Investigation Tools with Amazon QuickSight

Amazon QuickSight

You need to create a QuickSight account to try this demo.

quick

quick

  1. Grant QuickSight access to data
  • In QuickSight Home, click Manage QuickSightSecurity & permissions.
  • In the QuickSight access to AWS services section → click Manage → check AthenaSave.
  • In the QuickSight access to AWS services section → click Select S3 buckets → select audit-demo-logs -> and enable “Write permission for Athena Workgroup”. -> Save.

quick

  • QuickSight now has permission to run queries on Athena and read results in S3.
  1. Build Analysis & Visuals
  • From QuickSight Home → click Datasets (left menu) → New dataset.

quick

  • Select AthenaConnect.

  • Enter Data source name: AuditLogsAthenaCreate data source.

  • On the data selection screen:

    • Database: audit_reports

    • Table: audit_logsaudit_demo_logs

  • Click Select → you will see a preview of the table.

  • Enable Import to SPICE for quicker analyticsVisualize.

quick

  1. Build Analysis & Visuals.

quick

  • Draw Timeline Events:
    • In the Visuals pane, click the + ADD button → select Add visual.
    • Drag the timestamp field from the Data pane to the X axis area in the Field wells pane.
    • The chart will show the number of events over time.

quick

  • Draw Heatmap User Activity:
    • Click + ADD → Add visual.
    • Select the Heat map icon. In Field wells:
    • Drag user to Rows.
    • Drag timestamp to Columns → click the right arrow and change Date granularity to Day.
    • Drag Count to Color intensity. The heatmap will show the density of events per user per day, with color intensity representing the count.

quick

  • Draw Top Users:

    • Click + ADD → Add visual.

    Select the Horizontal bar chart icon.

    In Field wells:

    • Drag user to Category.
    • Drag Count to Value.

quick

  • Add a Filter by action.

  • After creating all visuals, click Save and name it AuditTrailInvestigation.

  1. Publish
  • In Analysis, click Publish dashboard.

  • Dashboard name: Audit Trail Investigation.

quick

quick