ODP has implemented Splunk SIEM and completed the onboarding of AWS Cloudtrail logs. However, customers do not have direct access to these logs. ODP is the only person who has visibility into these logs and we are dependent on them to notify us of any system outages.
It shouldn’t be too much effort to move those cloud trail logs from an Optimizely S3 bucket to a customer S3 bucket for ingest.
Any of the following additional methods would work:
HTTP Push
IBM MQ
Kafka Producer
MySQL
Oracle
PostgreSQL
SQL Server
JMS Fusion