Skip to content

Commit 4872489

Browse files
authored
New doc for AWS IAM users (app) (#5750)
1 parent f5da5c9 commit 4872489

File tree

6 files changed

+130
-1
lines changed

6 files changed

+130
-1
lines changed

blog-service/2025-09-05-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: AWS IAM Users (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- aws-iam-users
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new AWS IAM Users app for Sumo Logic. This app helps you monitor and analyze user-related data, enabling you to optimize security practices and ensure compliance within your AWS account. [Learn more](/docs/integrations/saas-cloud/aws-iam-users/).

cid-redirects.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2920,6 +2920,7 @@
29202920
"/cid/11000": "/docs/platform-services/automation-service/automation-service-playbooks",
29212921
"/cid/1105": "/docs/integrations/cloud-security-monitoring-analytics/aws-security-hub-ocsf",
29222922
"/cid/1106": "/docs/integrations/sumo-apps/opentelemetry-collector-insights",
2923+
"/cid/1107": "/docs/integrations/saas-cloud/aws-iam-users",
29232924
"/Cloud_SIEM_Enterprise": "/docs/cse",
29242925
"/Cloud_SIEM_Enterprise/Administration": "/docs/cse/administration",
29252926
"/Cloud_SIEM_Enterprise/Administration/Cloud_SIEM_Enterprise_Feature_Update_(2022)": "/docs/cse/administration",

docs/integrations/product-list/product-list-a-l.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
109109
| <img src={useBaseUrl('img/send-data/AWSGovCloudUS-Logo.jpeg')} alt="Thumbnail icon" width="50"/> | [AWS GovCloud](https://aws.amazon.com/govcloud-us) | Collector: [Collection from AWS GovCloud](/docs/send-data/hosted-collectors/amazon-aws/collection-aws-govcloud/) |
110110
| <img src={useBaseUrl('img/integrations/amazon-aws/aws-ground-station-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS Ground Station](https://aws.amazon.com/ground-station/) | App: [AWS Ground Station](/docs/integrations/amazon-aws/aws-ground-station/) |
111111
| <img src={useBaseUrl('img/integrations/amazon-aws/aws-healthlake-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS HealthLake](https://aws.amazon.com/healthlake/) | App: [AWS HealthLake](/docs/integrations/amazon-aws/aws-healthlake/) |
112-
| <img src={useBaseUrl('img/integrations/misc/aws-iam-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS Identity and Access Management](https://aws.amazon.com/iam/) | Automation Integration: [AWS IAM](/docs/platform-services/automation-service/app-central/integrations/aws-iam/)<br/>Collector: [AWS IAM Users](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-iam-users-source) |
112+
| <img src={useBaseUrl('img/integrations/misc/aws-iam-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS Identity and Access Management](https://aws.amazon.com/iam/) | App: [AWS IAM Users](/docs/integrations/saas-cloud/aws-iam-users) <br/>Automation Integration: [AWS IAM](/docs/platform-services/automation-service/app-central/integrations/aws-iam/)<br/>Collector: [AWS IAM Users](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-iam-users-source) |
113113
| <img src={useBaseUrl('img/integrations/amazon-aws/lambda.png')} alt="Thumbnail icon" width="50"/> | [AWS Lambda](https://aws.amazon.com/pm/lambda/) | App: [AWS Lambda](/docs/integrations/amazon-aws/lambda/) <br/>Collectors: <br/>- [Create a Sumo Lambda Function](/docs/send-data/collect-from-other-data-sources/create-amazon-lambda-function/) <br/>- [Collect AWS Lambda Logs using an Extension](/docs/send-data/collect-from-other-data-sources/collect-aws-lambda-logs-extension/) <br/>- [AWS Lambda Extension Performance Impact and Failover Handling](/docs/send-data/collect-from-other-data-sources/performance-impact-failover-handling/) <br/>Webhook: [Webhook Connection for AWS Lambda](/docs/alerts/webhook-connections/aws-lambda/) |
114114
| <img src={useBaseUrl('img/integrations/amazon-aws/network-firewall.png')} alt="Thumbnail icon" width="50"/> | [AWS Network Firewall](https://aws.amazon.com/network-firewall/) | App: [AWS Network Firewall](/docs/integrations/amazon-aws/network-firewall/) <br/>Automation integration: [AWS Network Firewall](/docs/platform-services/automation-service/app-central/integrations/aws-network-firewall/) <br/>Cloud SIEM integration: [Amazon AWS - Network Firewall](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/3a82061c-2ca3-4289-9c9b-78756001aa38.md) |
115115
| <img src={useBaseUrl('img/integrations/amazon-aws/networkLoadBalancer.png')} alt="Thumbnail icon" width="50"/> | [AWS Network Load Balancer](https://aws.amazon.com/elasticloadbalancing/network-load-balancer/) | App: [AWS Network Load Balancer](/docs/integrations/amazon-aws/network-load-balancer/) |
Lines changed: 109 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
1+
---
2+
id: aws-iam-users
3+
title: AWS IAM Users
4+
sidebar_label: AWS IAM Users
5+
description: The AWS IAM Users app for Sumo Logic helps monitor user activity and security within your AWS environment.
6+
---
7+
8+
import useBaseUrl from '@docusaurus/useBaseUrl';
9+
10+
<img src={useBaseUrl('img/integrations/misc/aws-iam-logo.png')} alt="logo" width="80" />
11+
12+
The Sumo Logic app for AWS IAM Users provides clear insights into user activity and security within your AWS environment. Its intuitive dashboard helps you monitor and analyze user data to strengthen security and support compliance. With powerful visualizations, security teams can track user behavior, detect anomalies, and spot unauthorized access attempts. The app also helps monitor permissions, enforce best practices, and improve overall user management. Stay secure and informed with real-time monitoring and actionable insights from the AWS IAM Users app on Sumo Logic.
13+
14+
## Log types
15+
16+
This app uses Sumo Logic’s [AWS IAM Users Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-iam-users-source/) to collect the users logs from the AWS IAM Users platform.
17+
18+
### Sample log messages
19+
20+
```json title="Users Log"
21+
{
22+
"Arn": "arn:aws:iam::987883700038:user/alice",
23+
"CreateDate": "2024-03-20T07:57:17Z",
24+
"Path": "/",
25+
"UserId": "AIDA522VHNHFBP4UFAXLG",
26+
"UserName": "alice",
27+
"PasswordLastUsed": "2025-08-11T04:48:52Z",
28+
"PermissionsBoundary": null,
29+
"Tags": null
30+
}
31+
```
32+
33+
### Sample queries
34+
35+
```sql title="Total Users"
36+
_sourceCategory="Labs/AWSIAMUsers"
37+
| json "UserId", "UserName", "CreateDate", "PasswordLastUsed", "PermissionsBoundary", "Arn" as user_id, user_name, create_date, password_last_used, permission_boundry, arn nodrop
38+
39+
// global filters
40+
| where user_name matches "{{user_name}}"
41+
42+
// panel specific
43+
| count by user_id
44+
| count
45+
```
46+
47+
```sql title="Never Logged Users"
48+
_sourceCategory="Labs/AWSIAMUsers"
49+
| json "UserId", "UserName", "CreateDate", "PasswordLastUsed", "PermissionsBoundary", "Arn" as user_id, user_name, create_date, password_last_used, permission_boundry, arn nodrop
50+
51+
// global filters
52+
| where user_name matches "{{user_name}}"
53+
54+
// panel specific
55+
| where isNull(password_last_used)
56+
| count by create_date, user_id, user_name
57+
| fields - _count
58+
| sort by create_date asc
59+
```
60+
61+
## Collection configuration and app installation
62+
63+
import CollectionConfiguration from '../../reuse/apps/collection-configuration.md';
64+
65+
<CollectionConfiguration/>
66+
67+
:::important
68+
Use the [Cloud-to-Cloud Integration for AWS IAM Users](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-iam-users-source/) to create the source and use the same source category while installing the app. By following these steps, you can ensure that your AWS IAM Users app is properly integrated and configured to collect and analyze your AWS IAM Users data.
69+
:::
70+
71+
### Create a new collector and install the app
72+
73+
import AppCollectionOPtion1 from '../../reuse/apps/app-collection-option-1.md';
74+
75+
<AppCollectionOPtion1/>
76+
77+
### Use an existing collector and install the app
78+
79+
import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md';
80+
81+
<AppCollectionOPtion2/>
82+
83+
### Use an existing source and install the app
84+
85+
import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
86+
87+
<AppCollectionOPtion3/>
88+
89+
## Viewing the AWS IAM Users dashboards​​
90+
91+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
92+
93+
<ViewDashboards/>
94+
95+
### Overview
96+
97+
The **AWS IAM Users - Overview** dashboard provides a clear view of user activity, status, and security within AWS IAM. It highlights key metrics such as total users, login trends, newly created accounts, and the status of active, inactive, or never-logged-in users. This centralized dashboard helps security teams monitor user activity, detect potential risks, and ensure compliance with IAM best practices—improving both security and operational efficiency.<br/><img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/AWS-IAM-Users/AWS+IAM+Users+-+Overview.png' alt="AWS IAM Users - Overview" />
98+
99+
## Upgrading the AWS IAM Users app (Optional)
100+
101+
import AppUpdate from '../../reuse/apps/app-update.md';
102+
103+
<AppUpdate/>
104+
105+
## Uninstalling the AWS IAM Users app (Optional)
106+
107+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
108+
109+
<AppUninstall/>

docs/integrations/saas-cloud/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,12 @@ Learn about the Sumo Logic apps for SaaS and Cloud applications.
7575
<p>Gain insights into Automox events and audit data to enhance security monitoring, streamline endpoint management, and boost operational resilience.</p>
7676
</div>
7777
</div>
78+
<div className="box smallbox card">
79+
<div className="container">
80+
<a href="/docs/integrations/saas-cloud/aws-iam-users"><img src={useBaseUrl('img/integrations/misc/aws-iam-logo.png')} alt="aws-iam-users-logo" width="60" /><h4>AWS IAM Users</h4></a>
81+
<p>Gain insights into AWS IAM Users events to enhance user activity and security within your AWS environment.</p>
82+
</div>
83+
</div>
7884
<div className="box smallbox card">
7985
<div className="container">
8086
<a href="/docs/integrations/saas-cloud/bitwarden"><img src={useBaseUrl('img/integrations/security-threat-detection/bitwarden.png')} alt="bitwarden-icon.png" width="100" /><h4>Bitwarden</h4></a>

sidebars.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2546,6 +2546,7 @@ integrations: [
25462546
'integrations/saas-cloud/asana',
25472547
'integrations/saas-cloud/atlassian',
25482548
'integrations/saas-cloud/automox',
2549+
'integrations/saas-cloud/aws-iam-users',
25492550
'integrations/saas-cloud/bitwarden',
25502551
'integrations/saas-cloud/box',
25512552
'integrations/saas-cloud/cato-networks',

0 commit comments

Comments
 (0)