User Docs
PlatformProduct updates
  • Getting started
    • What is DSPM?
    • Use DSPM in your company
    • Choose how to run DSPM
  • Quick start
  • Deployment guide
    • Sizing
    • Installation
      • Understand installation requirements
        • K3S installation
        • Configuring a HA K3s cluster
        • Configuring Rancher and Fleet agent to run behind an HTTP proxy
        • Install Synergy/Focus/Enterprise using Helm without Rancher
        • Install Synergy/Focus/Enterprise using Rancher
        • Air Gap Installation
        • Uploads to Rancher
      • Upgrade K3s
        • K3s - Upgrade
      • Troubleshooting
        • K3s on RHEL/CentOS/Oracle Linux
        • Networking
        • Configuring Rancher and Fleet agent to run behind a HTTP proxy if cluster was previously registered
    • Estimate hardware capacity needs
  • Administration guide
    • Customer Support Portal
    • Pattern matching
    • Data Controls
    • Analytics
    • Detectors
    • Import custom TLS certificate
    • GQL Quick Guide
    • Critical & Sensitive Classification Attribute Modification
    • How to Check AI Mesh Version
    • Webhooks
    • AI Mesh Overview
    • Is Customer Data Saved by Getvisibility?
  • Enterprise setup
    • Authentication
      • Keycloak configuration
      • Single Sign-on (SSO)
        • Using Azure AD as Keycloak Identity Provider
      • Keycloak User Federation Configuration (LDAP/AD)
      • Enable 2FA
      • Role-Based Access Control (RBAC)
      • Keycloak User Federation using LDAP over SSL
  • Implementation
    • Configuring Taxonomies & Labels
  • Integrations
    • GQL
    • Template Language
    • Multi-Language Machine Learning
    • SIEM Integration
    • Google Drive Auto-labelling
  • Scan with Getvisibility
    • Configure detectors
    • Configure data sources
      • Scan Configuration Fields
      • AWS IAM
      • AWS S3
      • Azure AD
      • Azure Blob
      • Azure Files
      • OneDrive
      • SharePoint Online
      • SharePoint on-premise
      • Box
      • Confluence Cloud
      • LDAP
      • SMB
      • Google IAM
      • Google Drive
      • ChatGPT
      • iManage
      • Dropbox
    • Scanning
      • Data Source Permissions
      • Scan Scheduler
      • Types of Scan
      • Scan History
      • Scan Analytics
      • Supported Languages for ML Classifiers
      • Rescan Files
    • Streaming
      • What is DDR?
      • How to Configure DDR Rules
      • Import Data Controls
      • Monitoring New Files via DDR Streaming
      • DDR Supported Events
      • Lineage
      • Supported Data Sources
      • Azure Blob Streaming Configuration
      • Azure Files Streaming Configuration
      • Confluence Cloud Streaming Configuration
      • Sharepoint Online Streaming Configuration
      • SMB Streaming Configuration
      • OneDrive Streaming Configuration
      • Azure AD Streaming Configuration
      • AWS S3 Streaming Configuration
      • Google Drive Streaming Configuration
      • Google IAM Streaming Configuration
      • AWS IAM Streaming Configuration
      • Box Streaming Configuration
      • Dropbox Streaming Configuration
    • Enterprise Search columns meaning
    • Supported File Types
  • Glossary
  • FAQ
  • EDC - All Documents
    • Deployment - Onboarding
      • EDC-Server Installation Guide
      • EDC-Deployment Flow Guide
        • EDC-installerConfig.json and CLI config Details
      • Deploying the agent using ManageEngine
      • EDC-Mac Agent - Installation Guide
      • Windows Agent Precheck Script
    • Functionality - Guides
      • EDC - Admin Guide - v4
      • EDC -Guide for writing Visual Labels
      • EDC- Guide for Header Footer Options
      • EDC-Metadata Details
      • EDC Supported File Types
      • Agent V4 - Configuration Options for Expert Mode
      • File Lineage - Agent Activities
      • Endpoint Data Discovery
    • Troubleshooting Documents
      • Preventing Users From Disabling Agent
      • Generate Installation Logs
      • Troubleshooting Agent for Windows
      • Guide for missing suggestions
      • Reseller Keycloak Quick Installation Guide
      • Alternative authentication methods for agent
  • EDC - All Documents
Powered by GitBook
On this page
  • Create a user
  • Configuring AWS IAM connector in Dashboard
  • Monitoring Real-Time Events

Was this helpful?

Export as PDF
  1. Scan with Getvisibility
  2. Streaming

AWS IAM Streaming Configuration

This guide provides steps on how to enable real-time data streaming for a AWS IAM connection and monitor streaming events within the Getvisibility platform.

PreviousGoogle IAM Streaming ConfigurationNextBox Streaming Configuration

Last updated 3 months ago

Was this helpful?

Create a policy

  • In the navigation pane on the left, choose Policies and then choose Create policy

  • In the Policy editor section, find the Select a service section, then choose IAM service, and select Next

  • In Actions allowed, choose the below actions to add to the policy:

    • GetPolicy

    • GetUserPolicy

    • ListUserPolicies

    • ListAttachedGroupPolicies

    • ListAttachedUserPolicies

    • ListGroups

    • ListUsers

    • ListGroupsForUser

    • PutRolePolicy

    • TagRole

    • GetGroup

    • GetRole

    • CreateRole

  • Choose SNS service and select the below actions:

    • CreateTopic,

    • DeleteTopic,

    • TagResource,

    • SetTopicAttributes,

    • Subscribe,

    • ConfirmSubscription

  • Choose Event Bridge service and select the below actions:

    • TagResource

    • PutTargets

    • EnableRule

    • PutRule

    • UntagResource

    • ListTargetsByRule

    • RemoveTargets

    • DeleteRule

  • Choose EC2 sercice and select the below action:

    • DescribeRegions

  • For Resources, choose All and select Create policy to save the new policy

Create a user

  • In the navigation pane on the left, choose Users and then choose Create user

  • On the Specify user details page, under User details, in User name, enter the name for the new user, example iam-connector-user and select Next

  • On the Set permissions page, select Attach policies directly and choose the policy created in above steps

  • Select Next

  • Once the user is created, select it, and from the user page, choose Create access key

  • Select Other then Next

  • Enter a description if you wish and select Create access key

  • The Access and Secret Access Keys have now been created. These can be downloaded as a CSV, and also copied from this section. NOTE: the secret access key cannot be viewed once you leave this page

Configuring AWS IAM connector in Dashboard

  • Navigate to Administration -> Data Sources -> AWS IAM ->Credentials - New credentials

  • Provide the access key and secret access key values generated in the above steps and select Save & Create Scan

  • Make sure the connection has a Name and Credentials set then click on Data streaming toggle and click Save & Close to finalize the changes

  • Clock icon: When data streaming is being activated, the "Requested" status will appear, indicating that the subscription is being processed. Once the subscription is activated, this status will change to "On".

  • After enabling Data Streaming, the system will automatically handle the subscription to AWS Iam’s real-time events. There is no need to manually configure Webhooks.

Monitoring Real-Time Events

After the subscription is activated, real-time events will start flowing into the platform, and can be monitored from the relevant parts of the platform.

Viewing Events in the Live Events Section

  1. Go to the Live Events section under Administration to view a detailed audit log of all streaming events.

  2. Filter by source to get only AWS IAM events

Monitoring Extended Streaming Events

Once extended streaming is enabled, events will be available for monitoring in multiple sections of the platform:

Live Events Section

  • Go to Live Events under Administration to view real-time extended events.

  • Use the filter options to narrow down events to only AWS IAM activities.

Sign in to the AWS Management Console and open the with the appropriate admin level account

IAM console