Connect your AWS Log Archive account with AWS CloudTrail and Control Tower configured to allow Trend Vision One to provide security for your multi-account AWS environment.
Adding an AWS Log Archive account to the Cloud Accounts app allows Trend Vision One to access
your cloud service to provide security and visibility into your cloud assets across
multiple
accounts. Some Cloud Account features have limited support for AWS regions. For more
information, see AWS supported regions and
limitations.
ImportantThe Cloud Accounts app currently only supports connecting Log Archive accounts using
the CloudFormation stack template.
The steps are valid for the AWS console as of April 2024.
|
Procedure
- Sign in to the Trend Vision One console.
- In a separate browser tab, sign into your AWS Log Archive account.
- In the Trend Vision One console, go to .
- Click Add Account.The Add AWS Account window appears.
- Specify the Deployment Type.
- For Deployment Method, select CloudFormation.
- For account type, select Single AWS Account.
- Click Next.
- Specify the general information for the account.
- Specify the Account name to display in the Cloud Accounts app.
- Add a Description to display in Cloud Accounts.
- Select the AWS region for CloudFormation template
deployment.
Note
The default region is based on your Trend Vision One region.Some features and permissions have limited support for some AWS regions. For more information, see AWS supported regions and limitations. - If you have more than one Server & Workload Protection Manager instance, select the
instance to associate with the connected account.
Note
-
If you only have one Server & Workload Protection Manager instance, the account is automatically associated with that instance.
-
- To add custom tags to the resources deployed by Trend Vision One, select Resource tagging and specify the key-value pairs.Click Create a new tag to add up to three tags.
Note
-
Keys can be up to 128 characters long, and cannot start with
aws
. -
Values can be up to 256 characters long.
-
- Click Next.
- Configure the Features and Permissions for your Log Account.
- Enable XDR for Cloud - AWS CloudTrail.
- Expand XDR for Cloud - AWS CloudTrail and then enable Control Tower deployment.
- Click Next.
- Launch the CloudFormation template in the AWS
console.
- If you want to review the stack template before launching, click Download and Review Template.
- Click Launch Stack.
Your AWS Log Archive account opens to the CloudFormation service on the Quick create stack screen. - Scroll down to Parameters and locate the section labeled
These are the parameters required to enable service cloud audit log monitoring
control tower.
Important
-
The monitored CloudTrail and CloudTrail SNS must be on the same account and located in the same region you selected for the template deployment.
-
Do not change any other settings in the Parameters section. CloudFormation automatically provides the settings for the parameters. Changing parameters might cause stack creation to fail.
-
- Specify the first parameter (CloudAuditLogMonitoringCloudTrailArn).
This is the ARN of the CloudTrail you want to monitor.
- Open the CloudTrail service.
- On the Trails screen, locate the following trail: aws-controltower-BaselineCloudTrail
- Copy the ARN.
- Make a note of the "Trail log location". You will need this information in the following step.
- In your Log Archive account, paste the ARN into the CloudAuditLogMonitoringCloudTrailArn field.
- Specify the third parameter
(CloudAuditLogMonitoringCloudTrailS3Arn). This is the ARN for the
CloudTrail S3 bucket.
- Open the S3 Bucket service.
- Under General purpose buckets, select the aws-controltower-logs S3 bucket with a number and region matching the "Trail log location" from the previous step.
- Go to the Properties tab.
- Scroll down to the Amazon EventBridge section and ensure that Send notifications to Amazon EventBridge for all events in this bucket is turned on. If not, click Edit to turn on the setting.
- Scroll up to the Bucket overview section and copy the bucket ARN.
- On the CloudFormation screen, paste the ARN into the CloudAuditLogMonitoringCloudTrailS3Arn field.
- Create an Amazon SNS topic.
- In your Log Archive account, open the Simple Notification Service.
- Go to Topics and click Create topic.
- Select Standard.
- Type a name for the topic.
- Leaving the remaining settings default, click Create topic.
- Create an EventBridge.
- In your Log Archive account, open the Amazon EventBridge service.
- Go to .
- Click Create rule.
- Type a name for the rule.
- Leaving the remaining settings default, click Next.
- Under Creation method, select Use pattern form.
- In the Event pattern section, for Event source, select AWS service.
- For AWS service, select Simple Storage Service (S3).
- For Event type, select Amazon S3 Event Notification.
- For Event type specification 1, select Any event.
- For Event type specification 2, select Specify bucket(s) by name.
- Go to CloudFormation and copy the S3 name from the
CloudAuditLogMonitoringCloudTrailS3Arn field.The S3 name is everything following the three colons (:::) in the ARN.
- Return to Simple Name Service and paste the S3 name in the Specify bucket(s) by name field.
- Click Next.
- On the Select target(s) screen, select AWS service.
- Under Select a target, select SNS topic
- Under Topic, select the SNS topic using the name you specified.
- Click Next.
- On the Configure tags - optional screen, click Next.
- On the Review and create screen, click Create rule.
- Copy the ARN.
- Specify the second parameter
(CloudAuditLogMonitoringCloudTrailSNSTopicArn). This is ARN of the
CloudTrail SNS topic.
- Paste the ARN you just copied into the CloudAuditLogMonitoringCloudTrailS3Arn field.
- In the Capabilities
section, select the following acknowledgments:
-
I acknowledge that AWS CloudFormation might create IAM resources with custom names.
-
I acknowledge that AWS CloudFormation might require the following capability: CAPABILITY_AUTO_EXPAND.
-
- Click Create Stack.The Stack details screen for the new stack appears with the Events tab displayed. Creation might take a few minutes. Click Refresh to check the progress.
- In the Trend Vision One console, click Done.The account appears in Cloud Accounts once the CloudFormation template deployment successfully completes. Refresh the screen to update the table.