Lacework Alert Channel Webhook

Panther supports receiving Lacework Event logs via webhook

Overview

You can ingest Lacework Event logs into Panther by configuring a Custom Webhook Alert Channel to post events to a Panther HTTP source.

If you are looking for instructions on ingesting Lacework log types other than Lacework.Events, please see the Lacework Export documentation.

How to onboard Alert Channel Webhook logs to Panther

Step 1: Create a Lacework Alert Channel Webhook log source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Lacework Alert Channel Webhook", then click its tile.

    • In the slide-out panel, the Transport Mechanism dropdown in the upper-right corner will be pre-populated with the HTTP option.

  4. Click Start Setup.

    In the Panther Console, the slideout panel for Lacework Alert Channel Webhook is open. Start Setup is in the upper right corner.
  5. Follow Panther's instructions for configuring an HTTP Source.

    • During setup, on the security configuration page, choose bearer authentication. You can generate a token value by clicking the circular arrows, or supply your own.

    • Payloads sent to this source are subject to the payload requirements for all HTTP sources.

    • Do not proceed to the next step until the creation of your HTTP endpoint has completed.

Step 2: Configure Lacework to push logs to your Panther HTTP source

Supported log type

Lacework.Events

Lacework.Events represents the content of an exported Lacework Alert S3 Object.

Reference: Lacework Documentation on Events.

Lacework Alert S3 Objects often contain only a subset of the fields shown below in Panther's Lacework.Events schema. Many fields in this schema are included to accommodate edge cases. See example payloads in the Lacework documentation.

Last updated

Was this helpful?