AWS Integration - Manual Configuration
Integrate Lacework with AWS to analyze CloudTrail activity and configuration compliance. This topic describes how to manually integrate Lacework with AWS.
Navigate to Manual Integration
- Log in to the Lacework Console.
- Go to Settings > Integrations > Cloud accounts.
- Click + Add New.
- Click Amazon Web Services and select Manual configuration.
- Click Next.
- Select an integration type and follow the steps that correspond to the integration type.
AWS Configuration
Ensure you have completed the preparatory steps described in AWS Config Integration Prerequisites.
- For Name, enter a unique name that displays in the Lacework Console.
- For Account ID, enter your AWS account identifier or alias.
- For External ID, copy the Lacework-generated external ID. You must use this external ID to replace the temporary one that you provided during cross-account role creation.
Refer to Update Cross-Account IAM Role External ID for how to update the cross-account role's external ID. - For Role ARN, enter the ARN of the cross-account role that Lacework uses to access your AWS resources.
- Click Save to finish the AWS integration and save your onboarding progress.
The integration appears in the list of cloud accounts under Cloud accounts.
AWS CloudTrail and Configuration
Ensure you have completed the preparatory steps described in AWS CloudTrail Integration Prerequisites.
- For Name, enter a unique name that displays in the Lacework Console.
- For Account ID, enter your AWS account identifier or alias.
- For External ID, copy the Lacework-generated external ID. You must use this external ID to replace the temporary one that you provided during cross-account role creation.
Refer to Update Cross-Account IAM Role External ID for how to update the cross-account role's external ID. - For Role ARN, enter the ARN of the cross-account role that Lacework uses to access your AWS resources.
- For SQSQueueURL, enter the Amazon Simple Queue Service (SQS) URL value.
- Click Save to finish the AWS integration and save your onboarding progress. The integration appears in the list of cloud accounts under Cloud accounts.