Define filter and aggregation criteria for AWS Security Hub findings ingestion
You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
Set the filtering conditions for AWS Security Hub findings to create security incidents
Set the filtering conditions so that security incidents are created only when the filtering conditions match.
Antes de Iniciar
Role required: sn_si.admin
Por Que e Quando Desempenhar Esta Tarefa
This type of filtering helps you to isolate security incidents and limits the number of security incidents that you create. If you set additional filtering criteria, only the required findings are ingested without having to change the query or the triggered incident configuration.
Perform the following steps to define the criteria that an incoming AWS Security Hub finding must satisfy so that a security incident is created:
Procedimento
Resultado
Based on the filtering conditions, AWS Security Hub findings are imported to SIR. Navigate to to view the imported findings.
Define conditions to aggregate AWS Security Hub findings to a security incident
Define additional incident aggregation criteria that aggregates an incoming AWS Security Hub finding to an existing SIR security incident instead of creating similar, potentially duplicate incidents. When you use field matching value criteria for each profile, this additional aggregation can reduce the number of active, overlapping security incidents by placing all related incidents data on a single security incident.
Antes de Iniciar
Role required: sn_si.admin
Por Que e Quando Desempenhar Esta Tarefa
All the aggregated AWS Security Hub findings on a security incident are displayed on the AWS Security Hub related list. This list details the associated timestamps and aggregated field values. This information helps you understand why AWS Security Hub findings are added to the existing security incidents.
Procedimento
Resultado
Based on the aggregation conditions, AWS Security Hub findings are are aggregated to create to create a SIR incident. Navigate to to view the list of security incidents that have been created.
O que Fazer Depois
Set a schedule to retrieve the finding data and finding incidents that match the criteria in the profile.