You can configure collecting Amazon S3 logs using a standard using a standard data source, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):
| Collection Method | Description |
| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard data source overview | Forward different types of logs to Cortex XSIAM from Amazon Simple Storage Service (Amazon S3) using the Amazon S3 data source. |
| Links to standard data source instructions | <p>The following types of logs can be ingested from Amazon S3:</p><ul><li><strong>Audit logs</strong>: See <a href="amazon-s3/ingest-audit-logs-from-aws-cloudtrail">Ingest audit logs from AWS Cloud Trail</a></li><li><strong>Flow logs</strong>: See <a href="amazon-s3/ingest-network-flow-logs-from-amazon-s3">Ingest network flow logs from Amazon S3</a></li><li><p><strong>Generic logs</strong>: See <a href="amazon-s3/ingest-generic-logs-from-amazon-s3">Ingest generic logs from Amazon S3</a></p><ul><li><strong>BeyondTust Privilege Management Cloud logs</strong>: See <a href="../beyondtrust/beyondtrust-privilege-management-cloud">BeyondTrust Privilege Management Cloud</a></li></ul></li><li><strong>Route 53 logs</strong>: See <a href="amazon-s3/ingest-network-route-53-logs-from-amazon-s3">Ingest network Route 53 logs from Amazon S3</a></li></ul><p>Configuring these types of Amazon S3 logs can include following these instructions:</p><ul><li><a href="amazon-s3/create-an-assumed-role">Create an assumed role</a></li><li><a href="amazon-s3/configure-data-collection-from-amazon-s3-manually">Configure data collection from Amazon S3 manually</a></li></ul> |
| Links to content pack/integration details (onboarded prior to July 26, 2026) | <ul><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSS3">AWS - S3</a> content pack provides integration with the Amazon Web Services Simple Storage Service (S3) for management, security controls, and visibility of stored objects. It includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---s3">AWS - S3</a>: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (<strong><code>aws-s3-get-bucket-encryption</code></strong>), controlling public access settings (<strong><code>aws-s3-put-public-access-block</code></strong>, <strong><code>aws-s3-get-public-access-block</code></strong>), and listing objects within a bucket, with support for pagination, delimiters, and prefixes (<strong><code>aws-s3-list-objects</code></strong>), alongside core support for authentication using AWS STS session tokens.</li></ul></li><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSRoute53">AWS - Route53</a> content pack provides an interface to manage the Amazon Web Services managed Cloud DNS service. It includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---route53">AWS - Route53</a>: Use this integration to manage the Amazon Web Services managed Cloud DNS service. Commands included allow users to list resource record sets, address issues such as when a set is missing its TTL value, and manage configurations related to AWS authentication like STS endpoint resolution logic.</li></ul></li><li><p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/AWSCloudTrail">AWS - CloudTrail</a> content pack provides functionality for interacting with an AWS CloudTrail trail via automation and includes rules for parsing and modeling ingested audit logs. It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/aws---cloud-trail">AWS - CloudTrail</a>: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using <strong><code>aws-cloudtrail-get-trail-status</code></strong>, and manage authentication configurations like specifying the AWS STS endpoint resolution logic.</li></ul></li></ul> |
| Link to connector (onboarded after July 26, 2026) | [AWS Automation and Collection](aws-automation-and-collection) |