For the complete documentation index, see llms.txt. This page is also available as Markdown.

Managing HTTP Log Sources with Terraform

Manage HTTP log sources as code in Terraform

Overview

You can define your HTTP log source in Terraform using the Panther Terraform provider.

Other methods to create an HTTP log source include using the Panther API directly and manual creation in the Panther Console.

How to define your Panther HTTP log source in Terraform

The following sections outline how to define your HTTP log source in HashiCorp Configuration Language (HCL).

Prerequisite

Step 1: Choose an authentication method

The authentication method you select will determine the variables you define in Step 2, below.

Step 2: Define variables

  • Define a variables.tf file with the Panther variables shown in the code block below.

Authentication method-specific variables

In your variables.tf file, include the values in the Additional variables column below for the authentication method you chose in Step 1.

Authentication method
auth_method value
Additional variables

SharedSecret

auth_header_key, auth_secret_value

HMAC

auth_header_key, auth_secret_value

Bearer

auth_bearer_token

Basic

auth_username, auth_password

None (not recommended)

None

Step 3: Provide values for the defined variables

  • Add a *.tfvars file that assigns values to the variables you defined in Step 2. Note that to complete this section, you will need the API URL and token outlined in the Prerequisite section.

    • Your panther_api_url value should be your root API URL. This is either:

Step 4: Define the Terraform provider

  • Add the Panther Terraform provider.

Step 5: Define Panther HTTP log source

The following HCL configuration defines the HTTP log source in Panther.

Step 6: Configure a drop-off alarm (optional)

To trigger an alert when the log source stops receiving data, add a panther_log_source_alarm resource pointing at the HTTP source created above:

For the full argument reference and import syntax, see Managing Log Source Alarms with Terraform.

Last updated

Was this helpful?