You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置匹配SecurityHub Findings的EventBridge规则推送至Kinesis Firehose?

问题根因
  • 你当前用来测试匹配的JSON是Security Hub主动查询/导出接口返回的Findings结构,不是EventBridge接收的Security Hub推送事件的原生结构,二者结构差异是匹配失败的核心原因。
EventBridge 接收的Security Hub事件标准结构

Security Hub推送至EventBridge的事件会外层包裹EventBridge的标准事件字段,Findings字段是放在detail参数下的,示例结构如下:

{
  "version": "0",
  "id": "xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "detail-type": "Security Hub Findings - Imported",
  "source": "aws.securityhub",
  "account": "220311111111",
  "time": "2021-10-12T16:35:29Z",
  "region": "us-west-2",
  "resources": [],
  "detail": {
    "Findings": [
      // 你手头的Findings数组内容完全匹配此处的结构
    ]
  }
}
正确的自定义事件模式配置

如果要匹配所有Security Hub Findings,直接使用如下模式即可:

{
  "source": ["aws.securityhub"],
  "detail-type": ["Security Hub Findings - Imported"]
}

如果需要做更细粒度的过滤,比如只匹配你示例中的EC2.9规则的INFORMATIONAL级别告警,可扩展为如下模式:

{
  "source": ["aws.securityhub"],
  "detail-type": ["Security Hub Findings - Imported"],
  "detail": {
    "Findings": {
      "GeneratorId": ["aws-foundational-security-best-practices/v/1.0.0/EC2.9"],
      "Severity": {
        "Label": ["INFORMATIONAL"]
      }
    }
  }
}
测试与推送配置校验
  • 匹配测试:不要直接用你手头的导出JSON测试,按照上述EventBridge标准事件结构构造测试数据,把你拿到的Findings数组放在detail字段下即可测试通过
  • Kinesis Firehose推送校验:规则匹配通过后如果无法正常推送,检查两个权限配置:
    • EventBridge规则关联的IAM执行角色,必须包含firehose:PutRecord权限,且资源字段指定目标Firehose的ARN
    • Kinesis Firehose自身的IAM权限配置正常,可正常写入下游存储目标

内容的提问来源于stack exchange,提问作者Bokambo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 14:36:02