AWS CloudTrail

New in version 3.2.0.

Wazuh provides the ability to read AWS CloudTrail logs directly from AWS S3 buckets. Amazon CloudTrail support is now a built-in Wazuh capability, giving you the ability to search, analyze, and alert on AWS CloudTrail log data.

This section provides instructions to configure the integration with Cloudtrail. In addition, it explains different use cases, as examples of how the rules can be customized for alerting on specific events from IAM, EC2 and VPC services.