AWS ALB

Connecting AWS ALB logs to your Panther Console

Overview

Panther supports ingesting Amazon Web Services (AWS) Application Load Balancer (ALB) logs via AWS S3.

How to onboard AWS ALB logs to Panther

To pull ALB logs into Panther, set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "AWS Application Load Balancer," then click its tile.

  4. In the slide-out panel, click Start Setup.

Panther-managed detections

See Panther-managed rules for AWS in the panther-analysis GitHub repository.

Supported ALB logs

AWS.ALB

Application Load Balancer logs layer 7 network logs for your application load balancer. For more information, see AWS's documentation on ALB access logs.

Last updated

Was this helpful?