Lacework Logs

Connecting Lacework logs to your Panther Console

Overview

Panther supports ingesting Lacework logs via common Data Transport options: Amazon Web Services (AWS) S3 and SQS.

How to onboard Lacework logs to Panther

To connect these logs into Panther:

  1. Log in to the Panther Console.

  2. In the left sidebar, click Configure > Log Sources.

  3. Click Create New.

  4. Search for the log type you want to onboard, then click its tile.

  5. Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:

  6. Configure Lacework to push logs to the Data Transport source.

Supported log types

Required fields in the schema are listed as "required: true" just below the "name" field.

Lacework.AgentManagement

Lacework.AgentManagement gathers Lacework agent management information.

Reference: Lacework Documentation on AgentManagement.

Lacework.AlertDetails

Lacework.AlertDetails provides information about generated alerts.

Reference: Lacework Documentation on AlertDetails.

Lacework.AllFiles

Lacework.AllFiles tracks every time Lacework detects a file.

Reference: Lacework Documentation on AllFiles.

Lacework.Applications

Lacework.Applications contains applications information running on the machine with an agent installed with details (such as application name, user name, machine, etc.).

Reference: Lacework Documentation on Applications.

Lacework.ChangeFiles

Lacework.ChangeFiles tracks every time a file is changed in your environment.

Reference: Lacework Documentation on ChangeFiles.

Lacework.CloudCompliance

Lacework.CloudCompliance tracks compliance violations identified by Lacework cloud assessments.

Reference: Lacework Documentation on CloudCompliance.

Lacework.CloudConfiguration

Lacework.CloudConfiguration contains details about supported and configured cloud resources.

Reference: Lacework Documentation on CloudConfiguration.

Lacework.Cmdline

Lacework.Cmdline monitors any command line invocations in your environment.

Reference: Lacework Documentation on Cmdline.

Lacework.Connections

Lacework.Connections monitors for connections in your environment.

Reference: Lacework Documentation on Connections.

Lacework.ContainerSummary

Lacework.ContainerSummary monitors for containers in your environment.

Reference: Lacework Documentation on ContainerSummary.

Lacework.ContainerVulnDetails

Lacework.ContainerVulnDetails monitors for container vulnerabilities in your environment.

Reference: Lacework Documentation on ContainerVulnDetails.

Lacework.DNSQuery

Lacework.DNSQuery monitors for any DNS queries in your environment.

Reference: Lacework Documentation on DNSQuery.

Lacework.Events

Lacework.Events represents the content of an exported Lacework Alert S3 Object.

Reference: Lacework Documentation on Events.

Lacework.HostVulnDetails

Lacework.HostVulnDetails provides details around any vulnerabilities on hosts across your environment.

Reference: Lacework Documentation on HostVulnDetails.

Lacework.Image

Lacework.Image provides details about any container images in your environment.

Reference: Lacework Documentation on Images.

Lacework.Interfaces

Lacework.Interfaces monitors any discovered network interfaces across your environment.

Reference: Lacework Documentation on Interfaces.

Lacework.InternalIPA

Lacework.InternalIPA monitors any internal IP addresses across your environment.

Reference: Lacework Documentation on InternalIPA.

Lacework.MachineDetails

Lacework.MachineDetails aggregates historical data about any machines found in your environment.

Reference: Lacework Documentation on MachineDetails.

Lacework.MachineSummary

Lacework.MachineSummary summarizes and aggregates details about machines in your environment.

Reference: Lacework Documentation on MachineSummary.

Lacework.NewHashes

Lacework.NewHashes tracks any new file hashes in your environment.

Reference: Lacework Documentation on NewHashes.

Lacework.Package

Lacework.Package tracks any packages in your environment.

Reference: Lacework Documentation on Packages.

Lacework.PodSummary

Lacework.PodSummary tracks any pods (collections of one or more containers) in your environment.

Reference: Lacework Documentation on PodSummary.

Lacework.ProcessSummary

Lacework.ProcessSummary tracks any processes running in your environment.

Reference: Lacework Documentation on ProcessSummary.

Lacework.UserDetails

Lacework.UserDetails tracks historical data about any users in your environment.

Reference: Lacework Documentation on UserDetails.

Last updated

Was this helpful?