Panther
You can import runZero data into your Panther instance and use it in Panther logging and alerting.
Requirements
- A Panther account with the required permissions
- An AWS S3 bucket
- Exported .jsonl files from runZero, uploaded to your AWS S3 bucket
Step 1: Adding a custom schema
- Go to Configure > Schemas and select Create New.
- Add a name.
- Upload a sample log, and Panther parses the runZero output schema from it.
Step 2: Adding a custom log source
- Go to Configure > Log Sources and select Create New.
- Complete the Basic Information section.
- Choose to configure S3 prefixes and schemas now, and select the custom schema you created.
- Configure the IAM role:
- Choose Using the AWS Console UI.
- Click Launch Console UI.
- Review the stack in AWS, check the box to approve it, and deploy the stack.
- When the deployment completes, open the Resources tab and select the new LogProcessingRole.
- Copy the ARN from that role into the field on the Panther console.
- Optionally, configure an alarm that fires if logs are not processed.
From then on, Panther automatically ingests and processes any .jsonl files added to that AWS S3 bucket.
Updated