Slide 27
Slide 27 text
26
Security Hubの通知設定 例
イベントパターンを以下の通り記載することで、通知内容を限定することが可能
BETTER
SHOULD
MUST
{
"source": [
"aws.securityhub"
],
"detail-type": [
"Security Hub Findings - Imported"
],
"detail": {
"findings": {
"ProductFields": {
"aws/securityhub/SeverityLabel": [
"HIGH",
"MEDIUM"
]
}
}
}
}
{
"source": [
"aws.securityhub"
],
"detail-type": [
"Security Hub Findings - Imported"
],
"detail": {
"findings": {
"ProductFields": {
"aws/securityhub/ProductName": [
"GuardDuty"
]
}
}
}
}
例1. 重要度がHIGH、MEDIUMのみ通知 例2. GuardDutyのみ通知