Analyze your AWS CloudTrail logs and receive alerts about abnormal activity through integration with your connected Trend Vision One environment.
This is a “Pre-release” feature and is not considered an official release. Please review the Pre-release Disclaimer before using the feature.
The following AWS instructions and screen captures were valid as of November 15, 2022. For further help, check your AWS documentation.
Your browser automatically opens a new tab and displays the Quick create stack screen for your AWS account.
For customers with a preexisting CloudTrail instance, specify an existing CloudTrail bucket resource or a new bucket will be created for you, which may incur additional AWS costs.
For new customers without preexisting CloudTrail buckets, the first bucket is included without charge and you should leave this field empty.
After creating the stack, allow at least 15 minutes for the data collection to begin.
For example, type the following search string and click Search:
productCode:sct
After verifying that the CloudTrail data collection is working, you can start receiving alerts on any CloudTrail events that trigger a detection model in the Workbench app (XDR Threat Investigation > Workbench).