obtaining more granular AWS Cognito App information in shib logs?
Peter Schober
peter.schober at univie.ac.at
Thu Sep 26 12:58:34 UTC 2024
Arron Merrill via users <users at shibboleth.net> [2024-09-26 13:41 CEST]:
> We would like this specific information so that we can feed it into our
> SIEM to enable us to more quickly determine which services users are
> accessing. The Cognito apps remain obfuscated and we are trying to get them
> in line with the rest of our integrations.
How about the referer (sic) header, then, as found in your IDP's web
server's log files?
Depending on how you correlate requests/responses you may not need to
pull that information into your IDP audit logs (assuming that's
possible it's probably not advisable, given that they're
client-controlled).
-peter
More information about the users
mailing list