Loading

Security Hub

<div class="condensed-table">
| | |
| --- | --- |
| Version | 2.38.2 (View all) |
| Compatible Kibana version(s) | 8.16.2 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |

</div>
The AWS Security Hub integration collects and parses data from AWS Security Hub REST APIs.

Important

Extra AWS charges on API requests will be generated by this integration. Check API Requests for more details.

  1. The minimum compatible version of this module is Elastic Agent 8.4.0.
  2. This module is tested against AWS Security Hub API version 1.0.
  1. Login to https://console.aws.amazon.com/.
  2. Go to https://console.aws.amazon.com/iam/ to access the IAM console.
  3. On the navigation menu, choose Users.
  4. Choose your IAM user name.
  5. Select Create access key from the Security Credentials tab.
  6. To see the new access key, choose Show.
  1. For the current integration package, it is recommended to have interval in hours.
  2. For the current integration package, it is compulsory to add Secret Access Key and Access Key ID.

This is the securityhub_findings data stream.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

This is the securityhub_insights data stream.

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.