Supressed or Hide Items on Security Hub

0

Hi!

Is it possible to hide or supressed specific items automatically on Security Hub with tags? We have some resources based on environment tags, that I wouldn't like to see this finding, like a RDS Multi AZ on DEV database.

I tested the Automations configuration on Security Hub, but filtering, he retrieve only GuardDuty items, I don't why the resource tag items finding on Security Hub are get.

Thanks!

gefragt vor 8 Monaten309 Aufrufe
3 Antworten
0

If using the CLI is acceptable to your use case, this documentation shows how to filter based on ResourceTags:
https://docs.aws.amazon.com/cli/latest/reference/securityhub/get-findings.html.

profile pictureAWS
beantwortet vor 8 Monaten
  • Doesn't work, I tested filtering by tag (with CLI), but he retrieves only GuardDuty finding resources, the Security Hub findings, doesn't have tags.

    I opened a case and AWS confirmed that :-(

    I think that I want it's a little bit simple, to build a automation way to hide or suppress some resources or controls that I don't want to see (preferably using tags based).

0

I did see a feature request for using resource tags within AWS Security Hub has been filed, but there isn't a timeline for release yet. You can monitor the AWS What's New Blog for the latest news though.

profile pictureAWS
beantwortet vor 7 Monaten
0

I encountered a similar problem with our Security Hub automation rules. Regrettably, I discovered that Security Hub doesn't offer support for tag-based automation during my interaction with AWS support

beantwortet vor 7 Monaten

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen