AWS S3

Connecting AWS S3 Access logs to your Panther Console

Overview

Panther supports ingesting Amazon Web Services (AWS) S3 logs via an S3 bucket.

How to onboard AWS S3 logs to Panther

To pull S3 logs into Panther, you will need to set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the lefthand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search "AWS" to see the list of available log sources.

  4. Select AWS S3 Server Access.

  5. Select AWS S3 Bucket for your source to begin setup. Follow Panther’s documentation for configuring S3 for Data Transport.

Panther-built detections

See Panther's prewritten AWS rules in the panther-analysis Github repository.

Querying logs in Data Explorer

See example SQL queries, for use in Panther's Data Explorer, in S3 Access logs queries.

Supported AWS S3 logs

AWS.S3ServerAccess

S3ServerAccess is an S3 access log. For more information, see AWS's documentation on S3 log format.

Last updated

Was this helpful?