Connect WatchGuard MDR with AWS CloudTrail

Applies To: WatchGuard Total MDR, WatchGuard Open MDR

To enable WatchGuard to monitor your AWS CloudTrail environment, complete the steps in this topic to set up an AWS CloudTrail connector and add the integration in the Managed Services portal. You must have a WatchGuard Total MDR or WatchGuard Open MDR license.

To connect WatchGuard MDR to your AWS CloudTrail environment, complete these steps:

  1. Run AWS CloudFormation Automation
  2. Get AWS CloudTrail Values for MDR Integration
  3. Add the Integration in the Managed Services Portal

Run AWS CloudFormation Automation

CloudFormation automation uses AWS CloudFormation templates to automatically provision, configure, and manage AWS resources in a repeatable and consistent manner.

To run AWS CloudFormation automation:

  1. Download the CloudFormation Template (external link).
  2. Go to the AWS Management Console at https://aws.amazon.com/ and log in with a root user for the account you want to monitor.

Screenshot of the AWS Management Console search box page

  1. In the search box, type and select CloudFormation.
    The CloudFormation page opens.

Screenshot of the CloudFormation Stacks page

  1. From the Create Stack drop-down list, select With New Resources (Standard).
    The Create Stack page opens.

Screenshot of the CloudFormation Create Stack page

  1. In the Prerequisite - Prepare Template section, select Template Is Ready.

Screenshot of the Specify template section

  1. In the Specify Template section, select Upload a Template File.
    1. Click Choose File.
    2. Select the cloudtrail-config.YML file you downloaded in Step 1.
  2. Click Next.
    The Specify Stack Details page opens.

Screenshot of the Specify stack details page

  1. In the Stack Name text box, type a stack name.
    • To use an existing CloudTrail, from the CloudTrailExists drop-down list, select Yes. In the trail name text box, type the name of the trail.
    • To create a new CloudTrail, from the CloudTrailExists drop-down list, select No. In the trail name text box, type a name for the trail.
  2. Click Next.
    The Configure Stack Options page opens.

Screenshot of the Configure stack options page

  1. Leave the default values for all options, then click Next.
    The Review page opens.

Screenshot of the Review stack page

  1. Scroll to the Capabilities section.
  2. Select the I acknowledge that AWS CloudFormation might create IAM resources with custom names check box.
  3. Click Create Stack.
    When the automation completes, a status message appears.

Screenshot of the Automation process status page

Get AWS CloudTrail Values for MDR Integration

To connect WatchGuard MDR to your AWS CloudTrail environment, you must get some values from AWS to add to the Managed Services portal.

To find the required AWS values from AWS CloudTrail:

  1. In the CloudFormation console, select the new stack you created in the Run AWS CloudFormation Automation section.
  2. Select the Outputs tab.
    The output keys show.

Screenshot of the stack outputs

  1. From the Outputs tab, copy the complete CloudTrailPrefix value and save it to add to the Managed Services portal later.
  2. The path uses this format: AWSLogs/<AWS account ID>/CloudTrail/<AWS region>. For example: AWSLogs/111122223333/CloudTrail/us-east-1. The region folder is required. If you omit it, the connector test can fail with a bad request (HTTP 400) error.

  1. From the Outputs tab, copy the CloudTrailS3Bucket value and save it to add to the Managed Services portal later.
  2. From the navigation menu, select AWS Secrets Manager > Secrets.
    The Secrets page opens.

Screenshot of the AWS Secrets page

  1. Select aws-cloudtrail-user-iam-keys.

Screenshot of the AWS Secret value Overview tab

  1. Click Retrieve Secret Value.
  2. Copy these values and save them to add to the Managed Services portal later:
    • AWS Account ID
    • Access Key ID
    • Secret Access Key

Add the Integration in the Managed Services Portal

To add the AWS integration in the Managed Services portal, use the values you copied previously from AWS CloudTrail.

To add the AWS integration, from the Managed Services portal:

  1. In WatchGuard Cloud, select Monitor > Managed Services.
    The Managed Services portal opens in a new browser tab.
  2. If you are a Service Provider, select your Subscriber account from the drop-down list.
  3. In the upper-right corner of the Managed Services portal, click The gear icon.
  4. From the drop-down list, select Onboarding.
  5. From the navigation menu, select Integrations.
    The Integrations page opens.

Screenshot of Managed Services portal Cloud Integrations page

  1. Select Add Service > AWS.
    The AWS page opens.

Screenshot of Managed Services portal AWS integration settings

  1. Click Add Integration.
    The Add AWS Integration dialog box opens.

Screenshot of Managed Services portal AWS integration settings dialog box

  1. In the Label text box, type a name for the integration.
  2. In the corresponding text boxes, type the values you copied from your AWS account:
    • AWS Account ID
    • S3 Bucket NameCloudTrailS3Bucket from CloudFormation Outputs
    • Prefix Path — complete CloudTrailPrefix value from CloudFormation Outputs, including the AWS region folder
    • Access Key ID
    • Secret Access Key
  3. Click Submit.

If the connector test fails with a message such as Bad request, please check configuration - status_code : 400, verify that the Prefix Path value includes the full path from CloudTrailPrefix, including the AWS region folder at the end of the path.

As a security best practice, we recommend that you regularly rotate the IAM credentials. For best practices and steps, go to How to Rotate Access Keys for IAM Users in the AWS documentation (external link).

Related Topics

About Managed Services with WatchGuard MDR

About WatchGuard MDR Licenses