Supressed or Hide Items on Security Hub

0

Hi!

Is it possible to hide or supressed specific items automatically on Security Hub with tags? We have some resources based on environment tags, that I wouldn't like to see this finding, like a RDS Multi AZ on DEV database.

I tested the Automations configuration on Security Hub, but filtering, he retrieve only GuardDuty items, I don't why the resource tag items finding on Security Hub are get.

Thanks!

preguntada hace 8 meses303 visualizaciones
3 Respuestas
0

If using the CLI is acceptable to your use case, this documentation shows how to filter based on ResourceTags:
https://docs.aws.amazon.com/cli/latest/reference/securityhub/get-findings.html.

profile pictureAWS
respondido hace 8 meses
  • Doesn't work, I tested filtering by tag (with CLI), but he retrieves only GuardDuty finding resources, the Security Hub findings, doesn't have tags.

    I opened a case and AWS confirmed that :-(

    I think that I want it's a little bit simple, to build a automation way to hide or suppress some resources or controls that I don't want to see (preferably using tags based).

0

I did see a feature request for using resource tags within AWS Security Hub has been filed, but there isn't a timeline for release yet. You can monitor the AWS What's New Blog for the latest news though.

profile pictureAWS
respondido hace 7 meses
0

I encountered a similar problem with our Security Hub automation rules. Regrettably, I discovered that Security Hub doesn't offer support for tag-based automation during my interaction with AWS support

respondido hace 7 meses

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas