You can leverage your Amazon GuardDuty service within the AWS Sensor to translate the raw log data into normalized events for analysis.
Amazon GuardDuty service is automatically detected when a new AWS Sensor is deployed. However, it still needs to be enabled for USM Anywhere to receive information from it.
To enable Amazon GuardDuty for your AWS Sensor
- Go to Settings > Scheduler.
- Search for GuardDuty in the Job Scheduler Filter By field.
-
In the row for the GuardDuty job, click
icon.