Panther

View as Markdown

You can import runZero data into your Panther instance and use it in Panther logging and alerting.

Requirements

  • A Panther account with the required permissions
  • An AWS S3 bucket
  • Exported .jsonl files from runZero, uploaded to your AWS S3 bucket

Step 1: Adding a custom schema

  1. Go to Configure > Schemas and select Create New.
  2. Add a name.
  3. Upload a sample log, and Panther parses the runZero output schema from it.

Step 2: Adding a custom log source

  1. Go to Configure > Log Sources and select Create New.
  2. Complete the Basic Information section.
  3. Choose to configure S3 prefixes and schemas now, and select the custom schema you created.
  4. Configure the IAM role:
    • Choose Using the AWS Console UI.
    • Click Launch Console UI.
    • Review the stack in AWS, check the box to approve it, and deploy the stack.
    • When the deployment completes, open the Resources tab and select the new LogProcessingRole.
    • Copy the ARN from that role into the field on the Panther console.
  5. Optionally, configure an alarm that fires if logs are not processed.

From then on, Panther automatically ingests and processes any .jsonl files added to that AWS S3 bucket.

Updated