Skip to content

Commit 522ac28

Browse files
authored
Merge branch 'main' into Update-Cloudflare-app-with-Zone-scoped-datasets
2 parents c52b056 + 6f13eb3 commit 522ac28

File tree

26 files changed

+144
-49
lines changed

26 files changed

+144
-49
lines changed

blog-service/2023/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ Here are some of the key features the new solution offers:
5757
* **Misconfigurations**. See areas in your environment that need to be addressed because they fail best practice security controls.
5858
* **Suspicious activity assessment**. See suspicious activity across users, web interactions, networks, and Identity Access Management (IAM).
5959

60-
To learn how you can set up and use Cloud Infrastructure Security for AWS, and for preview limitations, check out our technical documentation [here](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
60+
To learn how you can set up and use Cloud Infrastructure Security for AWS, and for preview limitations, check out our technical documentation [here](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
6161

6262
:::note
6363
To use the solution, you are required to sign up and activate Amazon GuardDuty and AWS Security Hub.

blog-service/2024/12-31.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -401,7 +401,7 @@ You can now more easily configure sources on a simplified screen, allowing you t
401401

402402
<img src={useBaseUrl('img/integrations/amazon-aws/cis-for-aws-install-0.png')} alt="Configure Sources screen" style={{border: '1px solid gray'}} width="700"/>
403403

404-
[Learn more](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
404+
[Learn more](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
405405

406406
### October 21, 2024 (Apps)
407407

@@ -807,7 +807,7 @@ We're excited to announce increased visibility into your AWS Cloud environment w
807807

808808
This functionality is in preview. To participate, reach out to your Sumo Logic account executive.
809809

810-
[Learn more](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
810+
[Learn more](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
811811

812812
:::note
813813
As part of the preview, you can use CloudQuery logs with Cloud Infrastructure Security for AWS. To use the logs, configure the CloudQuery source when you deploy the solution.
@@ -1077,7 +1077,7 @@ Here are some of the key features the new solution offers:
10771077
* **Misconfigurations**. See areas in your environment that need to be addressed because they fail best practice security controls.
10781078
* **Suspicious activity assessment**. See suspicious activity across users, web interactions, networks, and Identity Access Management (IAM).
10791079

1080-
To learn how you can set up and use Cloud Infrastructure Security for AWS, check out our [technical documentation](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
1080+
To learn how you can set up and use Cloud Infrastructure Security for AWS, check out our [technical documentation](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
10811081

10821082

10831083
:::note Action Required

cid-redirects.json

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1794,7 +1794,7 @@
17941794
"/cid/1094": "/docs/dashboards/share-dashboard-outside-org",
17951795
"/cid/1095": "/docs/integrations/amazon-aws/cis-aws-foundations-benchmark",
17961796
"/cid/1096": "/docs/dashboards/explore-view",
1797-
"/cid/1097": "/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
1797+
"/cid/1097": "/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
17981798
"/cid/1100": "/docs/integrations/amazon-aws/vpc-flow-logs-pci-compliance",
17991799
"/cid/1101": "/docs/search/search-query-language/math-expressions/floor",
18001800
"/cid/1102": "/docs/search/search-query-language/math-expressions/ceil",
@@ -4152,15 +4152,18 @@
41524152
"/cid/-1": "/",
41534153
"/docs/api/beta": "/docs/api",
41544154
"/docs/api/dashboard-data": "/docs/api/dashboard",
4155-
"/docs/cloud-security-analytics": "/docs/security/cloud-infrastructure-security",
4156-
"/docs/cloud-security-analytics/introduction-to-cloud-security-analytics": "/docs/security/cloud-infrastructure-security/introduction",
4155+
"/docs/cloud-security-analytics": "/docs/security/additional-security-features/cloud-infrastructure-security",
4156+
"/docs/cloud-security-analytics/introduction-to-cloud-security-analytics": "/docs/security/additional-security-features/cloud-infrastructure-security/introduction",
41574157
"/docs/cloud-security-analytics/data-lake": "/docs/security/additional-security-features/data-lake",
41584158
"/docs/cloud-security-analytics/audit-and-compliance": "/docs/security/additional-security-features/audit-and-compliance",
41594159
"/docs/cloud-security-analytics/threat-detection-and-investigation": "/docs/security/additional-security-features/threat-detection-and-investigation",
41604160
"/docs/cloud-security-analytics/application-security": "/docs/security/additional-security-features/application-security",
4161-
"/docs/integrations/amazon-aws/cloud-infrastructure-security-for-aws": "/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
4162-
"/docs/cloud-infrastructure-security": "/docs/security/cloud-infrastructure-security",
4163-
"/docs/cloud-infrastructure-security/introduction-to-cloud-infrastructure-security": "/docs/security/cloud-infrastructure-security/introduction",
4161+
"/docs/integrations/amazon-aws/cloud-infrastructure-security-for-aws": "/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
4162+
"/docs/cloud-infrastructure-security": "/docs/security/additional-security-features/cloud-infrastructure-security",
4163+
"/docs/cloud-infrastructure-security/introduction-to-cloud-infrastructure-security": "/docs/security/additional-security-features/cloud-infrastructure-security/introduction",
4164+
"/docs/security/cloud-infrastructure-security": "/docs/security/additional-security-features/cloud-infrastructure-security",
4165+
"/docs/security/cloud-infrastructure-security/introduction": "/docs/security/additional-security-features/cloud-infrastructure-security/introduction",
4166+
"/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws": "/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
41644167
"/docs/cloud-infrastructure-security/data-lake": "/docs/security/additional-security-features/data-lake",
41654168
"/docs/cloud-infrastructure-security/audit-and-compliance": "/docs/security/additional-security-features/audit-and-compliance",
41664169
"/docs/cloud-infrastructure-security/threat-detection-and-investigation": "/docs/security/additional-security-features/threat-detection-and-investigation",

docs/integrations/amazon-aws/index.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -379,5 +379,12 @@ This guide has documentation for all of the apps that Sumo provides for Amazon a
379379
<h4><a href="/docs/integrations/amazon-aws/threat-intel">AWS Foundations Benchmark App</a></h4>
380380
<p>A guide to the Sumo Logic app for AWS Threat Intel.</p>
381381
</div>
382+
</div>
383+
<div className="box smallbox card">
384+
<div className="container">
385+
<img src={useBaseUrl('img/integrations/amazon-aws/cis-for-aws-logo.png')} alt="Thumbnail icon" width="50"/>
386+
<h4><a href="/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws">Cloud Infrastructure Security for AWS</a></h4>
387+
<p>A guide to our Cloud Infrastructure Security for AWS app.</p>
388+
</div>
382389
</div>
383390
</div>

docs/integrations/product-list/product-list-a-l.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
8181
| <img src={useBaseUrl('img/integrations/misc/automation-anywhere-logo.png')} alt="Thumbnail icon" width="50"/> | [Automation Anywhere](https://www.automationanywhere.com/) | Partner integration: [Automation Anywhere](https://docs.automationanywhere.com/bundle/enterprise-v2019/page/enterprise-cloud/topics/control-room/administration/settings/setting-up-sumo-logic.html) |
8282
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/automox.png')} alt="Thumbnail icon" width="100"/> | [Automox](https://www.automox.com/) | Automation integration: [Automox](/docs/platform-services/automation-service/app-central/integrations/automox/) <br/>Collector: [Automox Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source) |
8383
| <img src={useBaseUrl('img/integrations/saml/auth0.png')} alt="Thumbnail icon" width="50"/> | [Auth0](https://auth0.com/) | App: [Auth0](/docs/integrations/saml/auth0/) <br/>Cloud SIEM integration: [Auth0](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/f002a19c-876e-4a33-8be0-ed3b922d19bc.md) <br/>Collector: [Auth0 - Cloud SIEM](/docs/cse/ingestion/ingestion-sources-for-cloud-siem/auth0/) <br/>Partner integration: [Auth0](https://auth0.com/docs/customize/log-streams/sumo-logic-dashboard) |
84-
| <img src={useBaseUrl('https://upload.wikimedia.org/wikipedia/commons/9/93/Amazon_Web_Services_Logo.svg')} alt="Thumbnail icon" width="50"/> | [AWS](https://aws.amazon.com/) | Apps: <br/>- [Cloud Infrastructure Security for AWS](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws) <br/>- [Threat Intel for AWS](/docs/integrations/amazon-aws/threat-intel/) <br/>Cloud SIEM integration: [Amazon AWS - Trusted Advisor](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/99d21ed4-c3fb-452e-8e4a-a10ff4b94fe0.md) <br/>Community app: [Sumo Logic for AWS Health Events](https://github.com/SumoLogic/sumologic-content/tree/master/Amazon_Web_Services/AWS_Health) <br/>Also see [AWS Observability](/docs/observability/aws/). |
84+
| <img src={useBaseUrl('https://upload.wikimedia.org/wikipedia/commons/9/93/Amazon_Web_Services_Logo.svg')} alt="Thumbnail icon" width="50"/> | [AWS](https://aws.amazon.com/) | Apps: <br/>- [Cloud Infrastructure Security for AWS](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/) <br/>- [Threat Intel for AWS](/docs/integrations/amazon-aws/threat-intel/) <br/>Cloud SIEM integration: [Amazon AWS - Trusted Advisor](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/99d21ed4-c3fb-452e-8e4a-a10ff4b94fe0.md) <br/>Community app: [Sumo Logic for AWS Health Events](https://github.com/SumoLogic/sumologic-content/tree/master/Amazon_Web_Services/AWS_Health) <br/>Also see [AWS Observability](/docs/observability/aws/). |
8585
| <img src={useBaseUrl('img/integrations/amazon-aws/aws-amplify-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS Amplify](https://aws.amazon.com/amplify/) | App: [AWS Amplify](/docs/integrations/amazon-aws/aws-amplify/) |
8686
| <img src={useBaseUrl('img/integrations/amazon-aws/AWS_API_Gateway.png')} alt="Thumbnail icon" width="50"/> | [AWS API Gateway](https://aws.amazon.com/api-gateway/) | App: [AWS API Gateway](/docs/integrations/amazon-aws/api-gateway/) <br/>Cloud SIEM integration: [Amazon AWS - API Gateway](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/products/9f76f1fd-fbb0-42d2-9bf5-0f4fd2c1ab82.md) |
8787
| <img src={useBaseUrl('img/integrations/amazon-aws/aws-apprunner-logo.png')} alt="Thumbnail icon" width="50"/> | [AWS App Runner](https://aws.amazon.com/apprunner/) | App: [AWS App Runner](/docs/integrations/amazon-aws/aws-apprunner/) |

docs/integrations/security-threat-detection/f5-big-ip-ltm.md

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,6 +112,24 @@ Now, using telemetry, we will define a [Sumo Logic sink](https://clouddocs.f5.co
112112
```bash
113113
curl -k --user admin:<BIGIP PWD> -H "Accept: application/json" -H "Content-Type:application/json" -X POST [email protected] https://<BIG-IP IP>:<PORT>3/mgmt/shared/telemetry/declare | python -m json.tool
114114
```
115+
:::note
116+
Contact F5 support team if the above curl commands return an error.
117+
:::
118+
119+
To begin collecting telemetry, the logging profiles (LTM and ASM) created by AS3 in [step 2](#step-2-use-as3-declarative-language-to-define-a-logging-profile-on-big-ip) need to be assigned to the BIG-IP virtual server(s).
120+
121+
Follow the below steps to associate LTM logging profile:
122+
123+
1. From the BIG-IP console UI, navigate to **Local Traffic** > **Virtual Servers** > **Virtual Server List**.<br/> <img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/F5+BIG-IP+Local+Traffic+Manager/step1.png')} alt="console UI" style={{border: '1px solid gray'}} width="500" />
124+
1. Select and open the virtual server(s) to update their properties. In the **Configuration** dropdown, change the virtual server configuration setting from **Basic** to **Advanced** to expose the logging properties.<br/> <img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/F5+BIG-IP+Local+Traffic+Manager/step2.png')} alt="server config" style={{border: '1px solid gray'}} width="500" />
125+
1. In the **Request Logging Profile**, select the previously created LTM logging profile to the virtual server(s).<br/> <img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/F5+BIG-IP+Local+Traffic+Manager/step3.png')} alt="assign LTM logging profile" style={{border: '1px solid gray'}} width="500" />
126+
1. Click **Update** to save the changes.
127+
128+
Follow the below steps to associate ASM logging profile:
129+
130+
1. After assigning the LTM logging profile to the virtual server, navigate to the **Security** tab and select **Policies** to access the virtual server’s security policy settings.<br/> <img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/F5+BIG-IP+Local+Traffic+Manager/step5.png')} alt="security" style={{border: '1px solid gray'}} width="500" />
131+
1. In the **Log Profile**, enable logging and assign the previously created ASM logging profile. <br/> <img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/F5+BIG-IP+Local+Traffic+Manager/step6.png')} alt="assign ASM logging profil" style={{border: '1px solid gray'}} width="500" />
132+
1. Click **Update** to save the configuration changes.
115133

116134
## Installing the F5 - BIG-IP LTM app
117135

@@ -188,4 +206,4 @@ import AppUpdate from '../../reuse/apps/app-update.md';
188206

189207
import AppUninstall from '../../reuse/apps/app-uninstall.md';
190208

191-
<AppUninstall/>
209+
<AppUninstall/>

docs/manage/manage-subscription/fedramp-capabilities.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ The following table shows the capabilities included with Sumo Logic’s FedRAMP
2020
| Abilities - Platform | [Training: Learn and certification](/docs/get-started/training-certification-faq/) |![check](/img/reuse/check.png)|![check](/img/reuse/check.png)|
2121
| Abilities - Solutions | [Application observability](/docs/observability/application-components/) |![check](/img/reuse/check.png)|![x](/img/reuse/x.png)|
2222
| Abilities - Solutions | [AWS observability](/docs/observability/aws/) |![check](/img/reuse/check.png)|![x](/img/reuse/x.png)|
23-
| Abilities - Solutions | [Cloud Infrastructure Security](/docs/security/cloud-infrastructure-security) |![check](/img/reuse/check.png)|![check](/img/reuse/check.png)|
23+
| Abilities - Solutions | [Logs for Security](/docs/security/additional-security-features/) |![check](/img/reuse/check.png)|![check](/img/reuse/check.png)|
2424
| Abilities - Solutions | [Cloud SIEM](/docs/cse/) |![check](/img/reuse/check.png)|![check](/img/reuse/check.png)|
2525
| Abilities - Solutions | [Cloud SOAR](/docs/cloud-soar/) / [Automation Service](/docs/platform-services/automation-service/) |![check](/img/reuse/check.png)|![x](/img/reuse/x.png)
2626
| Abilities - Solutions | [Software Development Optimization](/docs/observability/sdo/) |![check](/img/reuse/check.png)|![x](/img/reuse/x.png)|

docs/reuse/cis-note.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
:::tip
2-
To enable apps to perform security monitoring of your cloud infrastructure, see [Cloud Infrastructure Security](/docs/security/cloud-infrastructure-security/).
2+
To enable apps to perform security monitoring of your cloud infrastructure, see [Cloud Infrastructure Security](/docs/security/additional-security-features/cloud-infrastructure-security/).
33
:::

docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws.md renamed to docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import Iframe from 'react-iframe';
99

1010
<img src={useBaseUrl('img/integrations/amazon-aws/cis-for-aws-logo.png')} alt="Cloud Infrastructure Security for AWS logo" width="70"/>
1111

12-
Cloud Infrastructure Security for AWS provides a unified view of risks, misconfigurations, and active threats in your AWS infrastructure spanning multiple AWS accounts and regions. The solution leverages native AWS tools and telemetry to accelerate cloud security outcomes.
12+
The Cloud Infrastructure Security for AWS app provides a unified view of risks, misconfigurations, and active threats in your AWS infrastructure spanning multiple AWS accounts and regions. The solution leverages native AWS tools and telemetry to accelerate cloud security outcomes.
1313

1414
Key features of the solution include:
1515
* **Risk overview**. See a summary of all resources that pose risks, and get an action plan for addressing the most important areas of concern.
@@ -189,7 +189,7 @@ When you deploy the solution, consider the following.
189189

190190
#### Do you already have the required sources? 
191191

192-
When you deploy, you are given the option to create the Sumo Logic sources that the solution applications rely upon. If you have already configured those sources, you do not have to create new ones. You can just provide the URLs of the relevant Sumo Logic sources as part of the configuration. See [Install Cloud Infrastructure Security for AWS](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/#install-cloud-infrastructure-security-for-aws) below.
192+
When you deploy, you are given the option to create the Sumo Logic sources that the solution applications rely upon. If you have already configured those sources, you do not have to create new ones. You can just provide the URLs of the relevant Sumo Logic sources as part of the configuration. See [Install Cloud Infrastructure Security for AWS](#install-cloud-infrastructure-security-for-aws) below.
193193

194194
:::note
195195
If you use existing sources rather than create new ones, it is not necessary to modify the existing metadata and source categories associated with the sources. The metadata that the solution depends on will be added to the sources at deployment time. 
@@ -205,7 +205,7 @@ You can deploy Cloud Infrastructure Security to a single account or all accounts
205205

206206
#### Multi-region enablement
207207

208-
Cloud Infrastructure Security supports collecting data from multiple regions if you have any of the following services running in multiple regions in your AWS infrastructure. You can enable multiple regions when you perform the steps in the [Create new source: Deploy AWS](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/#create-new-source-deploy-aws) section below.
208+
Cloud Infrastructure Security supports collecting data from multiple regions if you have any of the following services running in multiple regions in your AWS infrastructure. You can enable multiple regions when you perform the steps in the [Create new source: Deploy AWS](#create-new-source-deploy-aws) section below.
209209

210210
##### GuardDuty
211211

@@ -570,7 +570,7 @@ Following are saved searches included with the solution:
570570

571571
## Cloud Infrastructure Security for AWS dashboards​
572572

573-
import FilterDashboards from '../../reuse/filter-dashboards.md';
573+
import FilterDashboards from '../../../reuse/filter-dashboards.md';
574574

575575
<FilterDashboards/>
576576

0 commit comments

Comments
 (0)