Lacework Logs

Connecting Lacework logs to your Panther Console

Overview

Panther supports ingesting Lacework logs via common Data Transport options: Amazon Web Services (AWS) S3 and SQS.

How to onboard Lacework logs to Panther

To connect these logs into Panther:

  1. Log in to the Panther Console.

  2. In the left sidebar, click Configure > Log Sources.

  3. Click Create New.

  4. Search for the log type you want to onboard, then click its tile.

  5. Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:

  6. Configure Lacework to push logs to the Data Transport source.

Supported log types

circle-info

Required fields in the schema are listed as "required: true" just below the "name" field.

Lacework.AgentManagement

Lacework.AgentManagement gathers Lacework agent management information.

Reference: Lacework Documentation on AgentManagementarrow-up-right.

Lacework.AlertDetails

Lacework.AlertDetails provides information about generated alerts.

Reference: Lacework Documentation on AlertDetails.arrow-up-right

Lacework.AllFiles

Lacework.AllFiles tracks every time Lacework detects a file.

Reference: Lacework Documentation on AllFilesarrow-up-right.

Lacework.Applications

Lacework.Applications contains applications information running on the machine with an agent installed with details (such as application name, user name, machine, etc.).

Reference: Lacework Documentation on Applications.arrow-up-right

Lacework.ChangeFiles

Lacework.ChangeFiles tracks every time a file is changed in your environment.

Reference: Lacework Documentation on ChangeFilesarrow-up-right.

Lacework.CloudCompliance

Lacework.CloudCompliance tracks compliance violations identified by Lacework cloud assessments.

Reference: Lacework Documentation on CloudCompliance.arrow-up-right

Lacework.CloudConfiguration

Lacework.CloudConfiguration contains details about supported and configured cloud resources.

Reference: Lacework Documentation on CloudConfiguration.arrow-up-right

Lacework.Cmdline

Lacework.Cmdline monitors any command line invocations in your environment.

Reference: Lacework Documentation on Cmdlinearrow-up-right.

Lacework.Connections

Lacework.Connections monitors for connections in your environment.

Reference: Lacework Documentation on Connectionsarrow-up-right.

Lacework.ContainerSummary

Lacework.ContainerSummary monitors for containers in your environment.

Reference: Lacework Documentation on ContainerSummaryarrow-up-right.

Lacework.ContainerVulnDetails

Lacework.ContainerVulnDetails monitors for container vulnerabilities in your environment.

Reference: Lacework Documentation on ContainerVulnDetailsarrow-up-right.

Lacework.DNSQuery

Lacework.DNSQuery monitors for any DNS queries in your environment.

Reference: Lacework Documentation on DNSQueryarrow-up-right.

Lacework.Events

Lacework.Events represents the content of an exported Lacework Alert S3 Object.

Reference: Lacework Documentation on Eventsarrow-up-right.

Lacework.HostVulnDetails

Lacework.HostVulnDetails provides details around any vulnerabilities on hosts across your environment.

Reference: Lacework Documentation on HostVulnDetailsarrow-up-right.

Lacework.Image

Lacework.Image provides details about any container images in your environment.

Reference: Lacework Documentation on Imagesarrow-up-right.

Lacework.Interfaces

Lacework.Interfaces monitors any discovered network interfaces across your environment.

Reference: Lacework Documentation on Interfacesarrow-up-right.

Lacework.InternalIPA

Lacework.InternalIPA monitors any internal IP addresses across your environment.

Reference: Lacework Documentation on InternalIPAarrow-up-right.

Lacework.MachineDetails

Lacework.MachineDetails aggregates historical data about any machines found in your environment.

Reference: Lacework Documentation on MachineDetailsarrow-up-right.

Lacework.MachineSummary

Lacework.MachineSummary summarizes and aggregates details about machines in your environment.

Reference: Lacework Documentation on MachineSummaryarrow-up-right.

Lacework.NewHashes

Lacework.NewHashes tracks any new file hashes in your environment.

Reference: Lacework Documentation on NewHashesarrow-up-right.

Lacework.Package

Lacework.Package tracks any packages in your environment.

Reference: Lacework Documentation on Packagesarrow-up-right.

Lacework.PodSummary

Lacework.PodSummary tracks any pods (collections of one or more containers) in your environment.

Reference: Lacework Documentation on PodSummaryarrow-up-right.

Lacework.ProcessSummary

Lacework.ProcessSummary tracks any processes running in your environment.

Reference: Lacework Documentation on ProcessSummaryarrow-up-right.

Lacework.UserDetails

Lacework.UserDetails tracks historical data about any users in your environment.

Reference: Lacework Documentation on UserDetailsarrow-up-right.

Last updated

Was this helpful?