Amazon Detective adds support for EKS audit logs in Security Lake integration
Share
Services
Amazon Detective now supports retrieving Amazon Elastic Kubernetes Service (Amazon EKS) audit logs from Amazon Security Lake. With this launch, Detective customers leveraging the Security Lake integration can query and analyze Amazon EKS audit logs in addition to AWS CloudTrail and Amazon VPC Flow Logs. This enhancement enables more comprehensive investigations into potential security issues involving Amazon EKS workloads.
By integrating Amazon EKS audit logs, Detective provides security analysts with deeper visibility into Kubernetes API calls and activities within EKS clusters. Amazon Detective is a managed security service that simplifies the investigation process by building data aggregations, summaries, and visualizations based on security findings and activity logs. Alongside EKS support, Detective now supports [OCSF v1.1.0](https://aws.amazon.com/about-aws/whats-new/2024/02/amazon-security-lake-analytics-ocsf-iceberg/), enchancing query performance for your security analytics. This allows for more effective threat detection, incident response, and compliance auditing for containerized applications. The integration seamlessly surfaces relevant Amazon EKS logs during investigations, accelerating the analysis process without the need to switch between multiple tools.
This new capability is available in all AWS Regions where both Amazon Detective and Amazon Security Lake are available. For the list of supported Regions, refer to the [AWS Regional Services list](https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/).
To get started, visit the Detective console and enable the Security Lake integration. You can find guidance on querying Amazon EKS audit logs in the Amazon Detective User Guide. For more information about Amazon Detective, visit the [service page](https://aws.amazon.com/detective/).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share