Cloud Trail
StandardCloud Trail enables you to fetch and analyze AWS Cloud Trail logs from the Amazon S3 (Simple Storage Service) buckets. Buckets are Amazon S3’s storage units that you can create and access using your AWS account. Cloud Trial can fetch logs from either Amazon S3’s buckets or from a bucket of a third-party service that is using Amazon S3’s storage.
Release Details
Package Details
- Fetcher
- CloudTrailLogFetcher
- Compiled Normalizer
- CloudTrailCompiledNormalizer
- Report Package
- LP_CloudTrail
- Dashboard
- LP_CloudTrail
- Parser
- CloudTrailLogParser
- Alert Packages
- LP_Console Sign In Without MFA
- LP_Console Sign In Without MFA
- LP_Amazon EC2 Instance Changes
- LP_CloudTrail Root Credentials Used
- LP_CloudTrail Changes
- LP_CloudTrail API Without MFA
- LP_AWSCloudTrail Amazon S3 Bucket Activity
- LP_Amazon Virtual Private Cloud Changes
- LP_AWSCloudTrail Failed Login
- LP_CloudTrail Authorization Failures
- LP_CloudTrail Network Access Control List Changes
- LP_CloudTrail Network Gateway Changes
- LP_AWSCloudTrail Security Group Configuration Changes
- LP_CloudTrail IAM Policy Changes
- LP_AWS Cloudtrail Reconnaissance - Gathering of Host Information Detected
- LP_AWS Cloudtrail Reconnaissance - Gathering of Network Information Detected
- LP_AWS Cloudtrail Reconnaissance - Gathering of User Information Detected
- LP_AWS Cloudtrail - Creation of IAM User Detected
Enhancement
CloudTrail is now compatible with Logpoint v7.8.0.
Bug Fix
PLUG-17199
The AWS ap-southeast-5 region was missing, preventing users from fetching logs from this region.
Past Releases
Cloud Trail v6.2.1 ▾
Enhancement
CloudTrail is now compatible with Logpoint v7.8.0.
Cloud Trail v6.2.0 ▾
Enhancement
PLUG-11796
You can now configure CloudTrail from Log Sources , which provides a centralized user interface for all the configurations of log collection. Compatibility is available with Director v2.6.0, currently available as Priority Access. Contact Support for its access.
Cloud Trail v6.0.0 ▾
Enhancement
PLUG-10592
Cloud Trail is now compatible with Logpoint v7.4.2 and later.
Cloud Trail v5.2.1 ▾
Enhancement
KB-20538, KB-17560, KB-20441, KB-20674, KB-20346, KB-17696
In the CloudTrailCompiledNormalizer: Renamed the receiver_id field to account_id and the tlsDetails_clientProvidedHostHeader field to host . Users can now see whether a User Login event was successful or not through the addition of the new User label. Parsed the principal_id field with AROAYW72NODXECCZZCVNL:user@ logpoint.com value of Cloud Trail logs to assign the user value user@logpoint.com in the upn field. Parsed the JSON field by three levels deep for faster performance.
Bug Fix
KB-19073
CloudTrailCompiledNormalizer dropped account_id fields for all Failed Login events and for some Successful Login events.
Cloud Trail v5.2.0 ▾
Bug Fix
PLUG-9108
The batch processor extracted compressed log files from Cloud Trail and loaded them in memory resulting in high CPU usage and long processing time.
Cloud Trail v5.1.0 ▾
Enhancements
PLUG-615043867, 66491
Cloud Trail now supports the EU West 3 (Paris) AWS region.
PLUG-845362868
You can now specify the Base Path of the directory from where logs are fetched.
PLUG-840462181
Cloud Trail now supports the configuration of proxy servers.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.