CloudWatch ASIM Parser

LS 10 Reputation points
2024-01-16T09:26:19.8533333+00:00

I have successfully connected AWS CloudWatch to Sentinel, and I am receiving events from multiple log groups. However, I am facing an issue with parsing the events, particularly with the 'Message' field that is in JSON format. Currently, the 'Message' field is parsed only when it contains a single JSON object; otherwise, it is not parsed. How can I resolve this to ensure that all data in the 'Message' fields is parsed? If I need to use ASIM (Azure Sentinel Integration Module), is there a pre-existing one that I can use, or do I need to create a new custom module?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
981 questions
{count} vote