Configure Audit Logs
Prisma Cloud by default uses the Amazon CloudTrail service to fetch the change events (ingest the audit logs). You can configure near real-time visibility in Prisma Cloud to ingest the audit logs using Amazon EventBridge on your onboarded AWS accounts.
Prisma Cloud config ingestion leverages EventBridge to reduce ingestion time of misconfigurations for the APIs which are supported by event-assisted ingestion (EAI). It makes the API call only if asset configuration has changed. However, the ingestion time for APIs that are not supported for EAI remains the same.
If you delete or disable your account, the associated EventBridge rules are correspondingly deleted or disabled in your AWS accounts and Prisma Cloud will not ingest audit logs or process audit logs policies.
Ingesting audit logs using EventBridge is only applicable for the management account enabled regions for all the member accounts that are part of the organization. If you individually disable a member account, specific rules for that member account are disabled.
When you run the CFT, Prisma Cloud creates rules in all accounts (including member) in only those regions where the management account is enabled.
If you delete EventBridge rules from your AWS accounts, Prisma Cloud will not ingest audit logs and will not process audit logs policies. There will also be a significant delay in processing config policies and generating the corresponding alerts.
If an AWS region does not support EventBridge, Prisma Cloud cannot support event-assisted ingestion for that region.
It is recommended to use EventBridge for faster ingestion. However, if you want to roll back to using CloudTrail, contact your Prisma Cloud customer support representative.
After you Onboard Your AWS Account or Onboard Your AWS Organization, select Settings > Providers > Cloud Accounts.
The steps to configure EventBridge are the same for your cloud account and organization. When you configure it for organization, make sure to run the CFT in the management account.
Click the View icon next to the AWS account or organization for which you want to ingest the audit logs using EventBridge.
Select Misconfigurations and click Configure under Near Real-Time Visibility.

Configure Details.
Click Download EventBridge CFT.

When you run the CFT, Prisma Cloud creates rules for all accounts (including member accounts) in only those regions where the management account is enabled.
If an error message displays when you click Download EventBridge CFT, you need to first Download IAM Role CFT and complete the required steps in your AWS console before continuing with EventBridge configuration.
If a region where you created EventBridge resources, is later disabled and you then want to update the EventBridge CloudFormation stack on AWS, the update fails due to AWS CloudFormation Service limitations. You must first delete the existing CloudFormation stack, Download EventBridge CFT, and then create a new stack with the newly downloaded CFT.
Log in to your AWS account and follow the steps to create a stack, select I acknowledge that AWS CloudFormation might create IAM resources with custom names, and click Create Stack.
Wait for status to display CREATE_COMPLETE.

Return to your Prisma Cloud console.
Click Next.
Review Status.
Review the status of the configuration. Once the template is run successfully on your account, a Successful message is displayed for each region and Prisma Cloud starts to ingest audit logs from Amazon EventBridge.

Click Save.
The corresponding EventBridge Rules are displayed in AWS.

Last updated
Was this helpful?

