Lacework Logs
Connecting Lacework logs to your Panther Console
Overview
Panther supports ingesting Lacework logs via common Data Transport options: Amazon Web Services (AWS) S3 and SQS.
How to onboard Lacework logs to Panther
To connect these logs into Panther:
Log in to the Panther Console.
In the left sidebar, click Configure > Log Sources.
Click Create New.
Search for the log type you want to onboard, then click its tile.
Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:
Configure Lacework to push logs to the Data Transport source.
See Lacework's documentation for instructions on pushing logs to your selected Data Transport source.
Supported log types
Lacework.AgentManagement
Lacework.AgentManagement gathers Lacework agent management information.
Reference: Lacework Documentation on AgentManagement.
Lacework.AlertDetails
Lacework.AlertDetails provides information about generated alerts.
Reference: Lacework Documentation on AlertDetails.
Lacework.AllFiles
Lacework.AllFiles tracks every time Lacework detects a file.
Reference: Lacework Documentation on AllFiles.
Lacework.Applications
Lacework.Applications contains applications information running on the machine with an agent installed with details (such as application name, user name, machine, etc.).
Reference: Lacework Documentation on Applications.
Lacework.ChangeFiles
Lacework.ChangeFiles tracks every time a file is changed in your environment.
Reference: Lacework Documentation on ChangeFiles.
Lacework.CloudCompliance
Lacework.CloudCompliance tracks compliance violations identified by Lacework cloud assessments.
Reference: Lacework Documentation on CloudCompliance.
Lacework.CloudConfiguration
Lacework.CloudConfiguration contains details about supported and configured cloud resources.
Reference: Lacework Documentation on CloudConfiguration.
Lacework.Cmdline
Lacework.Cmdline monitors any command line invocations in your environment.
Reference: Lacework Documentation on Cmdline.
Lacework.Connections
Lacework.Connections monitors for connections in your environment.
Reference: Lacework Documentation on Connections.
Lacework.ContainerSummary
Lacework.ContainerSummary monitors for containers in your environment.
Reference: Lacework Documentation on ContainerSummary.
Lacework.ContainerVulnDetails
Lacework.ContainerVulnDetails monitors for container vulnerabilities in your environment.
Reference: Lacework Documentation on ContainerVulnDetails.
Lacework.DNSQuery
Lacework.DNSQuery monitors for any DNS queries in your environment.
Reference: Lacework Documentation on DNSQuery.
Lacework.Events
Lacework.Events represents the content of an exported Lacework Alert S3 Object.
Reference: Lacework Documentation on Events.
Lacework.HostVulnDetails
Lacework.HostVulnDetails provides details around any vulnerabilities on hosts across your environment.
Reference: Lacework Documentation on HostVulnDetails.
Lacework.Image
Lacework.Image provides details about any container images in your environment.
Reference: Lacework Documentation on Images.
Lacework.Interfaces
Lacework.Interfaces monitors any discovered network interfaces across your environment.
Reference: Lacework Documentation on Interfaces.
Lacework.InternalIPA
Lacework.InternalIPA monitors any internal IP addresses across your environment.
Reference: Lacework Documentation on InternalIPA.
Lacework.MachineDetails
Lacework.MachineDetails aggregates historical data about any machines found in your environment.
Reference: Lacework Documentation on MachineDetails.
Lacework.MachineSummary
Lacework.MachineSummary summarizes and aggregates details about machines in your environment.
Reference: Lacework Documentation on MachineSummary.
Lacework.NewHashes
Lacework.NewHashes tracks any new file hashes in your environment.
Reference: Lacework Documentation on NewHashes.
Lacework.Package
Lacework.Package tracks any packages in your environment.
Reference: Lacework Documentation on Packages.
Lacework.PodSummary
Lacework.PodSummary tracks any pods (collections of one or more containers) in your environment.
Reference: Lacework Documentation on PodSummary.
Lacework.ProcessSummary
Lacework.ProcessSummary tracks any processes running in your environment.
Reference: Lacework Documentation on ProcessSummary.
Lacework.UserDetails
Lacework.UserDetails tracks historical data about any users in your environment.
Reference: Lacework Documentation on UserDetails.
Last updated
Was this helpful?

