AWS service integrations with Security Lake - Amazon Security Lake

AWS service integrations with Security Lake

Amazon Security Lake integrates with other AWS services. A service may either operate as a source integration, a subscriber integration, or both.

Source integrations have the following properties:

Subscriber integrations can access Security Lake data in one of the following ways:

  • Read source data from Security Lake through an HTTPS endpoint

  • Read source data from Security Lake through an Amazon Simple Queue Service (Amazon SQS)

  • By directly querying source data using AWS Lake Formation

The following table provides a list of AWS service integrations that Security Lake supports.

AWS service Integration type Description How integration works

Amazon Bedrock

Subscriber

Generate AI-powered insights to analyze Security Lake data.

Amazon Bedrock integration

Amazon Detective

Subscriber

Analyze, investigate, and quickly identify the root cause of security findings or suspicious activities by querying Security Lake.

Amazon Detective integration

Amazon OpenSearch Service

Subscriber

Generate security insights from Security Lake data by using OpenSearch Service ingestion.

Amazon OpenSearch Service integration

Amazon OpenSearch Service ingestion pipeline

Subscriber, Source

Stream logs, metrics, and trace data to OpenSearch Service and Security Lake.

Amazon OpenSearch Service Ingestion pipeline integration

Amazon OpenSearch Service zero-ETL

Subscriber (Query)

Query data in Security Lake with zero-ETL.

Amazon OpenSearch Service zero-ETL direct query integration

QuickSight

Subscriber

Visualize, explore, and interpret logs in Security Lake with QuickSight.

QuickSight integration

Amazon SageMaker AI

Subscriber

Generate AI-powered insights to analyze Security Lake data.

Amazon SageMaker AI integration

AWS AppFabric

Source

Ingests and normalize software as a service (SaaS) application logs into Security Lake standard format.

AWS AppFabric integration

AWS Security Hub

Source

Centralize and store security findings from Security Hub in Security Lake standard format.

AWS Security Hub integration