Views:

Learn how to enable Cloud Detections for AWS CloudTrail to monitor CloudTrail logs with XDR for Cloud.

You can enable Cloud Detections for AWS CloudTrail when connecting a single AWS account to Trend Vision One. This feature is available when using CloudFormation to deploy the connection, but not when using Terraform deployments.
Note
Note
Cloud Detections for AWS CloudTrail is only available for single account deployments. It is not available when connecting an AWS organization.

Procedure

  1. Ensure AWS CloudTrail is configured for integration with Trend Vision One.
  2. Enable Cloud Detections for AWS CloudTrail when connecting an AWS account using CloudFormation.
  3. If you have already connected your AWS account, update the CloudFormation stack to enable Cloud Detections for AWS CloudTrail.
  4. Test the AWS CloudTrail integration.