AWS Transit Gateway

Connecting Transit Gateway Flow logs to your Panther Console

Overview

Panther supports ingesting Amazon Web Services (AWS) Transit Gateway Flow logs via AWS S3.

How to onboard AWS Transit Gateway logs to Panther

To pull Transit Gateway logs into Panther, you need to set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the lefthand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search "AWS" to see the list of available log sources.

  4. Select AWS Transit Gateway Flow.

  5. Select AWS S3 Bucket for your source to begin setup. Follow Panther’s documentation for configuring S3 for data transport.

Panther-built detections

See Panther's prewritten AWS rules in the panther-analysis Github repository.

Supported AWS Transit Gateway logs

AWS.TransitGatewayFlow

TransitGatewayFlow logs enable you to capture information about the IP traffic going to and from your transit gateways.

Note that for Panther to properly ingest TransitGatewayFlow logs, they must come directly from S3, in CSV format with a header.

For more information, see AWS's documentation on Transit Gateway Flow Logs.

Last updated

Was this helpful?