AWS NLB

Connecting AWS NLB logs to your Panther Console

Overview

Panther supports ingesting Amazon Web Services (AWS) Network Load Balancer (NLB) logs via AWS S3.

AWS NLB access logs only support TLS listeners. TCP and UDP listeners do not generate access logs.

How to onboard AWS NLB logs to Panther

To pull NLB logs into Panther, set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "AWS Network Load Balancer," then click its tile.

  4. In upper right-hand corner, click Start Setup.

Panther-managed detections

See Panther-managed rules for AWS in the panther-analysis GitHub repository.

Supported NLB logs

AWS.NLB

Network Load Balancer logs Layer 4 TLS connection logs for your network load balancer. For more information, see AWS's documentation on NLB access logs.

Last updated

Was this helpful?