integration-docs
Loading

Security Hub

Stack 9.1.0 Serverless Observability Serverless Security

Version 4.2.0 (View all)
Subscription level
What's this?
Basic
Ingestion method(s) API, AWS CloudWatch, AWS S3

The AWS Security Hub integration collects and parses data from AWS Security Hub REST APIs.

Important

Extra AWS charges on API requests will be generated by this integration. Check API Requests for more details.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ. Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

  1. The minimum compatible version of this module is Elastic Agent 8.4.0.
  2. This module is tested against AWS Security Hub API version 1.0.
  1. Login to https://console.aws.amazon.com/.
  2. Go to https://console.aws.amazon.com/iam/ to access the IAM console.
  3. On the navigation menu, choose Users.
  4. Choose your IAM user name.
  5. Select Create access key from the Security Credentials tab.
  6. To see the new access key, choose Show.
  1. For the current integration package, it is recommended to have interval in hours.
  2. For the current integration package, it is compulsory to add Secret Access Key and Access Key ID.
  3. Findings Full Posture data stream request all the historical findings every 24 hours.

This is the securityhub_findings data stream.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This is the securityhub_findings_full_posture data stream.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This is the securityhub_insights data stream.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.