-
Notifications
You must be signed in to change notification settings - Fork 229
Release note for AWS CloudTrail update #5471
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 1 commit
Commits
Show all changes
30 commits
Select commit
Hold shift + click to select a range
dedcf21
Release note for AWS CloudTrail update
amee-sumo 2c304fc
Update blog-service/2025-06-17-apps.md
amee-sumo 4f306a5
Update blog-service/2025-06-17-apps.md
amee-sumo 6b0abd7
Update blog-service/2025-06-17-apps.md
amee-sumo f45521f
Update blog-service/2025-06-17-apps.md
amee-sumo 7f9e1bb
Update blog-service/2025-06-17-apps.md
amee-sumo 9fbe7e1
Update blog-service/2025-06-17-apps.md
amee-sumo c90aca5
Update blog-service/2025-06-17-apps.md
amee-sumo f6c7e33
Update blog-service/2025-06-17-apps.md
amee-sumo 2b9ae2f
Update blog-service/2025-06-17-apps.md
amee-sumo ce3d9a6
Update blog-service/2025-06-17-apps.md
amee-sumo 1c0f063
Update blog-service/2025-06-17-apps.md
amee-sumo 2593b3d
Update blog-service/2025-06-17-apps.md
amee-sumo 8446859
Update blog-service/2025-06-17-apps.md
amee-sumo 5c5b8e6
Update blog-service/2025-06-17-apps.md
amee-sumo 6c77443
Update blog-service/2025-06-17-apps.md
amee-sumo 1d28a2b
Update blog-service/2025-06-17-apps.md
amee-sumo 32a5029
Update blog-service/2025-06-17-apps.md
amee-sumo b708cee
Update blog-service/2025-06-17-apps.md
amee-sumo 70e9cd4
Update blog-service/2025-06-17-apps.md
amee-sumo 7cc6827
Update blog-service/2025-06-17-apps.md
amee-sumo 0b804b4
Update blog-service/2025-06-17-apps.md
amee-sumo 23e0867
Update blog-service/2025-06-17-apps.md
amee-sumo cbf5c28
Update blog-service/2025-06-17-apps.md
amee-sumo 4fad1d6
Update blog-service/2025-06-17-apps.md
amee-sumo 3df8b0f
Update blog-service/2025-06-17-apps.md
amee-sumo 816b621
Update 2025-06-17-apps.md
amee-sumo 1533f79
Update blog-service/2025-06-17-apps.md
amee-sumo c455e46
Change release note date to June 16 2025
jpipkin1 57121c2
Merge branch 'main' into Release-note-for-AWS-CloudTrail
jpipkin1 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,70 @@ | ||
| --- | ||
| title: AWS CloudTrail (Apps) | ||
| image: https://help.sumologic.com/img/sumo-square.png | ||
| keywords: | ||
| - apps | ||
| - aws-cloudtrail | ||
| hide_table_of_contents: true | ||
| --- | ||
|
|
||
| import useBaseUrl from '@docusaurus/useBaseUrl'; | ||
|
|
||
| AWS is streamlining [CloudTrail](https://aws.amazon.com/cloudtrail/) events for [IAM Identity Center](https://aws.amazon.com/iam/identity-center/) by keeping only the essential fields needed for workflows like audit and incident response. These changes make it easier to identify users in IAM Identity Center CloudTrail events, based on customer feedback. They also improve the ability to match users between IAM Identity Center and external directories like Okta Universal Directory or Microsoft Active Directory. These updates do not impact CloudTrail events from other AWS services. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| To learn more, see [Important changes to CloudTrail events for AWS IAM Identity Center](https://aws.amazon.com/blogs/security/modifications-to-aws-cloudtrail-event-data-of-iam-identity-center/). | ||
|
|
||
| ### Impact and required actions for Sumo Logic users following AWS CloudTrail updates | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| #### Overview of required updates | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| AWS is updating CloudTrail events for IAM Identity Center, affecting how user identity data is structured. So, if you are using the updated fields in your Cloud SIEM content or across the Sumo Logic platform, you need to update any saved queries, dashboards, or detection rules to reflect these changes and ensure continued functionality. | ||
|
|
||
| **Key updates**: | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| - Sumo Logic-provided apps must be manually reinstalled to incorporate the updated event field mappings. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| - Cloud SIEM parsers have already been automatically updated and require no customer intervention. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| #### Action plan for Sumo Logic users | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| **Step 1: Reinstall relevant Sumo Logic apps** | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| To reinstall the apps, follow the steps below: | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| 1. Navigate to the **App Catalog**. | ||
| 1. Search for the relevant app. | ||
|
|
||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| If you're using any of the following apps that consume CloudTrail data, you must reinstall them: | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| - Amazon CloudTrail – Cloud Security Monitoring and Analytics | ||
| - AWS CloudTrail | ||
| - CIS AWS Foundations Benchmark | ||
| - PCI Compliance for AWS CloudTrail | ||
| - Threat Intel for AWS | ||
| - Cloud Infrastructure Security for AWS | ||
| :::info | ||
| These are v1 apps, and reinstalling them will create a new folder in your Content Library with updated dashboards that reflect the field structure changes. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| ::: | ||
| 3. Install to deploy updated content under a new folder. | ||
|
|
||
| **Step 2: Update custom saved searches and dashboards** | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| If you’ve created custom content based on CloudTrail fields, manual updates will be necessary to accommodate the new schema. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| **Field mapping changes** | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| | Fields | New Location | | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| |:--|:--| | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| | `UserName` | Added under `additionalEventData` | | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| | `principalId` | Removed | | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| | `userId`<br/>`identityStoreArn`<br/>`credentialId` | Added under `userIdentity` | | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| For more information on field changes, see [AWS Security Blog](https://aws.amazon.com/blogs/security/modifications-to-aws-cloudtrail-event-data-of-iam-identity-center/#:~:text=How%20to%20prepare%20your%20workflows%20for%20the%20upcoming%20changes%20to%20IAM%20Identity%20Center%20user%20identification%20in%20CloudTrail) | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| #### Timeline for implementation | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| AWS plans to implement these changes on [July 14, 2025](https://aws.amazon.com/blogs/security/modifications-to-aws-cloudtrail-event-data-of-iam-identity-center/#:~:text=Effective%20July%2014%2C%202025). | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| Sumo Logic apps are backward-compatible, so you can safely reinstall updated apps before the AWS changes go live. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| For any custom content outside of Sumo Logic’s managed apps or parsers, ensure your changes are backward compatible and deploy updates before July 14, 2025. | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| #### Consequences of not updating | ||
amee-sumo marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| Failure to update your apps, saved searches, or dashboards will result in user-related fields not being parsed correctly. Consequently, visualizations and panels relying on those fields will appear empty or display inaccurate data. | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.