How can I check Firewall Manager security group policy findings using Security Hub?

2 minute read
0

I want to know how I can check my AWS Firewall Manager security group policy findings using AWS Security Hub.

Short description

Firewall Manager creates findings for resources that are out of compliance for detected attacks and then sends the findings to Security Hub. Firewall Manager is integrated with Security Hub to receive security group policy findings including:

Note: If you’re already using Firewall Manager, Security Hub automatically enables this integration. You don’t need to take any additional action to begin to receive findings from Firewall Manager.

Resolution

To view Firewall Manager security group finding types in Security Hub, follow these steps:

Filtering with findings

  1. Open the Security Hub console in the same Region where the security group policy was created.
  2. From the navigation pane, choose Findings.
  3. Choose Add filter. The filter menu opens.
  4. From the filter dropdown menu, choose Product name.
  5. Under Product name, choose the operator dropdown menu, and choose is.
  6. Enter the value as Firewall Manager, and then choose Apply. Note: Search values are case sensitive.

Filtering with integrations

  1. Open the Security Hub console in the same Region where the security group policy was created.
  2. From the navigation pane, choose Integrations.
  3. In the Integrations search pane, enter Firewall Manager. If you are already using Firewall Manager, the Status of this integration should display Accepting findings. Note: Search values are case sensitive.
  4. Choose See findings.

(Optional) Disabling integration

If you want to disable the integration of Firewall Manager findings with Security Hub, follow these steps:

  1. Open the Security Hub console.
  2. From the navigation pane, choose Integrations.
  3. In the Integrations search pane, enter Firewall Manager.
  4. Choose Stop accepting findings, accept the I want to stop accepting findings agreement, and then choose Stop accepting findings.

For more information, see Firewall Manager findings and Security Hub findings.

Related information

How can I use Security Hub to monitor security issues for my AWS environment?

How do I set up AWS Firewall Manager for my AWS account?

AWS OFFICIAL
AWS OFFICIALUpdated 10 months ago