Configure the Web Query Client Policy for AWS
Using the Client Policy Builder, you can create and modify policies for your Tenable Log Correlation Engine Web Query Client. The following steps are performed via the web interface on the Tenable Log Correlation Engine server that you configured your Tenable Log Correlation Engine Web Query Client to communicate with.
To configure the Web Query Client Policy for AWS:
Using the Client Policy Builder, create a policy for your Tenable Log Correlation Engine Web Query Client. This documentation includes a list of valid configuration items for the client policy.
A Web Query Client policy for AWS requires you to add an AWS CloudTrail endpoint to the policy. You must provide the following:
To add the endpoint:
- The User ID and secret key that was created when completing the prerequisite tasks.
In the Basic pane of the Client Policy Builder, click the button in to add a group.
The Add a new endpoint group window appears.
Click the Add AWS CloudTrail endpoint button.
A new AWS CloudTrail endpoint appears.
- In the Endpoint name box, enter a name that identifies the endpoint.
- Select the Active check box.
- In the Query interval box, enter the number of seconds between each query to the Salesforce API.
- In the Region box, enter the region defined in the AWS account.
- In the Access Key ID box, enter the Access Key ID for an IAM user.
In the Secret Access Key box, enter the IAM Secret Access Key that corresponds to the Access Key ID.
Note: You can add multiple endpoints to a single group. For example, one group could contain three AWS CloudTrail endpoints. Another group could contain a Salesforce endpoint, an AWS CloudTrail endpoint, and a Google Cloud endpoint.
- Assign the policy to the Tenable Log Correlation Engine Web Query Client.