View a markdown version of this page

Enable logging from third-party sources - Amazon CloudWatch Logs

Enable logging from third-party sources

CloudWatch Logs supports ingesting logs from third-party sources through direct API integrations and Amazon S3 bucket integrations. You can also receive additional third-party security findings through AWS Security Hub CSPM.

Direct third-party integrations

CloudWatch Logs provides direct integrations with the following third-party sources. These integrations use either direct API connections or Amazon S3 bucket integrations to ingest logs into CloudWatch Logs:

  • CrowdStrike Falcon

  • Microsoft Office 365

  • Okta Auth0

  • Microsoft Entra ID

  • Palo Alto Networks NGFW

  • Microsoft Windows Events

  • Wiz

  • Zscaler Internet Access

  • Okta SSO

  • SentinelOne Endpoint Security

  • GitHub Audit Logs

  • ServiceNow CMDB

  • Cisco Umbrella

For setup instructions, see the third-party integration setup guide in the Amazon CloudWatch User Guide.

Additional sources via AWS Security Hub CSPM

In addition to the direct integrations, third-party security partners send findings to AWS Security Hub CSPM, which are then available as data sources in CloudWatch Logs. The following table lists the Security Hub CSPM partner integrations and their integration type.

To enable Security Hub CSPM findings as a data source in CloudWatch Logs, create a telemetry enablement rule for AWS Security Hub in the CloudWatch console. The enablement rule configures CloudWatch to automatically ingest findings from Security Hub CSPM into a managed log group. For step-by-step instructions, see Telemetry enablement rules in the Amazon CloudWatch User Guide.

Partner Integration
3CORESec – NTASends findings via Security Hub CSPM
Alert Logic – SIEMless Threat ManagementSends findings via Security Hub CSPM
Aqua Security – Cloud Native Security PlatformSends findings via Security Hub CSPM
Aqua Security – Kube-benchSends findings via Security Hub CSPM
Armor – Armor AnywhereSends findings via Security Hub CSPM
AttackIQSends findings via Security Hub CSPM
Barracuda Networks – Cloud Security GuardianSends findings via Security Hub CSPM
BigID – BigID EnterpriseSends findings via Security Hub CSPM
Blue HexagonSends findings via Security Hub CSPM
Check Point – CloudGuard IaaSSends findings via Security Hub CSPM
Check Point – CloudGuard Posture ManagementSends findings via Security Hub CSPM
Claroty – xDomeSends findings via Security Hub CSPM
Cloud Storage Security – Antivirus for Amazon S3Sends findings via Security Hub CSPM
Contrast Security – Contrast AssessSends findings via Security Hub CSPM
CrowdStrike – CrowdStrike FalconSends findings via Security Hub CSPM
CyberArk – Privileged Threat AnalyticsSends findings via Security Hub CSPM
Data TheoremSends findings via Security Hub CSPM
DrataSends findings via Security Hub CSPM
Forcepoint – CASBSends findings via Security Hub CSPM
Forcepoint – Cloud Security GatewaySends findings via Security Hub CSPM
Forcepoint – DLPSends findings via Security Hub CSPM
Forcepoint – NGFWSends findings via Security Hub CSPM
FugueSends findings via Security Hub CSPM
Guardicore – CentraSends findings via Security Hub CSPM
HackerOne – Vulnerability IntelligenceSends findings via Security Hub CSPM
JFrog – XraySends findings via Security Hub CSPM
Juniper Networks – vSRX Next Generation FirewallSends findings via Security Hub CSPM
k9 Security – Access AnalyzerSends findings via Security Hub CSPM
LaceworkSends findings via Security Hub CSPM
McAfee – MVISION CNAPPSends findings via Security Hub CSPM
NETSCOUT – Cyber InvestigatorSends findings via Security Hub CSPM
Orca – Cloud Security PlatformSends findings via Security Hub CSPM
Palo Alto Networks – Prisma Cloud ComputeSends findings via Security Hub CSPM
Palo Alto Networks – Prisma Cloud EnterpriseSends findings via Security Hub CSPM
Plerion – Cloud Security PlatformSends findings via Security Hub CSPM
ProwlerSends findings via Security Hub CSPM
Qualys – Vulnerability ManagementSends findings via Security Hub CSPM
Rapid7 – InsightVMSends findings via Security Hub CSPM
SentinelOneSends findings via Security Hub CSPM
SnykSends findings via Security Hub CSPM
Sonrai Security – Sonrai DigSends findings via Security Hub CSPM
Sophos – Server ProtectionSends findings via Security Hub CSPM
StackRox – Kubernetes SecuritySends findings via Security Hub CSPM
Sumo Logic – Machine Data AnalyticsSends findings via Security Hub CSPM
Symantec – Cloud Workload ProtectionSends findings via Security Hub CSPM
Tenable.ioSends findings via Security Hub CSPM
Trend Micro – Cloud OneSends findings via Security Hub CSPM
Vectra – Cognito DetectSends findings via Security Hub CSPM
WizSends findings via Security Hub CSPM
Caveonix – Caveonix CloudSends and receives findings via Security Hub CSPM
Cloud CustodianSends and receives findings via Security Hub CSPM
DisruptOpsSends and receives findings via Security Hub CSPM
KionSends and receives findings via Security Hub CSPM
TurbotSends and receives findings via Security Hub CSPM
Note

This list reflects the Security Hub partner integrations that send findings at the time of writing. Because AWS Security Hub regularly adds new partner integrations, refer to Third-party product integrations with Security Hub CSPM in the AWS Security Hub User Guide for the most up-to-date list of available partners.