Platform logging integration with Cortex XSIAM
Introduction
The Modernisation Platform shares data with the Security Operations Cortex XSIAM application for the purpose of protective monitoring.
Categories of data shared with Security Operations
The following data is collected for Cortex XSIAM consumption:
CloudTrail logs aggregated from all Modernisation Platform accounts in the
core-loggingaccountAWS Config logs aggregated from all Modernisation Platform accounts are stored centrally in the
core-loggingaccount.Network Firewall
"Alert"Logs based incore-network-servicesRoute53 Resolver Query Logs for
live_dataVPCs based incore-*accountsVPC Flow Logs
- for the
external_inspectionVPC based incore-network-services - for
live_dataVPCs based incore-*accounts
- for the
SecurityHub, GuardDuty and Inspector findings from all MoJ AWS accounts aggregated in the
organisation-securityaccountOrganizations data based in the
moj-masteraccount
Log delivery methods
S3
- VPC Flow Log data is pulled from the
core-logging-vpc-flow-logsS3 bucket in thecore-loggingaccount. - Route 53 Resolver Query Log data is pulled from the
core-logging-r53-resolver-logsS3 bucket in thecore-loggingaccount. - Cloudtrail log data is pulled from the
modernisation-platform-logs-cloudtrailS3 bucket in thecore-loggingaccount. - AWS Config log data is pulled from the
modernisation-platform-logs-configS3 bucket in thecore-loggingaccount.
Data Firehose
- The Cortex XSIAM application receives Network Firewall
alertlogs by way of an Amazon Data Firehose configured in thecore-network-servicesaccount.
IAM Users
XsoarIntegrationandXsiamIntegrationIAM users based in themoj-masterandorganisation-securityaccounts to enable the AWS Organizations and AWS Security Hub Event Collector integrations
IAM Role/CloudFormation
- Cloud Inventory Data is shared with Xsiam using roles deployed into each AWS account in the organization using a CloudFormation StackSet based in the
organisation-securityaccount
Known Contacts:
Vinnie Burtonshaw - Vincent.Burtonshaw@justice.gov.uk. Implements the Cortex Xsiam endpoints that receive the Firehose transfers. (https://www.paloaltonetworks.com/cortex/cortex-xsiam)
The Protective Monitoring Team who will be managing the Cortex Xsiam platform going forward - monitoring-and-integration-platform@justice.gov.uk