File tree Expand file tree Collapse file tree 1 file changed +7
-7
lines changed
Monitoring/ingest_nas_audit_logs_into_cloudwatch Expand file tree Collapse file tree 1 file changed +7
-7
lines changed Original file line number Diff line number Diff line change @@ -29,17 +29,17 @@ systems that you want to ingest the audit logs from.
2929- You have created a role with the necessary permissions to allow the Lambda function to do the following:
3030
3131<table >
32- <tr ><th >Service</td ><td >Actions</td ><td >Resources</td ></tr >
32+ <tr ><th >Service</td ><th >Actions</td ><th >Resources</th ></tr >
3333<tr ><td >fsx</td ><td >fsx:DescribeFileSystems</td ><td >*</td ></tr >
3434<tr ><td rowspan =" 3 " >ec2</td ><td >DescribeNetworkInterfaces</td ><td >*</td ></tr >
3535<tr ><td >CreateNetworkInterface</td ><td >arn:aws:ec2:*:< ; accountID> ; :*</td ></tr >
3636<tr ><td >DeleteNetworkInterface</td ><td >arn:aws:ec2:*:< ; accountID> ; :*</td ></tr >
37- <tr ><td rowspan =" 2 " >logs</td ><td >CreateLogStream </td ><td > arn:aws:logs:\< region >:\< accountID > :log-group:\< logGroupName > :* </td ></tr >
38- <tr ><td >PutLogEvents </td ><td > arn:aws:logs:\< region >:\< accountID > :log-group:\< logGroupName > :* </td ></tr >
39- <tr ><td rowspan =" 3 " > s3 </td ><td > ListBucket </td ><td > arn:aws:s3:\< region >:\< accountID > :* </td ></tr >
40- <tr ><td >GetObject </td ><td > arn:aws:s3:\< region >:\< accountID > :*/* </td ></tr >
41- <tr ><td >PutObject </td ><td > arn:aws:s3:\< region >:\< accountID > :*/* </td ></tr >
42- <tr ><td >secretsmanager </td ><td > GetSecretValue </td ><td > arn:aws:secretsmanager:\< region >:\< accountID > :secret:\< secretName > </td ></tr >
37+ <tr ><td rowspan =" 2 " >logs</td ><td >CreateLogStream </td ><td > arn:aws:logs:& lt ; region& gt ; : & lt ; accountID& gt ; :log-group:& lt ; logGroupName& gt ; :* </td ></tr >
38+ <tr ><td >PutLogEvents </td ><td > arn:aws:logs:& lt ; region& gt ; : & lt ; accountID& gt ; :log-group:& lt ; logGroupName& gt ; :* </td ></tr >
39+ <tr ><td rowspan =" 3 " > s3 </td ><td > ListBucket </td ><td > arn:aws:s3:& lt ; region& gt ; : & lt ; accountID& gt ; :* </td ></tr >
40+ <tr ><td >GetObject </td ><td > arn:aws:s3:& lt ; region>:& lt ; accountID& gt ; :*/* </td ></tr >
41+ <tr ><td >PutObject </td ><td > arn:aws:s3:& lt ; region>:& lt ; accountID& gt ; :*/* </td ></tr >
42+ <tr ><td >secretsmanager </td ><td > GetSecretValue </td ><td > arn:aws:secretsmanager:& lt ; region& gt ; : & lt ; accountID& gt ; :secret:& lt ; secretName& gt ; </td ></tr >
4343</table >
4444
4545## Deployment
You can’t perform that action at this time.
0 commit comments