Supressed or Hide Items on Security Hub

0

Hi!

Is it possible to hide or supressed specific items automatically on Security Hub with tags? We have some resources based on environment tags, that I wouldn't like to see this finding, like a RDS Multi AZ on DEV database.

I tested the Automations configuration on Security Hub, but filtering, he retrieve only GuardDuty items, I don't why the resource tag items finding on Security Hub are get.

Thanks!

feita há 8 meses303 visualizações
3 Respostas
0

If using the CLI is acceptable to your use case, this documentation shows how to filter based on ResourceTags:
https://docs.aws.amazon.com/cli/latest/reference/securityhub/get-findings.html.

profile pictureAWS
respondido há 8 meses
  • Doesn't work, I tested filtering by tag (with CLI), but he retrieves only GuardDuty finding resources, the Security Hub findings, doesn't have tags.

    I opened a case and AWS confirmed that :-(

    I think that I want it's a little bit simple, to build a automation way to hide or suppress some resources or controls that I don't want to see (preferably using tags based).

0

I did see a feature request for using resource tags within AWS Security Hub has been filed, but there isn't a timeline for release yet. You can monitor the AWS What's New Blog for the latest news though.

profile pictureAWS
respondido há 7 meses
0

I encountered a similar problem with our Security Hub automation rules. Regrettably, I discovered that Security Hub doesn't offer support for tag-based automation during my interaction with AWS support

respondido há 7 meses

Você não está conectado. Fazer login para postar uma resposta.

Uma boa resposta responde claramente à pergunta, dá feedback construtivo e incentiva o crescimento profissional de quem perguntou.

Diretrizes para responder a perguntas