cisagov / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://cisagov.github.io/Malcolm/
Other
1.97k stars 331 forks source link

Support and document receiving cloud logs #468

Open mmguero opened 2 weeks ago

mmguero commented 2 weeks ago

@mmguero cloned issue idaholab/Malcolm#232 on 2023-08-01:

Support and documentation for setting up forwarding cloud logs to Malcolm, possibly such as:

  • AWS platform

    • VPC flow logs (somewhat related to #175)

    • CloudFront access logs

    • ELB logs

    • S3 Bucket Logs

    • Route 53 query logs

    • Amazon RDS logs

  • Azure

    • ?

On the Malcolm side this would preferably use the same plumbing as forwarding other third-party logs to Malcolm.