What is function of Download GeoIP lambda and GeoIP S3 bucket?

0

https://aws.amazon.com/blogs/security/how-to-use-aws-security-hub-and-amazon-opensearch-service-for-siem/

I was going through below blogpost where Opensearch can be used as SiEM tool. I want to understand what the role of Download GeoIp lambda and GeoIP s3 bucket?

1 Answer
1

The Download GeoIP lambda function is used for downloading GeoIPs from MaxMind and then GeoIP S3 bucket is used for storing the downloaded GeoIPs.

When you view/analyze logs in OpenSearch dashboard, you can add country information as well as latitude/longitude location information to each IP address. To get location information, SIEM on OpenSearch Service downloads and uses GeoLite2 Free by MaxMind. If you want to add location information, get your free license from MaxMind.

Refer to the following for more information:

profile picture
joahna
answered a year ago
profile picture
EXPERT
reviewed a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions