Search…
⌃K

AWS S3 Bucket

Integrating Keeper SIEM push to an Amazon S3 bucket endpoint

Overview

Keeper supports event streaming into an Amazon S3 bucket. Setup instructions are below.

S3 Bucket Configuration

(1) In AWS, create an S3 bucket and of course ensure that all permissions are locked down.
(2) Create a user account without console access and assign a basic role policy which can only put files within the bucket. Example below.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"s3:PutObject"
],
"Resource": [
"arn:aws:s3:::name_of_bucket/*"
]
}
]
}
(3) Generate Access Key and Secret Key, provide those to the Admin Console user interface along with the Bucket Name. You can select different time intervals for the file uploads. You can also select the file format which includes:
  • JSON
  • Syslog
  • CSV
Files will be posted only when events occur during the interval. In the example below, the json files are posted every hour when there is activity in the system.
If you set the time frame to a "day", all events will accumulate until the day has ended (using UTC clock) and then a new file containing all day events will be added to your S3 bucket.
Last modified 1yr ago