Loading

Config

Version 3.6.0 (View all)
Compatible Kibana version(s) ~8.16.6
~8.17.4
8.18.0 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic

AWS Config provides a detailed view of the configuration of AWS resources in your AWS account. This includes how the resources are related to one another and how they were configured in the past so that you can see how the configurations and relationships change over time.

Use this integration to collect and parse data from your AWS Config APIs. Visualize that data in Kibana, create alerts to notify you if something goes wrong, and reference data when troubleshooting an issue.

Important

Extra AWS charges on API requests will be generated by this integration. Check API Requests for more details.

The AWS Config integration collects one type of data: logs.

Logs help you keep a record of the findings in AWS Config, allowing you to track and audit compliance status of your resources.

The AWS Config integration works by first retrieving all config rules using the DescribeConfigRules API. Then, for each specific config rule, the integration fetches its evaluation results using the GetComplianceDetailsByConfigRule API. These evaluation results enrich their respective config rules, ultimately producing a finding log.

See more details in the Logs reference.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ. Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

  • Elastic Agent must be installed
  • You can install only one Elastic Agent per host.
  • Elastic Agent is required to stream data from the REST API and ship the data to Elastic, where the events will then be processed via the integration's ingest pipelines.

Before using any AWS integration you will need:

  • AWS Credentials to connect with your AWS account.
  • AWS Permissions to make sure the user you're using to connect has permission to share the relevant data.

For more details about these requirements, please take a look at the AWS integration documentation.

Use this integration if you only need to collect data from the AWS Config service.

  1. Login to https://console.aws.amazon.com/.
  2. Go to https://console.aws.amazon.com/iam/ to access the IAM console.
  3. On the navigation menu, choose Users.
  4. Choose your IAM user name.
  5. Select Create access key from the Security Credentials tab.
  6. To see the new access key, choose Show.
  1. In Kibana navigate to Management > Integrations.
  2. In "Search for integrations" top bar, search for AWS Config.
  3. Select the "AWS Config" integration from the search results.
  4. Select "Add AWS Config" to add the integration.
  5. Add all the required integration configuration parameters, including the aws_region to enable data collection.
  6. Select "Save and continue" to save the integration.

Note

  1. For the current integration package, it is compulsory to add Secret Access Key and Access Key ID.
  2. The AWS Config integration performs a full ingestion of all findings during each interval.

This is the config dataset.

An example event for config looks as following:

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

OSZAR »