Microsoft Sentinel
Cloud and workloads

Connect Aws S3 Waf

In brief

The documentation updates wording and clarifies that the second CloudFormation template creates the remaining AWS resources, including the S3 bucket, SQS queue, and IAM role.

What Defender admins need to know

Administrators have clearer guidance for completing AWS resource provisioning.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use the Amazon Web Services (AWS) S3-based Web Application Firewall (WAF) connector to ingest AWS WAF logs, collected in AWS S3 buckets, to Microsoft Sentinel. AWS WAF logs are detailed records of the web traffic analyzed by the AWS WAF against web access control lists (ACLs). These records contain information such as the time AWS WAF received the request, the specifics of the request, and the action taken by the rule that the request matched. These logs and this traffic analysis are essential for maintaining the security and performance of web applications.

This connector features an AWS CloudFormation-based onboarding script to streamline the creation of the AWS resources used by the Amazon Web Services S3 WAF connector.

  • Compliance and auditing: AWS WAF logs provide detailed records of web ACL traffic, which can be crucial for compliance reporting and auditing purposes. The connector ensures that these logs are available within Sentinel for easy access and analysis.

This article explains how to configure the Amazon Web Services S3 WAF connector. The process of setting it up the connector has two parts: the AWS side and the Microsoft Sentinel side. Each side'sThe AWS process produces information used by Microsoft Sentinel, and the other side.Microsoft Sentinel process produces information used by AWS. Exchanging this configuration information between AWS and Microsoft Sentinel enables secure authenticated communication.

Prerequisites

Set up the AWS environment

To simplify the onboarding process, the Amazon Web Services S3 WAF connector page in Microsoft Sentinel contains downloadable templates for you to use with the AWS CloudFormation service. The CloudFormation service uses these templates to automatically create resource stacks in AWS. These stacks include the resources themselvesthemselves, as described in this article, andEnable and configure the Amazon Web Services S3 WAF connector, along with credentials, permissions, and policies.

Create the remaining AWS resources

Use the second CloudFormation template to create the remaining AWS resources, including the S3 bucket, SQS queue, and IAM role.

  1. Return to the AWS CloudFormation stacks page and create a new stack.

  2. Select Choose file and locate the "Template 2_ AWS WAF resources deployment.json" file you downloaded.