For customers that run their infrastructure on AWS cloud and would like to ingest logs from various services into NetWitness for security and compliance, we have developed Amazon CloudWatch Plugin and S3 Universal Connector. For customers on NetWitness platform 11.5 or later these universal plugins alleviate the problem of managing multiple connectors, one for each service, faced by our customers.
Depending upon where in AWS the logs are being stored, customers can use either of Amazon CloudWatch or S3 Universal Connector to ingest logs into NetWitness. Both these plugins use same parsers to parse the logs and hence no difference is seen in meta selection.
Log types currently supported by amazoncloudwatch plugin and required parser are as shown. In addition to the below log types customers can collect any other log type and route them to a custom parser or get in touch with RSA customer service to add official support.
VPC Flow Logs
AWS Active Directory Logs
Similarly s3universal connector supported log types and the required parsers is as shown below. NetWitness will continue to add support for more AWS services based on customer request.