Finding an S3 bucket name and directory prefix

An Amazon administrator must create a user and then apply the AmazonS3ReadOnlyAccess policy in the AWS Management Console. The QRadar user can then create a log source in QRadar.

Note: Alternatively, you can assign more granular permissions to the bucket. The minimum required permissions are s3:listBucket and s3:getObject.

For more information about permissions that are related to bucket operations, go to the AWS documentation website.

Procedure

  1. Click Services.
  2. From the list, select Config.
  3. From the Config page, click the name of the Config.
  4. Note the name of the S3 bucket that is displayed in the S3 bucket field.
  5. Click the Edit icon.
  6. Note the location path for the S3 bucket that is displayed underneath the Log file prefix field.