If you want to collect AWS Config logs from Amazon S3 buckets, configure a log source on
the QRadar
Console so that AWS Config can
communicate with QRadar by
using the Amazon AWS S3 REST API protocol.
Procedure
- If automatic updates are not enabled, download and install the most recent version of the
following RPMs from the IBM Support Website onto your QRadar
Console.
- Protocol Common RPM
- Amazon AWS S3 REST API Protocol RPM
- DSM Common RPM
- Amazon Web Service RPM
- AWS Config DSM RPM
- Select a method to configure an AWS Config log source by using the Amazon AWS S3 REST API
protocol.
- Select one of the following methods to configure an AWS Config log source by using the
Amazon AWS S3 REST API protocol.