GuardDuty and AWS Security Hub - Timing

0

Hi All,

Ive a quick question re: the timings of findings being generated and being accessible in AWS Security Hub via GuardDuty.

Without giving away the trade secrets, Im guessing there various step that take place from the point there is suspicious activity to it being available via the SecurityHub API.

Im guessing the steps would be:

  1. Suspicious activity on the account taking place
  2. GuardDuty observes and stores this finding
  3. GuardDuty then passes this to Security Hub or does Security Hub have the same access to the GuardDuty repository (therefore does it get I the same time as GuardDuty finds it?)
  4. Available to be pulled via the findings API

What are the timeframes of these steps?

Im trying to understand how quickly I can access the finding from the point the suspious activity happened.

Thanks all.

1回答
1

Guardduty is designed to analyze account and network activity in near real time and at scale. The findings are available for retrieval through Guardduty API.

When GuardDuty creates a new finding, it is usually sent to Security Hub within five minutes. More details about Guardduty and Security Hub integration can be found here.

AWS
raj_b
回答済み 2年前
profile picture
エキスパート
レビュー済み 14日前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ