AWS Security Hub: Sending Findings to S3 for Athena

0

I am trying to find a way to create Athena queries that handle information from AWS Security Hub, such as the 'Findings' displayed within it. Athena's input data comes from S3. Is there a way to specify a location in S3 that will receive the findings from AWS Security Hub, or is there already a location I should try looking into? Is there any other way to feed Security Hub information into Athena?

2 réponses
0

Hi,

In principle, you should move security hub logs to an s3 bucket of choice, and then use Athena to query from that bucket.

You can check these out:

Hope it helps ;)

profile picture
EXPERT
répondu il y a un an
0

Hey there!

You can use the new service, Amazon Security Lake, which automatically sends security hub findings to an S3 bucket and sets up Athena for you.

For more details, see here: https://docs.aws.amazon.com/security-lake/latest/userguide/internal-sources.html

AWS
répondu il y a un an

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions