Skip to content

Update README with AWS Config connector details and the #14507

Open
KanenasCS wants to merge 2 commits into
Azure:masterfrom
KanenasCS:patch-1
Open

Update README with AWS Config connector details and the #14507
KanenasCS wants to merge 2 commits into
Azure:masterfrom
KanenasCS:patch-1

Conversation

@KanenasCS

Copy link
Copy Markdown
Contributor

Added detailed configuration and troubleshooting steps for the Amazon Web Services Config Microsoft Sentinel Connector, including data flow, key limitations, post-deployment requirements, validation steps, and operational checklist.

Required items, please complete

Change(s):

  • Updated the README.md for the Amazon Web Services Config Microsoft Sentinel Connector.
  • Added detailed end-to-end data flow for the AWS Config CCF integration.
  • Added CloudFormation deployment guidance and post-deployment configuration steps.
  • Added AWS Config limitations, including regional deployment scope and SNS delivery channel requirements.
  • Added validation and troubleshooting commands for AWS Config, SNS, Lambda, DynamoDB, API Gateway, and Microsoft Sentinel.
  • Added Microsoft Sentinel validation queries for the AWSConfig_CL custom table.
  • Updated the AWS Config connector ARM metadata, including support details and connector icon.

Reason for Change(s):

  • To provide clear deployment, configuration, validation, and troubleshooting guidance for users deploying the AWS Config CCF connector.
  • To clarify the required AWS post-deployment steps, especially preserving the existing AWS Config S3 bucket and adding the SNS topic to the AWS Config delivery channel.
  • To help users validate the full ingestion pipeline from AWS Config to Microsoft Sentinel.
  • To improve connector metadata accuracy, including support information and icon branding.

Version Updated:

  • Yes.
  • Updated connector/content package versions.
  • No Detection or Analytic Rule template versions were updated, as this PR does not modify detections or analytic rule templates.

Testing Completed:

  • Yes.
  • Validated the AWS Config CCF connector flow in a Microsoft Sentinel test environment.
  • Confirmed AWS Config notifications are delivered through SNS to the Lambda ingest function.
  • Confirmed events are stored in DynamoDB.
  • Confirmed the API Gateway /logs endpoint returns events using the x-api-key header.
  • Confirmed Microsoft Sentinel connector configuration uses the correct API endpoint, API key, data type, and stream name.
  • Confirmed AWSConfig_CL receives data in Microsoft Sentinel.
  • Reviewed README.md content for deployment steps, troubleshooting commands, and operational checklist.

Checked that the validations are passing and have addressed any issues that are present:

  • Yes.
  • ARM/template changes and README.md updates were reviewed.
  • No KQL detection template changes were included in this PR.
  • No analytic rule template version update is required.

Added detailed configuration and troubleshooting steps for the Amazon Web Services Config Microsoft Sentinel Connector, including data flow, key limitations, and operational checklist.
@KanenasCS KanenasCS requested review from a team as code owners June 17, 2026 07:29
pdated the AWS Config connector metadata.
Updated the connector author to Konstantinos Lianos.
Updated the Supported by value to KanenasCS.
Added support email: konstantinos_lianos@hotmail.com.
Updated the connector icon to use the AWS logo: Logos/Aws.svg.
Updated the connector display/solution metadata to align with the AWS Config CCF connector branding.
Bumped the connector/content versions to refresh the Microsoft Sentinel connector metadata.
@v-atulyadav v-atulyadav added the Connector Connector specialty review needed label Jun 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Connector Connector specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants