Amazon AWS EC2
Configuration
Setup in FortiSIEM
Complete these steps in the FortiSIEM UI:
- Go to the ADMIN > Setup > Credentials tab.
- In Step 1: Enter Credentials, click New.
- Enter the following settings from the table into the Access Method Definition dialog box:
Note: For more information, see "Setting Credentials" in the User's Guide to create a new credential.Settings Description Name <set name> Device Type Amazon AWS EC2 Access Protocol AWS SDK Region [Required] Region in which your AWS instance is located Access Key ID [Required] Access key for your AWS instance Secret Key [Required] Secret key for your AWS instance Description Description about the device Click Save.
- Enter the following settings from the table into the Access Method Definition dialog box:
- In Step 2: Enter IP Range to Credential Associations, click New.
- Enter "amazon.com" in the IP/Host Name field, if it does not already appear.
- Select the name of your AWS EC2 credential from the Credentials drop-down list if it is not already selected.
- Click Save.
- Click the Test drop-down list and select Test Connectivity to test the connection to Amazon AWS EC2.
- Navigate to Admin > Setup > Discovery, and click New.
- In the Name field, enter a name, such as "AWS_EC2".
- From the Discovery Type drop-down list, select AWS Scan.
- From the Credential drop-down list, select the credential you created, if it is not already selected.
- Click Save.
- To see the jobs associated with AWS, select ADMIN > Setup > Pull Events.
- To see the received events select ANALYTICS, then enter "AWS" in the search box.