AWS ECS
Scanner supports AWS ECS logs, which are logs generated by your containers running in ECS. In order for Scanner to see your ECS logs, you can configure ECS to publish logs to CloudWatch, then configure the CloudWatch log groups to forward data to a Kinesis Data Firehose, which can then write the logs into an S3 bucket that Scanner is linked to.
Collect logs in S3
ECS to CloudWatch
You can follow AWS documentation to publish your ECS logs to one or more CloudWatch log groups. See: Send Amazon ECS logs to CloudWatch.
CloudWatch to Kinesis Data Firehose
You can follow the AWS documentation to configure your CloudWatch log groups to push their logs to a Kinesis Data Firehose. See: Send CloudWatch Logs to Firehose.
Kinesis Data Firehose to S3
A Kinesis Data Firehose can push logs to various destinations. We want to push to an S3 bucket that Scanner is linked to. You can follow the AWS documentation to configure the Firehose to write to an S3 bucket. See: Understand data delivery in Amazon Data Firehose.
Create an Index Rule
Once ECS logs are landing in your S3 bucket, Create an Index Rule to ingest the logs via Scanner Collect for fast search and detections.
Last updated
Was this helpful?