Wrangling the M365 UAL with SOF-ELK on EC2 (Part 2 of 3)
ID: fbe1ab9b-4157-507c-b95b-4d71198d39fa
STIX ID: report--fbe1ab9b-4157-507c-b95b-4d71198d39fa
Feed Name: Black Hills Infosec Blog
Part 2 of the “Wrangling the M365 UAL” series provides a practical guide to deploying SOF-ELK on AWS EC2 for scalable, collaborative analysis of Microsoft 365 Unified Audit Log data, walking through exporting a local VM to OVA, uploading to S3, creating IAM roles/policies, importing the image as an AMI via AWS CLI, launching and securing the instance with appropriate security groups, and confirming access to the web UI, with references to Part 1 and a preview of Part 3 on CSV formatting for SOF-ELK ingestion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
