Lacework Export

Export Lacework logs to Panther via S3, Google Cloud Storage, or Azure

Overview

Panther supports ingesting Lacework export logs common Data Transport options: Amazon Web Services (AWS) S3, Google Cloud Storage (GCS), and Azure Blob.

If you are looking for instructions on ingesting Lacework.Events logs, please see the Lacework Alert Channel Webhook documentation.

How to onboard Lacework Export logs to Panther

To connect these logs into Panther:

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Lacework Export,", then click its tile.

  4. In the Transport Mechanism drop-down, select the Data Transport method you wish to use for this integration. After choosing Lacework Export, the slideout tile is displayed. There is a dropdown in the upper right where you can select the Transport Mechanism.

  5. Click Start Setup.

  6. Follow Panther's instructions for configuring the selected Data Transport method:

  7. Configure Lacework to push logs to the Data Transport source.

Supported log types

Lacework.AgentManagement

Lacework.AgentManagement gathers Lacework agent management information.

Reference: Lacework Documentation on AgentManagementarrow-up-right.

Lacework.AlertDetails

Lacework.AlertDetails provides information about generated alerts.

Reference: Lacework Documentation on AlertDetails.arrow-up-right

Lacework.AllFiles

Lacework.AllFiles tracks every time Lacework detects a file.

Reference: Lacework Documentation on AllFilesarrow-up-right.

Lacework.Applications

Lacework.Applications contains applications information running on the machine with an agent installed with details (such as application name, user name, machine, etc.).

Reference: Lacework Documentation on Applications.arrow-up-right

Lacework.ChangeFiles

Lacework.ChangeFiles tracks every time a file is changed in your environment.

Reference: Lacework Documentation on ChangeFilesarrow-up-right.

Lacework.CloudCompliance

Lacework.CloudCompliance tracks compliance violations identified by Lacework cloud assessments.

Reference: Lacework Documentation on CloudCompliance.arrow-up-right

Lacework.CloudConfiguration

Lacework.CloudConfiguration contains details about supported and configured cloud resources.

Reference: Lacework Documentation on CloudConfiguration.arrow-up-right

Lacework.Cmdline

Lacework.Cmdline monitors any command line invocations in your environment.

Reference: Lacework Documentation on Cmdlinearrow-up-right.

Lacework.Connections

Lacework.Connections monitors for connections in your environment.

Reference: Lacework Documentation on Connectionsarrow-up-right.

Lacework.ContainerSummary

Lacework.ContainerSummary monitors for containers in your environment.

Reference: Lacework Documentation on ContainerSummaryarrow-up-right.

Lacework.ContainerVulnDetails

Lacework.ContainerVulnDetails monitors for container vulnerabilities in your environment.

Reference: Lacework Documentation on ContainerVulnDetailsarrow-up-right.

Lacework.DNSQuery

Lacework.DNSQuery monitors for any DNS queries in your environment.

Reference: Lacework Documentation on DNSQueryarrow-up-right.

Lacework.HostVulnDetails

Lacework.HostVulnDetails provides details around any vulnerabilities on hosts across your environment.

Reference: Lacework Documentation on HostVulnDetailsarrow-up-right.

Lacework.Image

Lacework.Image provides details about any container images in your environment.

Reference: Lacework Documentation on Imagesarrow-up-right.

Lacework.Interfaces

Lacework.Interfaces monitors any discovered network interfaces across your environment.

Reference: Lacework Documentation on Interfacesarrow-up-right.

Lacework.InternalIPA

Lacework.InternalIPA monitors any internal IP addresses across your environment.

Reference: Lacework Documentation on InternalIPAarrow-up-right.

Lacework.MachineDetails

Lacework.MachineDetails aggregates historical data about any machines found in your environment.

Reference: Lacework Documentation on MachineDetailsarrow-up-right.

Lacework.MachineSummary

Lacework.MachineSummary summarizes and aggregates details about machines in your environment.

Reference: Lacework Documentation on MachineSummaryarrow-up-right.

Lacework.NewHashes

Lacework.NewHashes tracks any new file hashes in your environment.

Reference: Lacework Documentation on NewHashesarrow-up-right.

Lacework.Package

Lacework.Package tracks any packages in your environment.

Reference: Lacework Documentation on Packagesarrow-up-right.

Lacework.PodSummary

Lacework.PodSummary tracks any pods (collections of one or more containers) in your environment.

Reference: Lacework Documentation on PodSummaryarrow-up-right.

Lacework.ProcessSummary

Lacework.ProcessSummary tracks any processes running in your environment.

Reference: Lacework Documentation on ProcessSummaryarrow-up-right.

Lacework.UserDetails

Lacework.UserDetails tracks historical data about any users in your environment.

Reference: Lacework Documentation on UserDetailsarrow-up-right.

Last updated

Was this helpful?