Connect WatchGuard Total MDR with AWS CloudTrail

Applies To: WatchGuard Total MDR

If you have a WatchGuard Total MDR license, to enable WatchGuard to monitor your AWS CloudTrail environment, you must complete the steps in this topic to set up an AWS CloudTrail connector and add the integration in the Managed Services portal.

To connect WatchGuard MDR and your AWS CloudTrail environment, complete these steps:

Run AWS CloudFormation Automation

CloudFormation automation uses AWS CloudFormation templates to automatically provision, configure, and manage AWS resources in a repeatable and consistent manner.

To run AWS CloudFormation automation:

  1. Download the CloudFormation Template.
  2. Go to the AWS Management Console at https://aws.amazon.com/ and log in with a root user for the account you want to monitor.

Screen shot of the AWS Manager Console search box page

  1. In the search box, type and select CloudFormation.
    The Cloud Formation dashboard opens.

Screen shot of the CloudFormation Stacks page

  1. From the Create Stack drop-down list, select With New Resources (Standard).
    The Create Stack page opens.

Screen shot of the CloudFormation Create Stack page

  1. In the Prerequisite - Prepare Template section, select Template Is Ready.

Screen shot of the Specify template section

  1. In the Specify Template section, select Upload a Template File.
    1. Click Choose File.
    2. Select the cloudtrail-config.yml file you downloaded in Step 1.
  2. Click Next.
    The Specify Stack Details page opens.

Screen shot of the Specify stack details page

  1. Enter a Stack Name.
    • To use an existing CloudTrail, from CloudTrailExists, select Yes. Type the name of the trail.
    • To create a new CloudTrail, from CloudTrailExists, select No. Type a name for the trail.
  2. Click Next.
    The Configure Stack Options page opens.

Screen shot of the configure stack options page

  1. Leave the default values for all options. Click Next.
    The Review page opens.

Screen shot of the review stack page

  1. Scroll to the Capabilities section.
  2. Select the I acknowledge that AWS CloudFormation might create IAM resources with custom names check box.
  3. Click Create Stack.
    When the automation is complete, a status message shows.

Screen shot of the automation process status page

Get AWS CloudTrail Values for MDR Integration

To connect WatchGuard MDR to your AWS CloudTrail environment, you must get some values from AWS to add to the Managed Services portal.

To find the required AWS values, from AWS CloudTrail:

  1. In the CloudFormation console, select the new stack you created in the Run AWS CloudFormation Automation section.
  2. Select the Outputs tab.
    The output keys show.

Screen shot of the stack outputs

  1. Copy the CloudTrailPrefix and CloudTrailS3Bucket values and save them to add to the Managed Services portal later.
  2. From the navigation menu, go to AWS Secrets Manager > Secrets.
    The Secrets page opens.

Screen shot of the AWS Secrets page

  1. Select aws-cloudtrail-user-iam-keys.

Screen shot of the AWS Secret value Overview tab

  1. Click Retrieve Secret Value.
  2. Copy these values and save them to add to the Managed Services portal later:
    • AWS Account ID
    • Access Key ID
    • Secret Access Key

Add the Integration in the Managed Services Portal

To add the AWS integration in the Managed Services portal, use the values you copied previously from AWS CloudTrail.

To add the AWS integration, from the Managed Services portal:

  1. In WatchGuard Cloud, select Monitor > Managed Services.

    The Managed Services portal opens in a new browser tab.
  2. If you are a Service Provider, select your Subscriber account from the drop-down list.
  3. In the upper, right corner of the Managed Services portal, click Screenshot of the gear icon.
  4. From the drop-down list, select Onboarding.
  5. From the navigation menu, select Integrations.
    The Integrations page opens.

Screen shot of MDR portal Cloud Integrations page

  1. Click Add Additional Service > AWS.
    The AWS tab opens.

Screen shot of MDR portal AWS integration settings

  1. In the Add an Integration section, enter the values you copied from your AWS account:
    • AWS Account ID
    • S3 Bucket Name
    • Prefix Path
    • Access Key ID
    • Secret Access Key
  2. (Optional) In the Label text box, type a unique name for the integration.
  3. Click Add.

As a security best practice, we recommend that you regularly rotate the IAM credentials. For best practices and steps, go to How to Rotate Access Keys for IAM Users in the AWS documentation.

Related Topics

About Managed Services with WatchGuard MDR