2.5 Analyzing, Normalizing & Correlating Security Logs

Key Takeaways

  • CloudWatch Logs Insights queries only CloudWatch Logs data, using the Logs Insights query language, OpenSearch PPL, or SQL, and charges by data scanned.

  • Amazon Athena queries CloudTrail, VPC Flow Logs, ALB, WAF, and Security Lake data in S3 with SQL; partition projection keeps investigations fast and inexpensive.

  • Security Hub CSPM insights group findings by an attribute such as resource or account to prioritize remediation.

  • Lambda functions, invoked through subscription filters or Firehose transformations, parse, enrich, and normalize logs, ideally to OCSF.

  • OpenSearch Service Security Analytics uses Sigma-rule detectors and correlation rules, and Amazon Managed Grafana provides shared dashboards with IAM Identity Center sign-in.

Last updated: September 2026

2.5 Analyzing, Normalizing & Correlating Security Logs

Collecting logs is only half of detection. SCS-C03 Skills 1.2.4 and 1.2.5 test whether you can query logs to answer an investigation question and normalize, parse, and correlate logs from different sources. The exam names CloudWatch Logs Insights, Amazon Athena, Security Hub findings, Amazon OpenSearch Service, AWS Lambda, and Amazon Managed Grafana. The skill is choosing the right tool for where the data lives, how fast you need answers, and who will look at them.


Choosing an Analysis Tool

ToolBest ForData LocationQuery Style
CloudWatch Logs InsightsFast, ad hoc queries on recent operational and security logsCloudWatch Logs log groupsLogs Insights query language, OpenSearch PPL, or SQL
Amazon AthenaLarge historical investigations on logs stored in Amazon S3S3 (CloudTrail, VPC Flow Logs, ALB, CloudFront, WAF logs, Security Lake)Standard SQL, pay per data scanned
Security Hub CSPM insightsGrouping and prioritizing findingsFindings from GuardDuty, Inspector, Macie, Config, and partnersFilters plus a group-by attribute
Amazon OpenSearch ServiceNear real-time search, dashboards, and correlation at scaleOpenSearch indexes, or direct query of S3, CloudWatch Logs, and Security LakeQuery DSL, PPL, SQL, Security Analytics detectors
AWS LambdaParsing, enriching, and normalizing records in flightSubscription filters, Firehose transformations, S3 eventsYour code
Amazon Managed GrafanaShared dashboards across many data sourcesCloudWatch, OpenSearch, Athena, Prometheus, and othersData source query editors

CloudWatch Logs Insights

Logs Insights runs interactive queries across one or more log groups, which makes it the fastest option when CloudTrail, VPC Flow Logs, Route 53 Resolver query logs, Lambda logs, or application logs already stream to CloudWatch Logs. Queries can be written in the Logs Insights query language, OpenSearch Piped Processing Language (PPL), or SQL. You pay for the data scanned, so narrow the time range and log groups first.

A typical investigation query finds which principals are generating access denials in a CloudTrail log group:

fields @timestamp, eventSource, eventName, userIdentity.arn, sourceIPAddress
| filter errorCode = "AccessDenied" or errorCode = "UnauthorizedOperation"
| stats count(*) as denials by userIdentity.arn, eventName
| sort denials desc
| limit 20

Useful features include saved queries, adding query results to CloudWatch dashboards, and the pattern command, which clusters similar log lines so unusual messages stand out. Logs Insights only sees data in CloudWatch Logs, so logs that go straight to S3 need Athena instead.


Amazon Athena for Logs in S3

Organization trails, VPC Flow Logs, ALB and CloudFront access logs, and AWS WAF logs commonly land in a central log archive bucket. Athena queries them in place with SQL. Two practices keep investigations fast and affordable:

  • Partition the tables (by account, Region, and date) and use partition projection, so a query for one day in one account doesn't scan years of logs.
  • Use workgroups to enforce an encrypted query-results location, per-query data-scan limits, and separate access for the security team.
SELECT eventtime, useridentity.arn, eventname, sourceipaddress
FROM cloudtrail_logs
WHERE eventsource = 'iam.amazonaws.com'
  AND eventname IN ('CreateAccessKey', 'AttachUserPolicy', 'PutUserPolicy')
  AND timestamp BETWEEN '2026/09/01' AND '2026/09/07'
ORDER BY eventtime;

Here timestamp is the partition column that CloudTrail's generated table uses. Amazon Security Lake stores normalized OCSF data in S3 and registers it in the AWS Glue Data Catalog, so a subscriber with query access can run the same kind of SQL across CloudTrail, VPC Flow Logs, Route 53, and Security Hub data at once.


Security Hub CSPM Findings as an Analysis Source

Security Hub CSPM collects findings from GuardDuty, Inspector, Macie, IAM Access Analyzer, AWS Config, and partner products. Insights group related findings by an attribute, such as resource ID or AWS account, so you can see, for example, which EC2 instances have the most critical findings. With cross-Region aggregation and a delegated administrator, one account can analyze findings for the whole organization. Findings also flow to Amazon EventBridge for automated response and can be sent to Security Lake for long-term SQL analysis.


Normalizing, Parsing & Correlating

Logs from different sources use different field names, time formats, and identifiers. Correlation needs a common shape.

  • OCSF normalization: Security Lake converts supported AWS sources to the Open Cybersecurity Schema Framework automatically. Custom sources must be written as OCSF records in Parquet format.
  • Lambda transformation: A CloudWatch Logs subscription filter can send events to Lambda, or an Amazon Data Firehose stream can invoke Lambda to transform records before delivery. Typical jobs include parsing an application's text log into JSON, converting timestamps to UTC, adding account names or asset owners, and mapping fields to OCSF. Send failed records to a dead-letter destination so parsing errors don't silently drop evidence.
  • Amazon OpenSearch Service: OpenSearch Ingestion pipelines load logs from S3, Security Lake, or HTTP sources. The Security Analytics feature applies detectors built from Sigma rules to log types such as CloudTrail, VPC Flow Logs, and DNS, and correlation rules link findings across log types (for example, a suspicious DNS query followed by an outbound connection from the same host). Direct query (zero-ETL) integrations can also query data in S3, CloudWatch Logs, and Security Lake without copying it into an index. Protect the domain with VPC access, fine-grained access control, and encryption.
  • Amazon Managed Grafana: A managed Grafana workspace builds shared dashboards over CloudWatch, OpenSearch, Athena, and other data sources. Users sign in through IAM Identity Center or SAML, and the workspace uses an IAM role to read each data source, so dashboards can span accounts without handing out console access.

Specialty Exam Pitfalls

  1. Choosing Logs Insights for data in S3: Logs Insights queries CloudWatch Logs only. For an organization trail delivered only to S3, use Athena or Security Lake.
  2. Unpartitioned Athena tables: Full-table scans over years of CloudTrail logs are slow and expensive; partition projection limits the scan.
  3. Correlating without normalization: Joining events on inconsistent field names or time zones produces false conclusions. Normalize to OCSF or a common schema first.
  4. Treating dashboards as detection: Grafana and OpenSearch dashboards show data; alerts, detectors, or EventBridge rules are what notify responders.
Loading diagram...
Security Log Analysis and Correlation Pipeline
Test Your Knowledge

An organization trail delivers CloudTrail logs only to a central Amazon S3 bucket in the log archive account. During an investigation, analysts must find every IAM CreateAccessKey call made in the past 18 months across 60 accounts, as cost-effectively as possible. Which approach should the security team use?

A

Run a CloudWatch Logs Insights query against the organization trail's log group.

B

Query the bucket with Amazon Athena using a CloudTrail table with partition projection, filtering on eventname and the date partition.

C

Download all log files to an EC2 instance and search them with grep.

D

Enable CloudTrail Insights on the trail and wait for an anomaly event.

Test Your Knowledge

A security team collects CloudTrail, VPC Flow Logs, and Route 53 Resolver query logs in Amazon OpenSearch Service. They want to be alerted when a host resolves a known malicious domain and then opens an outbound connection to an unusual IP address within minutes, using detection rules they can share with the wider community. Which OpenSearch capability fits best?

A

Index State Management policies that roll indexes over daily.

B

Cross-cluster replication to a second domain.

C

Security Analytics detectors using Sigma rules, combined with correlation rules that link findings across the DNS and flow log types.

D

UltraWarm storage for the DNS and flow log indexes.

Test Your Knowledge

An application writes free-text log lines to CloudWatch Logs. The security team wants each event parsed into JSON, its timestamp converted to UTC, and the owning team's name added before the records reach the security data lake. The solution must use managed services and minimal infrastructure. Which approach meets these requirements?

A

Create a CloudWatch Logs subscription filter that sends events to an Amazon Data Firehose stream with a Lambda transformation function, delivering the normalized records to the data lake.

B

Enable CloudTrail data events for the log group so CloudTrail parses the text automatically.

C

Configure a CloudWatch metric filter that rewrites each log line into JSON.

D

Export the log group to S3 once a month and fix the format manually.

Test Your Knowledge

A CISO wants a single set of dashboards that shows GuardDuty trends from CloudWatch, OpenSearch Service search results, and Athena query results from the log archive. Security analysts across the organization must sign in with their existing IAM Identity Center credentials and must not receive direct console access to the log archive account. Which service should the team deploy?

A

Amazon QuickSight with an IAM user for each analyst in the log archive account.

B

CloudWatch dashboards shared publicly with a URL.

C

An EC2 instance running self-managed Grafana with long-term access keys stored in its configuration.

D

An Amazon Managed Grafana workspace that authenticates users through IAM Identity Center and reads each data source through the workspace IAM role.

Sections you finish are checked off in the contents.