authenticated by his/her google mail, is anyway I can track the user's behavior, like which aws resource he/she access or modified? is any software or service i can levelrage?

I appreciate you thoughts.

已提問 2 年前檢視次數 297 次
1 個回答
0

Good day.

Have you already looked into CloudTrail events? https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/monitoring-cloudtrail.html

"When activity occurs in Client VPN, that activity is recorded in a CloudTrail event along with other AWS service events in Event history."

Remember that CloudTrail only supports 90 days in the dashboard by default, and if you need to retain a longer period then you should look into CloudTrail Trails (https://docs.aws.amazon.com/awscloudtrail/latest/userguide/view-cloudtrail-events.html) or integrate CloudTrail with your SIEM solution.

I hope this helps!

Jason H.

AWS
Jason_H
已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南