AWS ALB

Connecting AWS ALB logs to your Panther Console

Overview

Panther supports ingesting Amazon Web Services (AWS) Application Load Balancer (ALB) logs via AWS S3.

How to onboard AWS ALB logs to Panther

To pull ALB logs into Panther, you will need to set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the lefthand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search "AWS" to see the list of available log sources.

  4. Select AWS Application Load Balancer.

  5. Select AWS S3 Bucket for your source to begin setup. Follow Panther’s documentation for configuring S3 for data transport.

Panther-built detections

See Panther's prewritten AWS rules in the panther-analysis Github repository.

Supported ALB logs

AWS.ALB

Application Load Balancer logs layer 7 network logs for your application load balancer. For more information, see AWS's documentation on ALB access logs.

Last updated

Was this helpful?