Purpose
AWS SQS may be used to send any kind of data to Devo. If the data is already located in AWS, then SQS should be used to send it to Devo. The AWS SQS collector provides superior reliability, speed, security, and flexibility.
The AWS SQS collector is commonly used to secure services like WAF, VPC, Control Tower, and CloudTrail.
Send data to Devo
There are three requirements to send data to Devo with SQS.
Place data in an S3 bucket.
Authorize SQS data access.
Enable the collector with the service matching the data format.
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading ( |
|
Running environments |
|
Writes to |
|
Data sources
Data source | Security Purpose | Collector service name | Devo table |
---|---|---|---|
Any | The collector can be customized to process any data. Use a custom service only if there is no prebuilt service. | | All |
Cloud Resource Audit |
|
| |
Load Balancer |
|
| |
Load Balancer |
|
| |
DNS |
|
| |
Content Distribution |
|
| |
Content Distribution |
|
| |
AWS Audit |
|
| |
CLOUDTRAIL VIA KINESIS FIREHOSE | AWS Audit |
|
|
Instance Metrics |
|
| |
CLOUDWATCH VPC | Private Cloud Metrics |
|
|
In most cases, use the CloudTrail service instead. VPC Flow Logs, Cloudtrail, Cloudfront, and/or AWS config logs |
|
| |
deprecated |
|
|
|
Antivirus |
|
| |
Threat Detection |
|
| |
GUARD DUTY VIA KINESIS FIREHOUSE |
|
|
|
Content Delivery |
|
| |
Container and Cloud |
|
| |
Firewall |
|
| |
Domain Name Service |
|
| |
OPERATING SYSTEM | Windows and Unix events |
|
|
Endpoint Detections |
|
| |
S3 Bucket Audit |
|
| |
Deprecated in favor of CloudWatch VPC Logs |
|
| |
Firewall |
|
|