AWS NLB

Connecting AWS NLB logs to your Panther Console

Overview

circle-info

AWS NLB log ingestion is in open betaarrow-up-right starting with Panther version 1.118, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther supports ingesting Amazon Web Services (AWS) Network Load Balancer (NLB) logs via AWS S3.

circle-info

AWS NLB access logs only support TLS listeners. TCP and UDP listeners do not generate access logs.

How to onboard AWS NLB logs to Panther

To pull NLB logs into Panther, set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "AWS Network Load Balancer," then click its tile.

  4. In upper right-hand corner, click Start Setup.

Panther-managed detections

See Panther-managed rules for AWS in the panther-analysis GitHub repositoryarrow-up-right.

Supported NLB logs

AWS.NLB

Network Load Balancer logs Layer 4 TLS connection logs for your network load balancer. For more information, see AWS's documentation on NLB access logsarrow-up-right.

Last updated

Was this helpful?