When you configure Amazon Web Services (AWS) Directory Service to send log data to USM Anywhere, you can use the AWS Directory Service plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:
|Device Type||Management Platform|
|Connection Type||Amazon CloudWatch|
Integrating AWS Directory Service
According to AWS documentation, AWS Directory Service provides multiple ways to set up Amazon Cloud Directory, Amazon Cognito, and Microsoft Active Directory (AD) with other AWS services. You can forward directory logs to Amazon CloudWatch Logs and then set up a scheduler job in USM Anywhere to collect them.
Follow the instructions on the AWS website to enable log forwarding in AWS Directory Service.
In USM Anywhere, you need to create a log collection job for CloudWatch and select the AWS Directory Service plugin. See Collecting Amazon CloudWatch Logs for details.
Available Plugin Fields
The following plugin fields are important attributes extracted from the syslog message. The USM Anywhere reports use these fields, and you can also reference them when creating custom reports. In addition to reporting, the USM Anywhere correlation rules make use of these fields.
Additional Resources and Troubleshooting
For troubleshooting, see the vendor documentation: