SIEM
● Security Information and Event Management
● 多種多様なログを一元管理
● 各種ログを横断して分析
SIEM
VPC flow log
Cloudfront
ALB
WAF
IPS
Application
Slide 8
Slide 8 text
SIEM on AWS OpenSearch Service
● OpenSearchを使ったSIEMソリューション
● https://github.com/aws-samples/siem-on-amazon-opensearch-service
● S3 bucketなどに入れたログをAWS LambdaでOpenSearchに格納
Slide 9
Slide 9 text
SIEM on AWS OpenSearch Service
● OpenSearch Dashboardで一覧できる
https://opensearch.org/docs/2.4/dashboards/discover/index-discover/
Slide 10
Slide 10 text
SIEM on AWS OpenSearch Service
● OpenSearch Dashboardで一覧できる
https://github.com/aws-samples/siem-on-amazon-opensearch-service/blob/main/docs/images/dashboard-awswaf.jpg