aws-networkfirewall-alert-flow-log-destination
Firewall alert and flow records can reveal application metadata and, depending on rule/log content, fragments of packet data.
Where it sits
| location | CloudWatch Logs/S3/Firehose Network Firewall log record |
| location kind | log_field |
| data kinds | credential api_key bearer_token customer_data pii sensitive_data |
| emits edge | ContainsSecret |
| service | Network Firewall (aws:networkfirewall) |
Collection recipe
| access mode | indirect_destination |
| operation | logs:FilterLogEvents or s3:GetObject |
| response path | log event message or object body |
| encoding | string |
| params | {"Destination": "\u003clogging-destination\u003e"} |
Required permissions
network-firewall:DescribeLoggingConfiguration
logs:FilterLogEvents
References