Security Hub CSPM

Version 7.1.5 (View all)
Managed integration release status
Subscription level
What's this?
Basic
Ingestion method(s) API, AWS CloudWatch, AWS S3
Minimum Kibana version(s) 9.4.0
Important - Managed integrations on Elastic Cloud Hosted

You can use this integration as an Elastic Managed integration on Elastic Cloud Hosted deployments running this version or later.

The AWS Security Hub CSPM integration collects and parses data from AWS Security Hub REST APIs.

Important

Extra AWS charges on API requests will be generated by this integration. Check API Requests for more details.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ. Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

  1. The minimum compatible version of this module is Elastic Agent 9.4.0.
  2. This module is tested against AWS Security Hub API version 1.0.

The data streams authenticate with the standard AWS credential methods described in AWS Credentials: an access key pair, temporary security credentials, a shared credentials file, or an IAM role to assume. To create an access key pair:

  1. Login to https://console.aws.amazon.com/.
  2. Go to https://console.aws.amazon.com/iam/ to access the IAM console.
  3. On the navigation menu, choose Users.
  4. Choose your IAM user name.
  5. Select Create access key from the Security Credentials tab.
  6. To see the new access key, choose Show.
  1. For the current integration package, it is recommended to have interval in hours.
  2. AWS credentials are required; any of the supported credential methods listed above can be used.
  3. Findings Full Posture data stream request all the historical findings every 24 hours.
  4. The Findings and Findings Full Posture data streams collect from the GetFindings API using the CEL input with native AWS SigV4 signing (auth.aws). The Insights data stream also signs requests with auth.aws.

The Findings and Findings Full Posture data streams page through the GetFindings API using the CEL input, which caps the number of pages fetched per collection interval at the Maximum Executions value (each page returns up to 100 findings). When an account holds more findings than the cap allows, the agent logs reached maximum number of CEL executions: will continue at next periodic evaluation and stops paging for that interval.

For the Findings stream this is usually self-correcting: collection is incremental, so the next interval resumes where the previous one stopped. For Findings Full Posture, which re-reads the full current posture on each run, a very large account may not finish a sweep within one interval.

To resolve this, increase Maximum Executions in the data stream's advanced settings (it must be a positive integer). For the Findings stream, shortening the collection interval also reduces the pages per run, since each run then covers fewer new findings. For Findings Full Posture the interval does not change the sweep size; instead raise Maximum Executions or narrow the result set with the Findings Filters setting.

This is the securityhub_findings data stream. Findings are collected incrementally using the finding's UpdatedAt timestamp, which the integration manages automatically.

Use the Findings Filters setting to apply additional server-side AwsSecurityFindingFilters so that only matching findings are collected (for example, to restrict collection by SeverityLabel or RecordState). Provide a YAML or JSON object using the AWS AwsSecurityFindingFilters shape; the UpdatedAt filter is reserved for incremental collection and takes precedence over any UpdatedAt supplied here.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This is the securityhub_findings_full_posture data stream. It requests the full set of current findings every 24 hours rather than collecting incrementally.

Use the Findings Filters setting to control which findings are collected via server-side AwsSecurityFindingFilters. The default excludes archived (RecordState) and suppressed (WorkflowStatus) findings to reflect the current security posture; editing or clearing this setting replaces those defaults.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This is the securityhub_insights data stream.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.