Submit Search
Upload
Strengthen Operations with AWS CloudTrail and Splunk
•
4 likes
•
2,128 views
AI-enhanced title
Alan Williams
Follow
How we use Splunk and CloudTrail to gain deeper insights into our AWS accounts
Read less
Read more
Software
Report
Share
Report
Share
1 of 22
Recommended
DevTalks 2021 Cloud Engineering @Crowdstrike
DevTalks 2021 Cloud Engineering @Crowdstrike
Cosmin Bratu
Splunk Architecture overview
Splunk Architecture overview
Alex Fok
AWS Partner Webcast - Use Your AWS CloudTrail Data and Splunk Software To Imp...
AWS Partner Webcast - Use Your AWS CloudTrail Data and Splunk Software To Imp...
Amazon Web Services
Getting Data into Splunk
Getting Data into Splunk
Splunk
SplunkLive! Splunk for Security
SplunkLive! Splunk for Security
Splunk
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
Amazon Web Services
Splunk Overview
Splunk Overview
Splunk
Splunk for ITOps
Splunk for ITOps
Splunk
Recommended
DevTalks 2021 Cloud Engineering @Crowdstrike
DevTalks 2021 Cloud Engineering @Crowdstrike
Cosmin Bratu
Splunk Architecture overview
Splunk Architecture overview
Alex Fok
AWS Partner Webcast - Use Your AWS CloudTrail Data and Splunk Software To Imp...
AWS Partner Webcast - Use Your AWS CloudTrail Data and Splunk Software To Imp...
Amazon Web Services
Getting Data into Splunk
Getting Data into Splunk
Splunk
SplunkLive! Splunk for Security
SplunkLive! Splunk for Security
Splunk
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
Amazon Web Services
Splunk Overview
Splunk Overview
Splunk
Splunk for ITOps
Splunk for ITOps
Splunk
Getting started with Splunk - Break out Session
Getting started with Splunk - Break out Session
Georg Knon
Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On)
Splunk
Splunk for IT Operations
Splunk for IT Operations
Splunk
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
Splunk
Analytics Driven SIEM Workshop
Analytics Driven SIEM Workshop
Splunk
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
Splunk
Leveraging Splunk Enterprise Security with the MITRE’s ATT&CK Framework
Leveraging Splunk Enterprise Security with the MITRE’s ATT&CK Framework
Splunk
게임의 성공을 위한 Scalable 한 데이터 플랫폼 사례 공유 - 오승용, 데이터 플랫폼 리더, 데브시스터즈 ::: Games on AW...
게임의 성공을 위한 Scalable 한 데이터 플랫폼 사례 공유 - 오승용, 데이터 플랫폼 리더, 데브시스터즈 ::: Games on AW...
Amazon Web Services Korea
Best Practices for Forwarder Hierarchies
Best Practices for Forwarder Hierarchies
Splunk
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Amazon Web Services
Splunk Tutorial for Beginners - What is Splunk | Edureka
Splunk Tutorial for Beginners - What is Splunk | Edureka
Edureka!
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
Splunk
Splunk for Enterprise Security and User Behavior Analytics
Splunk for Enterprise Security and User Behavior Analytics
Splunk
Splunk Cloud
Splunk Cloud
Splunk
Splunk Live - Security Best Practices for AWS
Splunk Live - Security Best Practices for AWS
Amazon Web Services
오토스케일링 제대로 활용하기 (김일호) - AWS 웨비나 시리즈 2015
오토스케일링 제대로 활용하기 (김일호) - AWS 웨비나 시리즈 2015
Amazon Web Services Korea
Splunk 101
Splunk 101
Splunk
Security Automation & Orchestration
Security Automation & Orchestration
Splunk
Splunk-Presentation
Splunk-Presentation
PrasadThorat23
Big Data - in the cloud or rather on-premises?
Big Data - in the cloud or rather on-premises?
Guido Schmutz
How Autodesk Leverages Splunk as an Assurance Platform on AWS
How Autodesk Leverages Splunk as an Assurance Platform on AWS
Alan Williams
AWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWS
Splunk
More Related Content
What's hot
Getting started with Splunk - Break out Session
Getting started with Splunk - Break out Session
Georg Knon
Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On)
Splunk
Splunk for IT Operations
Splunk for IT Operations
Splunk
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
Splunk
Analytics Driven SIEM Workshop
Analytics Driven SIEM Workshop
Splunk
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
Splunk
Leveraging Splunk Enterprise Security with the MITRE’s ATT&CK Framework
Leveraging Splunk Enterprise Security with the MITRE’s ATT&CK Framework
Splunk
게임의 성공을 위한 Scalable 한 데이터 플랫폼 사례 공유 - 오승용, 데이터 플랫폼 리더, 데브시스터즈 ::: Games on AW...
게임의 성공을 위한 Scalable 한 데이터 플랫폼 사례 공유 - 오승용, 데이터 플랫폼 리더, 데브시스터즈 ::: Games on AW...
Amazon Web Services Korea
Best Practices for Forwarder Hierarchies
Best Practices for Forwarder Hierarchies
Splunk
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Amazon Web Services
Splunk Tutorial for Beginners - What is Splunk | Edureka
Splunk Tutorial for Beginners - What is Splunk | Edureka
Edureka!
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
Splunk
Splunk for Enterprise Security and User Behavior Analytics
Splunk for Enterprise Security and User Behavior Analytics
Splunk
Splunk Cloud
Splunk Cloud
Splunk
Splunk Live - Security Best Practices for AWS
Splunk Live - Security Best Practices for AWS
Amazon Web Services
오토스케일링 제대로 활용하기 (김일호) - AWS 웨비나 시리즈 2015
오토스케일링 제대로 활용하기 (김일호) - AWS 웨비나 시리즈 2015
Amazon Web Services Korea
Splunk 101
Splunk 101
Splunk
Security Automation & Orchestration
Security Automation & Orchestration
Splunk
Splunk-Presentation
Splunk-Presentation
PrasadThorat23
Big Data - in the cloud or rather on-premises?
Big Data - in the cloud or rather on-premises?
Guido Schmutz
What's hot
(20)
Getting started with Splunk - Break out Session
Getting started with Splunk - Break out Session
Getting Started with Splunk (Hands-On)
Getting Started with Splunk (Hands-On)
Splunk for IT Operations
Splunk for IT Operations
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
Analytics Driven SIEM Workshop
Analytics Driven SIEM Workshop
Splunk Cloud and Splunk Enterprise 7.2
Splunk Cloud and Splunk Enterprise 7.2
Leveraging Splunk Enterprise Security with the MITRE’s ATT&CK Framework
Leveraging Splunk Enterprise Security with the MITRE’s ATT&CK Framework
게임의 성공을 위한 Scalable 한 데이터 플랫폼 사례 공유 - 오승용, 데이터 플랫폼 리더, 데브시스터즈 ::: Games on AW...
게임의 성공을 위한 Scalable 한 데이터 플랫폼 사례 공유 - 오승용, 데이터 플랫폼 리더, 데브시스터즈 ::: Games on AW...
Best Practices for Forwarder Hierarchies
Best Practices for Forwarder Hierarchies
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Session Sponsored by Splunk: Splunk for the Cloud, in the Cloud
Splunk Tutorial for Beginners - What is Splunk | Edureka
Splunk Tutorial for Beginners - What is Splunk | Edureka
Worst Splunk practices...and how to fix them
Worst Splunk practices...and how to fix them
Splunk for Enterprise Security and User Behavior Analytics
Splunk for Enterprise Security and User Behavior Analytics
Splunk Cloud
Splunk Cloud
Splunk Live - Security Best Practices for AWS
Splunk Live - Security Best Practices for AWS
오토스케일링 제대로 활용하기 (김일호) - AWS 웨비나 시리즈 2015
오토스케일링 제대로 활용하기 (김일호) - AWS 웨비나 시리즈 2015
Splunk 101
Splunk 101
Security Automation & Orchestration
Security Automation & Orchestration
Splunk-Presentation
Splunk-Presentation
Big Data - in the cloud or rather on-premises?
Big Data - in the cloud or rather on-premises?
Viewers also liked
How Autodesk Leverages Splunk as an Assurance Platform on AWS
How Autodesk Leverages Splunk as an Assurance Platform on AWS
Alan Williams
AWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWS
Splunk
Running Splunk on AWS
Running Splunk on AWS
Alan Williams
December 2013 HUG: Hunk - Splunk over Hadoop
December 2013 HUG: Hunk - Splunk over Hadoop
Yahoo Developer Network
Logstash
Logstash
Rajgourav Jain
AWS Storage Tiering for Enterprise Workloads
AWS Storage Tiering for Enterprise Workloads
Tom Laszewski
What's better than Microservices? Serverless Microservices
What's better than Microservices? Serverless Microservices
Alan Williams
Monitoring Performance of Enterprise Applications on AWS: Understanding the D...
Monitoring Performance of Enterprise Applications on AWS: Understanding the D...
Amazon Web Services
Transparency and Control with AWS CloudTrail and AWS Config
Transparency and Control with AWS CloudTrail and AWS Config
Amazon Web Services
AWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design Patterns
Amazon Web Services
Viewers also liked
(10)
How Autodesk Leverages Splunk as an Assurance Platform on AWS
How Autodesk Leverages Splunk as an Assurance Platform on AWS
AWS on Splunk, Splunk on AWS
AWS on Splunk, Splunk on AWS
Running Splunk on AWS
Running Splunk on AWS
December 2013 HUG: Hunk - Splunk over Hadoop
December 2013 HUG: Hunk - Splunk over Hadoop
Logstash
Logstash
AWS Storage Tiering for Enterprise Workloads
AWS Storage Tiering for Enterprise Workloads
What's better than Microservices? Serverless Microservices
What's better than Microservices? Serverless Microservices
Monitoring Performance of Enterprise Applications on AWS: Understanding the D...
Monitoring Performance of Enterprise Applications on AWS: Understanding the D...
Transparency and Control with AWS CloudTrail and AWS Config
Transparency and Control with AWS CloudTrail and AWS Config
AWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design Patterns
Similar to Strengthen Operations with AWS CloudTrail and Splunk
AWS Webcast - Splunk and Autodesk
AWS Webcast - Splunk and Autodesk
Amazon Web Services
(ENT212) How Autodesk Leverages Splunk as an Assurance Platform on AWS | AWS ...
(ENT212) How Autodesk Leverages Splunk as an Assurance Platform on AWS | AWS ...
Amazon Web Services
AWS Dublin User Group: 2016-03-23
AWS Dublin User Group: 2016-03-23
Brian Murray
PCF: Platform for a New Era - Kubernetes for the Enterprise - London
PCF: Platform for a New Era - Kubernetes for the Enterprise - London
VMware Tanzu
Introducing Cloudera Director at Big Data Bash
Introducing Cloudera Director at Big Data Bash
Andrei Savu
How Hudl and Cloud Cruiser Leverage Sumo Logic's Unified Logs and Metrics
How Hudl and Cloud Cruiser Leverage Sumo Logic's Unified Logs and Metrics
Sumo Logic
AWSome Day, Milan | 5 Marzo 2015 - Opening Keynote (Nicola Previati - Italy T...
AWSome Day, Milan | 5 Marzo 2015 - Opening Keynote (Nicola Previati - Italy T...
lanfranf
Webinar aws 101 a walk through the aws cloud- introduction to cloud computi...
Webinar aws 101 a walk through the aws cloud- introduction to cloud computi...
Amazon Web Services
What is Vultr Used for?
What is Vultr Used for?
Home
Cloud Builders Meetup - Containers @ Autodesk
Cloud Builders Meetup - Containers @ Autodesk
Stephen Voorhees
Get connected with Azure Logic Apps & Flow
Get connected with Azure Logic Apps & Flow
Dynamics 365 Customer Engagement Professionals Netherlands (CEProNL)
AWS Dev Tips: Learn from the experts
AWS Dev Tips: Learn from the experts
CeciliaTimm2
Business Agility: Taking an App Global (at Speed) - Session Sponsored by ITOC
Business Agility: Taking an App Global (at Speed) - Session Sponsored by ITOC
Amazon Web Services
Dockerizing apps for the Deployment Platform of the Month with OSGi - David B...
Dockerizing apps for the Deployment Platform of the Month with OSGi - David B...
mfrancis
DevCamp - What can the cloud do for me
DevCamp - What can the cloud do for me
Chris Dufour
Strumenti e servizi basici per sviluppatori, come iniziare a creare sul cloud...
Strumenti e servizi basici per sviluppatori, come iniziare a creare sul cloud...
Amazon Web Services
Introduction to DevSecOps on AWS
Introduction to DevSecOps on AWS
Amazon Web Services
vBrownBag AWS Certified SysOps : Associate Domain 4
vBrownBag AWS Certified SysOps : Associate Domain 4
Eric Santelices
Developing applications on AWS with .NET core - AWS Cape Town Summit 2018
Developing applications on AWS with .NET core - AWS Cape Town Summit 2018
Amazon Web Services
Capture the Cloud with Azure
Capture the Cloud with Azure
Shahed Chowdhuri
Similar to Strengthen Operations with AWS CloudTrail and Splunk
(20)
AWS Webcast - Splunk and Autodesk
AWS Webcast - Splunk and Autodesk
(ENT212) How Autodesk Leverages Splunk as an Assurance Platform on AWS | AWS ...
(ENT212) How Autodesk Leverages Splunk as an Assurance Platform on AWS | AWS ...
AWS Dublin User Group: 2016-03-23
AWS Dublin User Group: 2016-03-23
PCF: Platform for a New Era - Kubernetes for the Enterprise - London
PCF: Platform for a New Era - Kubernetes for the Enterprise - London
Introducing Cloudera Director at Big Data Bash
Introducing Cloudera Director at Big Data Bash
How Hudl and Cloud Cruiser Leverage Sumo Logic's Unified Logs and Metrics
How Hudl and Cloud Cruiser Leverage Sumo Logic's Unified Logs and Metrics
AWSome Day, Milan | 5 Marzo 2015 - Opening Keynote (Nicola Previati - Italy T...
AWSome Day, Milan | 5 Marzo 2015 - Opening Keynote (Nicola Previati - Italy T...
Webinar aws 101 a walk through the aws cloud- introduction to cloud computi...
Webinar aws 101 a walk through the aws cloud- introduction to cloud computi...
What is Vultr Used for?
What is Vultr Used for?
Cloud Builders Meetup - Containers @ Autodesk
Cloud Builders Meetup - Containers @ Autodesk
Get connected with Azure Logic Apps & Flow
Get connected with Azure Logic Apps & Flow
AWS Dev Tips: Learn from the experts
AWS Dev Tips: Learn from the experts
Business Agility: Taking an App Global (at Speed) - Session Sponsored by ITOC
Business Agility: Taking an App Global (at Speed) - Session Sponsored by ITOC
Dockerizing apps for the Deployment Platform of the Month with OSGi - David B...
Dockerizing apps for the Deployment Platform of the Month with OSGi - David B...
DevCamp - What can the cloud do for me
DevCamp - What can the cloud do for me
Strumenti e servizi basici per sviluppatori, come iniziare a creare sul cloud...
Strumenti e servizi basici per sviluppatori, come iniziare a creare sul cloud...
Introduction to DevSecOps on AWS
Introduction to DevSecOps on AWS
vBrownBag AWS Certified SysOps : Associate Domain 4
vBrownBag AWS Certified SysOps : Associate Domain 4
Developing applications on AWS with .NET core - AWS Cape Town Summit 2018
Developing applications on AWS with .NET core - AWS Cape Town Summit 2018
Capture the Cloud with Azure
Capture the Cloud with Azure
Recently uploaded
chapter--4-software-project-planning.ppt
chapter--4-software-project-planning.ppt
kotipi9215
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
Tier1 app
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Christina Lin
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
BradBedford3
Cloud Management Software Platforms: OpenStack
Cloud Management Software Platforms: OpenStack
VICTOR MAESTRE RAMIREZ
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024
Andreas Granig
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)
OPEN KNOWLEDGE GmbH
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽❤️🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽❤️🧑🏻 89...
gurkirankumar98700
Cloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEE
VICTOR MAESTRE RAMIREZ
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
StefanoLambiase
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Ahmed Mohamed
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
soniya singh
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a series
Philip Schwarz
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
Professional Resume Template for Software Developers
Professional Resume Template for Software Developers
Vinodh Ram
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
Christina Lin
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalm
Sujith Sukumaran
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need It
Wave PLM
MYjobs Presentation Django-based project
MYjobs Presentation Django-based project
AnoyGreter
Recently uploaded
(20)
chapter--4-software-project-planning.ppt
chapter--4-software-project-planning.ppt
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Cloud Management Software Platforms: OpenStack
Cloud Management Software Platforms: OpenStack
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024
Der Spagat zwischen BIAS und FAIRNESS (2024)
Der Spagat zwischen BIAS und FAIRNESS (2024)
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽❤️🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽❤️🧑🏻 89...
Cloud Data Center Network Construction - IEEE
Cloud Data Center Network Construction - IEEE
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a series
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Professional Resume Template for Software Developers
Professional Resume Template for Software Developers
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
ODSC - Batch to Stream workshop - integration of Apache Spark, Cassandra, Pos...
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalm
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need It
MYjobs Presentation Django-based project
MYjobs Presentation Django-based project
Strengthen Operations with AWS CloudTrail and Splunk
1.
AWS/Splunk Big Data
Webinar 10/16/2014 Strengthening Operations with Splunk and AWS CloudTrail Alan Williams Principal Engineer alanwill on Twitter & GitHub © 2014 Autodesk
2.
Who Am I?
Engineer @ Autodesk Technology Generalist Background in Infrastructure AWS for ~4 years Splunk for ~1 year Motorcyclist Soft spot for pit bulls © 2014 Autodesk
3.
Who is Autodesk?
Leader in 3D design, engineering and entertainment software Introduced AutoCAD in 1982 Empowering the Maker movement Help our customers imagine, design and create a better world http://www.autodesk.com/products/personal-design-and-creativity © 2014 Autodesk
4.
Problem How
do we know what’s happening in our accounts? Malicious activity? How can we validate that we’re compliant? © 2014 Autodesk
5.
© 2014 Autodesk
6.
© 2014 Autodesk
+
7.
Why CloudTrail?
Logs AWS API calls © 2014 Autodesk Visibility and analytics AWS native Simple to configure Point and click (most parts automatable) Covers almost all AWS services New coverage added regularly (http://goo.gl/jf9uLq) Available in all 8 regions (http://goo.gl/ojU7ut)
8.
Why Splunk?
Leverage existing investment © 2014 Autodesk Standard log aggregation platform Splunk App for AWS (http://goo.gl/Xc7XsZ) Familiar technology Logging = Splunk Supports logging REST endpoints SQS & S3 Single view across all accounts
9.
CloudTrail + Splunk
Architecture Account A Account B © 2014 Autodesk 3 3 SNS Topic 1 1 SQS Queue CloudTrail S3 Bucket CloudTrail SNS Topic 2 2 4 4 5 Core Services Account Simple to configure Scalable to many accounts Central logging view across all accounts
10.
CloudTrail Use Cases
Incident Response Operations Troubleshooting Compliance Auditing © 2014 Autodesk
11.
Incident Response
Something happened in Account X between a certain time window Has this compromised host made any API calls? Where have these IAM keys been used? © 2014 Autodesk
12.
Something happened in
Account X between a certain time window © 2014 Autodesk
13.
Has this compromised
host made any API calls? © 2014 Autodesk
14.
Where have these
IAM keys been used? © 2014 Autodesk
15.
Operations Troubleshooting
Who created this instance? Where in the world are sign-ins originating? © 2014 Autodesk
16.
Who created this
instance? © 2014 Autodesk
17.
Where in the
world are sign-ins originating? © 2014 Autodesk
18.
Compliance Auditing
Alert if an SG rule is created with 0.0.0.0/0 rule Frequency of certain events Alert whenever an IAM user is created © 2014 Autodesk
19.
Alert if an
SG rule is created with 0.0.0.0/0 rule © 2014 Autodesk
20.
Alert whenever an
IAM user is created © 2014 Autodesk
21.
Summary AWS
CloudTrail + Splunk = Happy Marriage Scalable to 100s of accounts Toolset for Operations and Security Teams Our common use cases with examples © 2014 Autodesk
22.
Autodesk is a
registered trademark of Autodesk, Inc., and/or its subsidiaries and/or affiliates in the USA and/or other countries. All other brand names, product names, or trademarks belong to their respective holders. Autodesk reserves the right to alter product and services offerings, and specifications and pricing at any time without notice, and is not responsible for typographical or graphical errors that may appear in this document. © 2014 Autodesk. All rights reserved. @alanwill alanwill