Skip to content

This guide walks you through the steps to gather the necessary information and configure your AWS account for the purpose of creating an integration with Synqly's Network Security connector. AWS Network Security integrates Amazon VPC Flow Logs with Synqly.

Before you begin, ensure that you have:

Synqly can discover flow log configurations that deliver to CloudWatch Logs or S3. Traffic event queries are supported for CloudWatch Logs Insights and for S3 objects in text or gzip format. Kinesis Data Firehose destinations and S3 parquet delivery are not supported for traffic event queries.

Required Policy Actions

OperationRequired Policy Action(s)
Query Traffic Log Configurationsec2:DescribeFlowLogs
Resolve account contextsts:GetCallerIdentity
Query Traffic Events (CloudWatch Logs destination)logs:StartQuery logs:GetQueryResults
Query Traffic Events (S3 destination)s3:ListBucket s3:GetObject

If your flow logs only publish to CloudWatch Logs, the S3 actions are not required. If your flow logs only publish to S3, the CloudWatch Logs actions are not required. sts:GetCallerIdentity is required for all setups — the client uses it at initialization to resolve the account ID (including when building S3 flow log prefixes).

Example IAM Policy

Replace YOUR_ACCOUNT_ID, YOUR_FLOW_LOG_BUCKET, and any optional custom prefix to match your environment. Attach this policy (or an equivalent) to the IAM role or user you create in the credentials section below.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DiscoverVpcFlowLogs",
      "Effect": "Allow",
      "Action": ["ec2:DescribeFlowLogs"],
      "Resource": "*"
    },
    {
      "Sid": "ResolveCallerIdentity",
      "Effect": "Allow",
      "Action": ["sts:GetCallerIdentity"],
      "Resource": "*"
    },
    {
      "Sid": "QueryCloudWatchFlowLogs",
      "Effect": "Allow",
      "Action": [
        "logs:StartQuery",
        "logs:GetQueryResults"
      ],
      "Resource": "*"
    },
    {
      "Sid": "ListS3FlowLogPrefix",
      "Effect": "Allow",
      "Action": ["s3:ListBucket"],
      "Resource": "arn:aws:s3:::YOUR_FLOW_LOG_BUCKET",
      "Condition": {
        "StringLike": {
          "s3:prefix": [
            "AWSLogs/YOUR_ACCOUNT_ID/*",
            "OPTIONAL_CUSTOM_PREFIX/AWSLogs/YOUR_ACCOUNT_ID/*"
          ]
        }
      }
    },
    {
      "Sid": "ReadS3FlowLogObjects",
      "Effect": "Allow",
      "Action": ["s3:GetObject"],
      "Resource": [
        "arn:aws:s3:::YOUR_FLOW_LOG_BUCKET/AWSLogs/YOUR_ACCOUNT_ID/*",
        "arn:aws:s3:::YOUR_FLOW_LOG_BUCKET/OPTIONAL_CUSTOM_PREFIX/AWSLogs/YOUR_ACCOUNT_ID/*"
      ]
    }
  ]
}

AWS Credentials Configuration

Synqly supports two methods for authenticating with AWS: static credentials (IAM user access keys) and role-based access (IAM role assumption). Role-based access is recommended for production environments because it uses short-lived credentials and provides better auditability through CloudTrail.

Role-Based Access

Role-Based access is recommended and is considered an AWS best practice.

Role-based access uses AWS IAM roles to grant Synqly temporary credentials to access resources in your AWS account. This eliminates long-lived credentials and provides better security through the principle of least privilege.

1. Create an IAM Role

Create a role in your AWS account with a name that starts with SynqlyAccess (for example, SynqlyAccessS3Reader). This naming convention is required.

  1. In the AWS IAM console, go to Roles and choose Create role.
  2. For trusted entity type, choose Custom trust policy.
  3. Enter the following trust policy:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::733459310821:role/SynqlyIntegrationAccess"
      },
      "Action": "sts:AssumeRole",
      "Condition": {
        "StringEquals": {
          "sts:ExternalId": "YOUR_EXTERNAL_ID"
        }
      }
    }
  ]
}

Replace YOUR_EXTERNAL_ID with a unique identifier you generate (for example, a UUID). You will provide this External ID when configuring the integration.

  1. Name the role with a SynqlyAccess prefix (for example, SynqlyAccessMyIntegration).
  2. Attach the appropriate permissions policy for your use case.
  3. Create the role and note its ARN.

For more details, see:

External ID Requirements

The External ID is a security mechanism that prevents the confused deputy problem. It ensures that only authorized requests from Synqly can assume your role.

The External ID must contain only the following characters:

  • Alphanumeric characters (a-z, A-Z, 0-9)
  • Special characters: + = , . @ : / -
  • Must be between 2 and 1224 characters in length

Configuring the Integration Credentials

When creating an AWS integration in Synqly, provide the following configuration values based on your chosen authentication method.

Credential ParameterDescription
Role ARNThe ARN of the IAM role you created, for example arn:aws:iam::123456789012:role/SynqlyAccessMyIntegration. The role name must start with SynqlyAccess
External IDThe External ID you specified in the role's trust policy. This value must match exactly
Role Session NameOPTIONAL: A name for the role session. If not specified, Synqly generates a default session name
DurationOPTIONAL: The duration of the role session in seconds. The value can range from 900 seconds (15 minutes) up to the maximum session duration configured on your role (default is 1 hour)

Configure the Integration

Create your integration by supplying the following configuration values, in addition to the AWS credentials from the section above.

Integration ParameterDescription
RegionThe AWS region that contains the VPC Flow Logs to query. Example: us-east-1
Traffic Log Configuration IDs (optional)One or more VPC Flow Log IDs (fl-...). When omitted, all discoverable flow logs in the region are used