Configure Amazon GuardDuty for Arctic Wolf monitoring

You can configure Amazon GuardDuty® to send the necessary logs to Arctic Wolf® for security monitoring.

Amazon GuardDuty is a threat detection service that continuously monitors your AWS accounts and resources for unexpected and potentially malicious activity in your AWS environment. To integrate this service with Arctic Wolf Cloud Detection and Response (CDR), configure Amazon GuardDuty to forward its findings to Arctic Wolf.

Note:
  • By default, GuardDuty is integrated with AWS Security Hub. If you have Security Hub enabled or plan to enable Security Hub, see Configure AWS Security Hub for Arctic Wolf monitoring instead of this document.
  • GuardDuty is a chargeable service, based on the traffic and usage of your Amazon Web Services (AWS)® account. See GuardDuty pricing documentation before enabling this service.
  • Make sure to complete these steps for each region that you want to forward GuardDuty findings from.

These resources are required:

  • An AWS user or Identity and Access Management (IAM) role with AdministratorAccess or an equivalent IAM policy
  • Access to the AWS Management Console

These actions are required:

Determine if you have a delegated GuardDuty administrator account

Note: Delegated GuardDuty administrator accounts are region-specific.
  1. Sign in to the GuardDuty console.
  2. In the navigation menu, click Accounts.
    If you have a delegated GuardDuty administrator account, a banner displays with Your account is being managed by your GuardDuty administrator account with ID #.
    Note: If you do not have a delegated GuardDuty administrator account, contact your CST.
  3. Sign in to the GuardDuty console with that account and proceed to Determine if GuardDuty has been configured to export logs.

Determine if GuardDuty has been configured to export logs

  1. Sign in to the GuardDuty console with your delegated GuardDuty administrator account.
  2. In the navigation menu, click Settings.
  3. In the Findings export options section, in the S3 bucket section, if a bucket is:
    • Configured — Contact your CST.
    • Not configured — Determine if you have AWS Control Tower.
  4. If you: