# Setup CDR for AWS CFT
## Overview
This lab will walk though setting up CloudTrail in a AWS.  Then enabling the Trail as a DfAWS Data Source for CDR.
For this lab SEs should use their personal AWS account NOT the Vectra TME demo accounts!  
## Notes 
- In some cases an existing Trail can be used
- A max of 5 Trails can be setup per AWS region
- The Trail should be enabled at the org level
- The first Trail is free
- Anywhere you see *initials* your initials should be used as the value 
##  Setting up first Trail
1.  Logon to AWS Management Console ([Web UI](https://aws.amazon.com/)).
2.  In the search at the top right type **trails**, then Click **Trails**.
    
3.  Once at the **Trails** page, click **Create Trail** on the top right.
    
4.  On the **Create Trail Attributes** page fill in the following values, and click **Next**:
      
    - **Trail name** - gts2022-*initials*
    - **Storage location** -  Create new S3 bucket
    - **Trail log bucket and folder** - gts2022-cloudtrail-*initials*
    - **Log file SSE-KMS encryption** - Uncheck
    - All other fields should be left at defaults
    
    
    
    
    
5.  On the **Choose log events** page fill in the following values, and click **Next**:
    - **Events**
        - **Management events** - Checked
        - **Data events** - Checked
    - **Management events**
        - **Read** - Checked
        - **Write** - Checked
    - **Data events**
        - **Data event type** - S3
    
    
    
    
    
5.  You will be taken to the **Review and create** page, scroll down to the bottom and click **Create trail**
    
##  Gather values for DfAWS Data Source
When you run the Cloud Formation Template (CFT) for DfAWS you will need the bucket name and region.
1.  To get this, go back to your **Trails** page in the AWS Management Console.
2.  Make note of the **S3 bucket** name, and click the **S3 bucket** name
    
3.  Press the **Properties**
    
4.  Make note of the **AWS Region**
    
 ##  Setup DfAWS Data Source 
1.  Logon to the [DfAWS instance](https://207753870716.uw2.portal.vectra.ai) with **SSO**.