The steps below outline integration between Amazon Security Lake and Barracuda XDR monitoring. Amazon Security Lake helps you analyze security data so that you can get a complete understanding of your security posture across the entire organization. With Amazon Security Lake, you can also improve the protection of your workloads, applications, and data.
Prerequisites
To integrate Amazon Security Lake, you must have the following:
- A functioning Amazon Security Lake instance. See https://docs.aws.amazon.com/security-lake/latest/userguide/getting-started.html
- Server Access Logging enabled on Amazon S3 Security. See the To enable Server Access Logging enabled on Amazon S3 Security procedure below.
To enable Server Access Logging enabled on Amazon S3 Security
- In Amazon S3 Security, navigate to Buckets > [your bucket], where [your bucket] is the name of your bucket.
- Click the Properties tab.
- In Server access logging, select the Enable check box.
- In Destination, enter the path to your bucket.
- In Log Object key Format, select a format.
- Click Save Changes.
- Proceed to the To enable the Amazon Security Lake integration for an S3 Bucket procedure.
To create and save access keys for integration
- In Amazon S3, in the profile menu in the top right corner of the window, click Security Credentials.
- In the Access keys section, click Create access key.
- Select the I understand creating a root access key is not a best practice, but I still want to create one check box.
- Click Create access key.
- Copy and save your Access key and Secret access key.
- Click Done.
To integrate Amazon Security Lake via Simple Queue Service (Optional)
- In Amazon S3 Security, navigate to Buckets > [your bucket], where [your bucket] is the name of your bucket.
- Click the Properties tab.
- In the Event notifications area, do one of the following:
- If there are no event notifications, proceed to step 7.
- If there is an event notification, click a link in the Destination column on the right.
- In the Details section, copy and save the URL.
- In the Search bar, type
Simple Queue Service
and hit Return. - Click Create queue.
- Select your options, then click Create queue.
- Navigate to Buckets > [your bucket], where [your bucket] is the name of your bucket.
- Click the Properties tab.
- In the Event notifications area, click Create event notification.
- In the General configuration area, provide the following:
- Event name
- Prefix - optional
- Suffix - optional
- In Event types, select All object create events.
- In Destination, select SQS queue.
- In Specify SQS queue, select Choose from your SQS queue.
- Select an SQS queue.
- Click Save Changes.
- Proceed to the To enable the Amazon Security Lake integration for an SQS Queue procedure below.
To enable the Amazon Security Lake integration for an S3 Bucket
- In Barracuda XDR Dashboard, navigate to Administration > Integrations.
- On the AWS Security Lake card, click Setup.
- Select the Enabled check box.
- In Log Type, select S3 Bucket.
- In AWS Bucket, paste the path to your Amazon Bucket.
- In Access Key, paste your access key.
- In Secret Key, paste your secret key.
- Optionally, click Test to verify the credentials.
- Select the Enable check box.
- Click Save.
To enable the Amazon Security Lake integration for an SQS Queue
- In Barracuda XDR Dashboard, navigate to Administration > Integrations.
- On the AWS Security Lake card, click Setup.
- Select the Enabled check box.
- In Log Type, select SQS Queue.
- In SQS Queue, paste the SQS queue you set up in the previous procedure.
- In Access Key, paste your access key.
- In Secret Key, paste your secret key.
- Optionally, click Test to verify the credentials.
- Select the Enable check box.
- Click Save.