InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Livin' the Stream with Your Amazon Security Lake

Presented by

Scott Schwartz, Software Engineering Senior Manager at Siemens & Pedro Borges, Senior Security Engineer at Siemens

About this talk

Amazon Security Lake is a great service that makes the collection and centralization of critical AWS infrastructure logs simple and easy. However, getting the logs out of Amazon Security Lake and into your SIEM can be tricky and potentially very costly. In this talk, we will go over our approach to using Cribl Stream to get logs out of Amazon Security Lake for our 800+ AWS accounts, and how we went about configuring the various relevant pipelines to reduce, transform and aggregate events to achieve a 90%+ log reduction. This includes AWS WAF logs, Route53 DNS query logs, VPC flow logs, and CloudTrail S3 data events. We'll go over some of the technical details on how we achieved this as well as some lessons learned we picked up along the way.
Cribl

Cribl

26019 subscribers198 talks
Cribl is the Data Engine for IT and Security
Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl to analyze, collect, process, and route all IT and security data, delivering the choice, control, and flexibility required to adapt to their ever-changing needs. Interested in seeing first-hand how Cribl can support your use case? Sign up for Cribl.Cloud and process up to 1TB/day, for free! https://cribl.io/cribl-cloud/try-cribl-cloud/
Related topics