tomwwright / littleorange

Minimalist AWS multi-account cloud leveraging CloudFormation and Lambda.
GNU General Public License v3.0
4 stars 1 forks source link

SecurityHub: example integration of findings with Logging or SIEM #20

Open tomwwright opened 3 years ago

tomwwright commented 3 years ago

SecurityHub Findings are published as CloudWatch Events. LittleOrange should showcase an example of forwarding findings to some external logging or SIEM system.

e.g. CloudWatch Event Rule to invoke Lambda to publish to Slack e.g. CloudWatch Event Rule to invoke Lambda to publish to CloudWatch Logs