Teleport Logs

Connecting Teleport logs to your Panther Console

Overview

Panther supports ingesting Teleport logs via common Data Transport options: Amazon Web Services (AWS) S3 and SQS.

How to onboard Teleport logs to Panther

To pull these logs into Panther:

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for the log type you want to onboard, then click its tile.

  4. Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:

  5. Configure your Data Transport source to pull in logs from Teleport.

    • See the Data Transport service provider's documentation for instructions on pulling in logs.

Panther-Built Detections

See Panther's built in rules for Teleport in panther-analysis in Github.

Supported log types

Gravitational.TeleportAudit

Teleport logs events like successful user logins along with the metadata like remote IP address, time and the session ID. Please see Teleport's Cluster Administration Guide for more information.

Last updated

Was this helpful?