How-To: Export your EZCMS Logs to CloudWatch

Learn how to monitor critical user actions by pushing the information to your CloudWatch SIEM.

Prerequisites

How To Export Your EZCMS Audit Logs To CloudWatch

How To Enable Log Export in EZCMS Portal

  1. Go to your EZCMS portal.

  2. Click on Settings.

    EZCMS Passwordless Onboarding portal showing Settings option highlighted in the left navigation sidebar

  3. Scroll down to SIEM Connection Settings and enable the Send Alerts to SIEM option.

    EZCMS Passwordless Onboarding SIEM Connection Settings panel with Send Alerts to SIEM checkbox highlighted in red

How To Configure CloudWatch Logs in the CloudWatch Portal

  1. Open your CloudWatch Portal in a new browser tab.

  2. In the top right corner, locate your AWS Region and make a note of it.

    CloudWatch region selection screenshot

  3. From the left-hand menu, under Setup, click on Settings.

    CloudWatch settings navigation screenshot

  4. Go to the Logs tab. In the API Keys section, click Create.

    CloudWatch Logs tab and API Keys section screenshot

  5. Choose your preferred API key expiration, then click Generate.

    CloudWatch API key generation screenshot

  6. After the key is generated, copy and save it immediately. You will not be able to view it again after leaving this page.

    CloudWatch API key save dialog screenshot

  7. Navigate to Log Management under Logs in the left-hand menu. Select the Log Group where you want to deliver your logs.

    CloudWatch log group selection screenshot

  8. Click the Actions dropdown, then select Edit bearer token authentication.

    CloudWatch bearer token authentication option screenshot

  9. When prompted, enable bearer token authentication by selecting Yes.

    CloudWatch enable bearer token authentication screenshot

  10. Confirm that bearer token authentication is enabled.

    CloudWatch bearer token authentication confirmation screenshot

  11. Identify and note the log stream where you want your logs delivered.

    CloudWatch log stream identification screenshot

How To Configure the CloudWatch SIEM in EZCMS Portal

  1. Now go back to the EZCMS Portal.

  2. Select CloudWatch as the SIEM Provider.

    Set CloudWatch as the SIEM in EZCMS

  3. Input the values that you copied from the CloudWatch portal. Then, click Test Connection. This will create a test log in your CloudWatch SIEM (please allow a few minutes for the log to show up in the CloudWatch portal).

    CloudWatch Paste Values and Test Connection

  4. If the connection test is successful, click Save Changes.

    EZCMS SIEM Settings Save Changes

  5. EZCMS will now send your security alerts to your SIEM. If an error occurs it will email your subscription administrators.