Integrations
AWS CloudTrail
CloudTrail needs no integration of its own. Send the trail to CloudWatch Logs, turn the events you care about into a CloudWatch alarm with a metric filter, and send the alarm to EvoHub through the AWS CloudWatch integration. The alert resolves when the alarm returns to OK.
Set it up
Create a CloudWatch integration
In EvoHub, add an AWS CloudWatch integration and subscribe its webhook URL to an SNS topic (HTTPS, raw message delivery off), as described in AWS CloudWatch.
Send the trail to CloudWatch Logs
In the CloudTrail console, edit the trail and turn on CloudWatch Logs, choosing a log group.
Example filters
Root user sign-in or API use:
{ $.userIdentity.type = "Root" && $.userIdentity.invokedBy NOT EXISTS && $.eventType != "AwsServiceEvent" }
Logging stopped or the trail changed:
{ ($.eventName = StopLogging) || ($.eventName = DeleteTrail) || ($.eventName = UpdateTrail) }
The alert title is the alarm name, so name each alarm after what it watches.
Related
Was this page helpful?
