Supported services
All the services except Inspector Classic
and CloudWatch Logs
get their data from log files stored in an S3
bucket. These services store their data into log files which are configured inside <bucket type='TYPE'> </bucket>
tags, while Inspector Classic
and CloudWatch Logs
services are configured inside <service type='inspector'> </service>
and <service type='cloudwatchlogs'> </service>
tags, respectively.
New in version 4.4.2.
The <subscriber type='TYPE'> </subscriber>
tags are added in order to obtain logs from Amazon Security Lake
buckets.
The next table contains the most relevant information about configuring each service in the ossec.conf
file, as well as the path where the logs will be stored in the bucket if the corresponding service uses them as its storage medium:
Provider |
Service |
Configuration tag |
Type |
Path to logs |
Amazon |
bucket |
cloudtrail |
<bucket_name>/<prefix>/AWSLogs/<suffix>/<organization_id>/<account_id>/CloudTrail/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
vpcflow |
<bucket_name>/<prefix>/AWSLogs/<suffix>/<account_id>/vpcflowlogs/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
config |
<bucket_name>/<prefix>/AWSLogs/<suffix>/<account_id>/Config/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
alb |
<bucket_name>/<prefix>/AWSLogs/<account_id>/elasticloadbalancing/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
clb |
<bucket_name>/<prefix>/AWSLogs/<account_id>/elasticloadbalancing/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
nlb |
<bucket_name>/<prefix>/AWSLogs/<account_id>/elasticloadbalancing/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
custom |
<bucket_name>/<prefix>/<year>/<month>/<day> |
|
Amazon |
bucket |
custom |
<bucket_name>/<prefix>/<year>/<month>/<day> |
|
Amazon |
bucket |
custom |
<bucket_name>/<prefix>/<year>/<month>/<day> |
|
Amazon |
bucket |
guardduty |
<bucket_name>/<prefix>/AWSLogs/<suffix>/<account_id>/GuardDuty/<region>/<year>/<month>/<day> |
|
Amazon |
bucket |
guardduty |
<bucket_name>/<prefix>/<year>/<month>/<day>/<hh> |
|
Amazon |
bucket |
waf |
<bucket_name>/<prefix>/<year>/<month>/<day>/<hh> |
|
Amazon |
bucket |
server_access |
<bucket_name>/<prefix> |
|
Amazon |
service |
inspector |
||
Amazon |
service |
cloudwatchlogs |
||
Amazon |
service |
cloudwatchlogs |
||
Amazon |
subscriber |
security_lake |
||
Amazon |
subscriber |
buckets |
||
Cisco |
bucket |
cisco_umbrella |
<bucket_name>/<prefix>/<year>-<month>-<day> |