Selecting a custom action for findings and insight results
After you create Amazon Security Hub Cloud Security Posture Management (CSPM) custom actions and Amazon EventBridge rules, you can send findings and insight results to EventBridge for automatic management and processing.
Events are sent to EventBridge only in the account in which they are viewed. If you view a finding using an administrator account, the event is sent to EventBridge in the administrator account.
For Amazon API calls to be effective, the implementations of target code must switch roles into member accounts. This also means that the role you switch into must be deployed to each member where action is needed.
To send findings to EventBridge (console)
Open the Amazon Security Hub Cloud Security Posture Management (CSPM) console at https://console.amazonaws.cn/securityhub/
. -
Display a list of findings:
-
From Findings, you can view findings from all of the enabled product integrations and controls.
-
From Security standards, you can navigate to a list of findings generated from a specific control. For more information, see Reviewing the details of controls in Security Hub CSPM.
-
From Integrations, you can navigate to a list of findings generated by an enabled integration. For more information, see Viewing findings from a Security Hub CSPM integration.
-
From Insights, you can navigate to a list of findings for an insight result. For more information, see Reviewing and acting on insights in Security Hub CSPM.
-
-
Select the findings to send to EventBridge. You can select up to 20 findings at a time.
-
From Actions, choose the custom action that aligns with the EventBridge rule to apply.
Security Hub CSPM sends a separate Security Hub Findings - Custom Action event for each finding.
To send insight results to EventBridge (console)
Open the Amazon Security Hub Cloud Security Posture Management (CSPM) console at https://console.amazonaws.cn/securityhub/
. -
In the navigation pane, choose Insights.
-
On the Insights page, choose the insight that includes the results to send to EventBridge.
-
Select the insight results to send to EventBridge. You can select up to 20 results at a time.
-
From Actions, choose the custom action that aligns with the EventBridge rule to apply.