Review AWS Events in Tenable.sc
To review AWS Events in Tenable.sc:
Navigate to Tenable.sc and log on with a user account that has permission to view logs for the organization.
A dashboard that corresponds to the user role appears.
In the top navigation bar, click Analysis, and then click the Events link.
The Event Analysis page appears, displaying the Type Summary section.
Click the Type Summary button, and then select Normalized Event Summary.
The Normalized Event Summary section appears.
In the upper-left corner of the page, click .
The Filters pane appears.
Click the Select Filters button
- In the Add Filter window, select Normalized Event.
Click the Apply button.
Click the Normalized Event box.
- In the Normalized Event window, type AWS-*.
In the Filters pane, click the Apply All button.
In the Normalized Event Summary section, the list of events is filtered and displays only events that start with AWS-.
The AWS events available will be based on the monitored activity logged by AWS CloudTrail. For a list of specific events, you can click an AWS event type (e. g., AWS-Console_Login) listed in the Normalized Event Summary section. You can also click the Jump to Raw Syslog Events link to directly view the log data.
At the top of the Event Analysis page, click the Normalized Event Summary button, and then select Detailed Event Summary.
The Detailed Event Summary section appears.
For a list of specific events, click an AWS event (e. g., ConsoleLogin) listed in the Detailed Event Summary section.