Serverless defender for AWS Lambda not detected in Prisma Cloud Compute
6387
Created On 08/17/21 08:24 AM - Last Modified 02/08/22 03:45 AM
Symptom
Trying to create Serverless auto-defend rule for an AWS lambda function. The console is showing that the rule is created and there are 0/1 defenders and the console in Manage > Defenders > Manage is not showing that defender in the list. Also getting 403 errors in the console.
Environment
- Prisma Cloud Compute (SaaS) Version: 18 October 2021
- Prisma Cloud Compute Edition (Self Hosted) Versions: 21.08, 21.04
Cause
An Issue in the documentation. In Required permissions , these3 lines were missing under Actions.
, "lambda:ListLayerVersions", "lambda:ListLayers", "lambda:DeleteLayerVersion"
Resolution
- OPTION 1: Use online documentation
SaaS 18 October 2021: Prisma Cloud > Prisma Cloud Administrator’s Guide (Compute) > Install > Install Defender > Auto-defend serverless functions
Self.Hosted 21.08: Prisma Cloud > Prisma Cloud Compute Edition Administrator’s Guide > Install > Install Defender > Auto-defend serverless functions
- OPTION 2: Read the documentation with this correction (Self.Hosted 21.04, PDF documentations)
In Required permissions , append these3 lines under Actions.
, "lambda:ListLayerVersions", "lambda:ListLayers", "lambda:DeleteLayerVersion"
Additional Information
The page in the PDF documentation
- Saas 18 October 2021: Prisma Cloud > Prisma Cloud Administrator’s Guide (Compute) > DOWNLOAD PDF > Page 138
- Self.Hosted 21.08: Prisma Cloud > Prisma Cloud Compute Edition Administrator’s Guide > DOWNLOAD PDF > Page 164
- Self.Hosted 21.04: Prisma Cloud > Prisma Cloud Compute Edition Administrator’s Guide > DOWNLOAD PDF > Page 177