For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Amazon S3

Use Amazon S3 data in Cortex Cloud.

You can configure collecting Amazon S3 logs using a standard data source or content pack integration (onboarded prior to July 26, 2026):

Amazon S3 vendor
Description

Standard data source overview

Forward different types of logs to Cortex Cloud from Amazon Simple Storage Service (Amazon S3) using the Amazon S3 data source.

Links to standard data source instructions

The following types of logs can be ingested from Amazon S3:

Configuring these types of Amazon S3 logs can include following these instructions:

Links to content pack/integration details (onboarded prior to July 26, 2026)

  • The AWS - S3 content pack provides integration with the Amazon Web Services Simple Storage Service (S3) for management, security controls, and visibility of stored objects. It includes the following integration:

    • AWS - S3: Use this integration to manage Amazon Web Services Simple Storage Service (S3) objects and security configurations, including listing contents, setting encryption, and blocking public access. Commands are included for fetching bucket encryption status (aws-s3-get-bucket-encryption), controlling public access settings (aws-s3-put-public-access-block, aws-s3-get-public-access-block), and listing objects within a bucket, with support for pagination, delimiters, and prefixes (aws-s3-list-objects), alongside core support for authentication using AWS STS session tokens.

  • The AWS - Route53 content pack provides an interface to manage the Amazon Web Services managed Cloud DNS service. It includes the following integration:

    • AWS - Route53: Use this integration to manage the Amazon Web Services managed Cloud DNS service. Commands included allow users to list resource record sets, address issues such as when a set is missing its TTL value, and manage configurations related to AWS authentication like STS endpoint resolution logic.

  • The AWS - CloudTrail content pack provides functionality for interacting with an AWS CloudTrail trail via automation and includes rules for parsing and modeling ingested audit logs. It also includes the following integration:

    • AWS - CloudTrail: Use this integration to interact with a CloudTrail trail on AWS via playbooks and the Playground. It includes commands that enable retrieving information about the trail status using aws-cloudtrail-get-trail-status, and manage authentication configurations like specifying the AWS STS endpoint resolution logic.

Last updated

Was this helpful?