Automating AWS Cloud Onboarding
Consider these three options for configuring AWS VPC flow logs and onboarding them to Fusion as traffic sources:
1. Manual Onboarding (AWS Console and Fusion Console, aws CLI, and/or Single-Stack CloudFormation)
aws CLI, and/or Single-Stack CloudFormation)Follow step-by-step documentation on configuring AWS and Fusion to onboard each VPC.
Best For: Organizations with a small number of VPCs that rarely change or for an initial PoC.
Next Steps:
AWS VPC via S3 Setup (AWS Console method)
AWS VPC via S3 Setup (CloudFormation method)
2. Netography Cloud Onboarding Automation for AWS Organizations
Best For: Organizations that want a complete, supported, end-to-end solution for managing flow log configurations and onboarding to Fusion that can be deployed easily. If you are multi-cloud, have a large dynamic cloud environment, and/or also want to handle context enrichment or Route53 DNS ingest, this will save you a significant amount of time compared to options 1 or 2.
Next Steps:
E-mail [email protected] requesting access to the GitHub repo (providing your GitHub ID) or the latest release package.
3. Custom IaC Automation
Leverage your existing automation pipelines or scripts to:
• Deploy the IAM policy and custom role needed for Netography to read flow logs from S3 bucket(s) • Configure VPC Flow Logs on each VPC to write to the S3 bucket • Call the Fusion API to create a new Fusion traffic source for each VPC (or each account/region when using a centralized S3 log destination) with flow logs configured
Best For: Organizations experienced at developing IaC for AWS that already create VPCs and/or VPC flow log configurations through IaC and want to extend that to onboard the flow logs to Netography.
Next Steps:
Netography AWS Onboarding Guide for Cloud Automation Engineers
Last updated