View a markdown version of this page

Supported third-party sources for data sources - Amazon CloudWatch Logs

Supported third-party sources for data sources

The following table lists the third-party sources that are automatically categorized by CloudWatch Logs as data sources when ingested through pipelines:

Data Source Name (@data_source_name field) Data Source Type (@data_source_type field)
akamai_datastream_2 base_event
akamai_datastream_2 dns_activity
akamai_datastream_2 http_activity
cisco_meraki api_activity
cisco_meraki detection_finding
cisco_meraki network_activity
cisco_umbrella data_security_finding
cisco_umbrella dns_activity
cisco_umbrella entity_management
cisco_umbrella network_activity
crowdstrike_falcon detection_finding
crowdstrike_falcon process_activity
drupal_core application_lifecycle
drupal_core authentication
drupal_core entity_management
drupal_core http_activity
entrust_idaas authentication
entrust_idaas entity_management
f5_bigip http_activity
f5_bigip network_activity
github_auditlogs account_change
github_auditlogs api_activity
github_auditlogs entity_management
microsoft_entraid account_change
microsoft_entraid authentication
microsoft_entraid entity_management
microsoft_entraid user_access_management
microsoft_office365 account_change
microsoft_office365 application_lifecycle
microsoft_office365 authentication
microsoft_office365 compliance_finding
microsoft_office365 detection_finding
microsoft_office365 email_activity
microsoft_office365 file_hosting_activity
microsoft_office365 group_management
microsoft_office365 incident_finding
microsoft_office365 user_access_management
microsoft_office365 vulnerability_finding
microsoft_office365 web_resources_activity
microsoft_windows account_change
microsoft_windows authentication
microsoft_windows entity_management
microsoft_windows event_log_activity
microsoft_windows file_system_activity
microsoft_windows group_management
microsoft_windows kernel_activity
okta_auth0 api_activity
okta_auth0 authentication
okta_sso api_activity
okta_sso authentication
okta_sso detection_finding
okta_sso entity_management
onelogin_identity account_change
onelogin_identity authentication
onelogin_identity entity_management
paloaltonetworks_nextgenerationfirewall authentication
paloaltonetworks_nextgenerationfirewall detection_finding
paloaltonetworks_nextgenerationfirewall network_activity
paloaltonetworks_nextgenerationfirewall process_activity
pingidentity_pingone account_change
pingidentity_pingone authentication
pingidentity_pingone entity_management
sentinelone_endpointsecurity dns_activity
sentinelone_endpointsecurity file_system_activity
sentinelone_endpointsecurity http_activity
sentinelone_endpointsecurity process_activity
servicenow_cmdb api_activity
servicenow_cmdb datastore_activity
servicenow_cmdb entity_management
wiz_cnapp api_activity
wiz_cnapp authentication
wiz_cnapp compliance_finding
wiz_cnapp detection_finding
wiz_cnapp vulnerability_finding
zeek authentication
zeek base_event
zeek detection_finding
zeek dhcp_activity
zeek dns_activity
zeek email_activity
zeek ftp_activity
zeek http_activity
zeek network_activity
zeek rdp_activity
zeek smb_activity
zeek software_inventory_info
zeek ssh_activity
zeek tunnel_activity
zscaler_internetaccess authentication
zscaler_internetaccess dns_activity
zscaler_internetaccess http_activity
zscaler_internetaccess network_activity

Additional third-party sources via AWS Security Hub CSPM

Additional third-party security findings are available through AWS Security Hub CSPM integration. The following partners send findings to Security Hub CSPM, which are then available as data sources in CloudWatch Logs. For comprehensive details about these integrations, see Third-party product integrations with Security Hub CSPM in the AWS Security Hub User Guide.

Partner Integration
3CORESec – NTASends findings via Security Hub CSPM
Alert Logic – SIEMless Threat ManagementSends findings via Security Hub CSPM
Aqua Security – Cloud Native Security PlatformSends findings via Security Hub CSPM
Aqua Security – Kube-benchSends findings via Security Hub CSPM
Armor – Armor AnywhereSends findings via Security Hub CSPM
AttackIQSends findings via Security Hub CSPM
Barracuda Networks – Cloud Security GuardianSends findings via Security Hub CSPM
BigID – BigID EnterpriseSends findings via Security Hub CSPM
Blue HexagonSends findings via Security Hub CSPM
Check Point – CloudGuard IaaSSends findings via Security Hub CSPM
Check Point – CloudGuard Posture ManagementSends findings via Security Hub CSPM
Claroty – xDomeSends findings via Security Hub CSPM
Cloud Storage Security – Antivirus for Amazon S3Sends findings via Security Hub CSPM
Contrast Security – Contrast AssessSends findings via Security Hub CSPM
CrowdStrike – CrowdStrike FalconSends findings via Security Hub CSPM
CyberArk – Privileged Threat AnalyticsSends findings via Security Hub CSPM
Data TheoremSends findings via Security Hub CSPM
DrataSends findings via Security Hub CSPM
Forcepoint – CASBSends findings via Security Hub CSPM
Forcepoint – Cloud Security GatewaySends findings via Security Hub CSPM
Forcepoint – DLPSends findings via Security Hub CSPM
Forcepoint – NGFWSends findings via Security Hub CSPM
FugueSends findings via Security Hub CSPM
Guardicore – CentraSends findings via Security Hub CSPM
HackerOne – Vulnerability IntelligenceSends findings via Security Hub CSPM
JFrog – XraySends findings via Security Hub CSPM
Juniper Networks – vSRX Next Generation FirewallSends findings via Security Hub CSPM
k9 Security – Access AnalyzerSends findings via Security Hub CSPM
LaceworkSends findings via Security Hub CSPM
McAfee – MVISION CNAPPSends findings via Security Hub CSPM
NETSCOUT – Cyber InvestigatorSends findings via Security Hub CSPM
Orca – Cloud Security PlatformSends findings via Security Hub CSPM
Palo Alto Networks – Prisma Cloud ComputeSends findings via Security Hub CSPM
Palo Alto Networks – Prisma Cloud EnterpriseSends findings via Security Hub CSPM
Plerion – Cloud Security PlatformSends findings via Security Hub CSPM
ProwlerSends findings via Security Hub CSPM
Qualys – Vulnerability ManagementSends findings via Security Hub CSPM
Rapid7 – InsightVMSends findings via Security Hub CSPM
SentinelOneSends findings via Security Hub CSPM
SnykSends findings via Security Hub CSPM
Sonrai Security – Sonrai DigSends findings via Security Hub CSPM
Sophos – Server ProtectionSends findings via Security Hub CSPM
StackRox – Kubernetes SecuritySends findings via Security Hub CSPM
Sumo Logic – Machine Data AnalyticsSends findings via Security Hub CSPM
Symantec – Cloud Workload ProtectionSends findings via Security Hub CSPM
Tenable.ioSends findings via Security Hub CSPM
Trend Micro – Cloud OneSends findings via Security Hub CSPM
Vectra – Cognito DetectSends findings via Security Hub CSPM
WizSends findings via Security Hub CSPM
Caveonix – Caveonix CloudSends and receives findings via Security Hub CSPM
Cloud CustodianSends and receives findings via Security Hub CSPM
DisruptOpsSends and receives findings via Security Hub CSPM
KionSends and receives findings via Security Hub CSPM
TurbotSends and receives findings via Security Hub CSPM
Note

This list reflects the Security Hub partner integrations that send findings at the time of writing. Because AWS Security Hub regularly adds new partner integrations, refer to Third-party product integrations with Security Hub CSPM in the AWS Security Hub User Guide for the most up-to-date list of available partners.