Hi Asif,
If you had an Event Collector deployed in your AWS environment you could send the Linux events directly to that EC via syslog as the DSM guide recommends. But if your ECs are in your on-prem data centre and the AWS environment has no network line-of-sight to them, then direct syslog forwarding is not an option. We have protocols for collecting from AWS S3 storage (the "Amazon AWS S3 REST API" protocol) or from the CloudWatch Logs service or Kinesis Data Streams service ("Amazon Web Services" protocol). The usage of both protocols are in the DSM Guide. If you can get your AWS-based Linux machines logging to one of these AWS services, then using thes eprotocols you can obtain the events that way.
Cheers
Colin
------------------------------
COLIN HAY
IBM Security
------------------------------