Connect read-only
Create a read-only IAM role using Flare’s CloudFormation template and protect role assumption with a connector-specific ExternalId.
Amazon Web Services security
Flare turns recent regional CloudTrail management-event history into ranked, explained findings—without complete-log retention, per-GB ingestion fees, or detection rules for your team to author.
How it works
Analyze recent regional management-event history available through CloudTrail LookupEvents. Flare does not claim to ingest every CloudTrail event or retain a complete copy of your logs.
Create a read-only IAM role using Flare’s CloudFormation template and protect role assumption with a connector-specific ExternalId.
Flare assesses current-window evidence with available historical context, then ranks noteworthy activity by severity and explains why it matters.
Inspect selected source-event excerpts and ask follow-up questions using the retained analysis results and supporting evidence.
Built for small teams
Flare uses read-only access and retains analysis results with selected supporting evidence—not a complete copy of your logs.
Learn how to investigate CloudTrail anomalies →Review AWS access requirements →Explore GCP Audit Logs audit coverage, access requirements and availability.
Explore GCP Audit Logs anomaly detection →Start with real evidence
Connect read-only or upload a focused JSON, NDJSON, CSV, or plain-text log file. Flare is free during the open beta.
Start free