obtaining more granular AWS Cognito App information in shib logs?

Peter Schober peter.schober at univie.ac.at
Thu Sep 26 12:58:34 UTC 2024


Arron Merrill via users <users at shibboleth.net> [2024-09-26 13:41 CEST]:
> We would like this specific information so that we can feed it into our
> SIEM to enable us to more quickly determine which services users are
> accessing. The Cognito apps remain obfuscated and we are trying to get them
> in line with the rest of our integrations.

How about the referer (sic) header, then, as found in your IDP's web
server's log files?
Depending on how you correlate requests/responses you may not need to
pull that information into your IDP audit logs (assuming that's
possible it's probably not advisable, given that they're
client-controlled).

-peter


More information about the users mailing list