Cloud environments introduce new data sources and attack surfaces. The architect ensures AWS CloudTrail, Azure Activity Logs, GCP Audit Logs, and cloud-native security tool outputs (GuardDuty, Defender for Cloud, Security Command Center) all flow into Splunk via the appropriate Add-ons.
The Shared Responsibility Model is central to cloud security architecture. The cloud provider secures the infrastructure (hypervisor, network, physical); the organization secures what runs on top (OS, applications, IAM configurations, data). Misconfigurations (overly permissive S3 buckets, open security groups) are the leading cause of cloud breaches and must be monitored continuously.