AWS GuardDuty - finding logs location

0

Hi.

I have some questions:

1.I have enabled GuardDuty in my Organization with Control Tower. About findings I see this: "Findings are automatically sent to EventBridge. You can also export findings to an S3 bucket. New findings are exported within 5 minutes. You can modify the frequency for updated findings below." So, I understand that Findings are sent to Eventbridge, but where? in my account I was not be able to see any EventBridge logs or something like that, is it visible or is unmanaged?

2.Also, I see an option for S3 bucket. As I implemented Control Tower I have Log Archive Account with 02 buckets: aws-controltower-logs- aws-controltower-s3-access-logs- So, for GuardDuty findings export, could I use the current s3 buckets in Log Archive account or it is recommended a new buckets?

3.-As I have Control Tower, I recevie sns notifications from Audit Account for events related to Config rules, Controls. Could I use the same sns notification for GuardDuty, or how could I enable something like that?

Thank you-

1개 답변
1

Hi Orlando,

1/ and 3/: For SNS notification rule, check this example for custom notifications from specific AWS service event types [1]. GuardDuty integrates with Amazon EventBridge, which can be used to send findings data to other applications and services for processing. With EventBridge you can use GuardDuty findings to initiate automatic responses to your findings by connecting finding events to targets such as AWS Lambda functions, Amazon EC2 Systems Manager automation and Amazon Simple Notification Service (SNS) [2].

2/: The S3 bucket used can be in the same account in which GuardDuty is enabled, or in a different AWS account. With multiple buckets you can define individual bucket features like bucket policy, S3 Versioning, S3 Object Lock, as documented here in Security best practices for Amazon S3 [3] . Also, GuardDuty recommends configuring settings to export findings because it allows you to export your findings to an S3 bucket for indefinite storage beyond the GuardDuty 90-day retention period. This allows you to keep records of findings or track issues within your AWS environment over time. [4]

[1] - https://repost.aws/knowledge-center/guardduty-eventbridge-sns-rule

[2] - https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_settingup.html#setup-sns

[3] - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html

[4] - https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_settingup.html#setup-export

profile pictureAWS
Edu
답변함 7달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠