Parsing Logs and Events with AWS Native Tools
The previous chapter showed you how the CloudWatch service can help collect and store logs from a myriad of services in AWS. You are now ready to turn your attention to the most cost-effective ways to retain those log files for long-term storage, along with the methods to pull out the necessary data from them.
One of the critical duties of a security professional is to assimilate all the information coming in from different sources and distinguish the relevant bits of information from that which is just noise. Services and applications in any environment (not just the cloud) constantly produce logs. Knowing which services and techniques can gather, collect, and then help you quickly sift through and analyze these logs is an essential skill for real-life situations as well as for the AWS Security competency exam.
Several services can help you with this task. This chapter will cover such services, including storing logs on the S3 storage...