Test the Cloud Detections for AWS CloudTrail integration in your AWS cloud environment.
Cloud Detections for AWS CloudTrail integration allows Trend Vision One to access and monitor your AWS CloudTrail logs and automate response actions to detected
threats. The following steps provide a guide on how to test the feature within your
environment.
Procedure
- Sign in to the AWS account you want to use to test Cloud Detections for AWS CloudTrail.
- Configure your CloudTrail settings.For full steps, see Configure AWS CloudTrail settings.
- Add your AWS account to Trend Vision One cloud accounts app.Follow the steps in Connect an AWS account using CloudFormation and enable the following features and permissions:
-
Core Features
-
Cloud Detections for AWS CloudTrail
-
Cloud Response for AWS

Note
If you want to test integration with Control Tower, see Connect an AWS account with CloudTrail and Control Tower. -
- After your account successfully connects, use XDR Data Explorer to verify data is being sent.
- Use one of the following demo models to trigger a Workbench alert.

Important
Make sure to use an IAM user in AWS when using a demo model to enable testing the Revoke Access Permission response task. - Test response capabilities with the Revoke Access Permission task.
