如何配置匹配SecurityHub Findings的EventBridge规则推送至Kinesis Firehose?
问题根因
- 你当前用来测试匹配的JSON是Security Hub主动查询/导出接口返回的Findings结构,不是EventBridge接收的Security Hub推送事件的原生结构,二者结构差异是匹配失败的核心原因。
EventBridge 接收的Security Hub事件标准结构
Security Hub推送至EventBridge的事件会外层包裹EventBridge的标准事件字段,Findings字段是放在detail参数下的,示例结构如下:
{ "version": "0", "id": "xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx", "detail-type": "Security Hub Findings - Imported", "source": "aws.securityhub", "account": "220311111111", "time": "2021-10-12T16:35:29Z", "region": "us-west-2", "resources": [], "detail": { "Findings": [ // 你手头的Findings数组内容完全匹配此处的结构 ] } }
正确的自定义事件模式配置
如果要匹配所有Security Hub Findings,直接使用如下模式即可:
{ "source": ["aws.securityhub"], "detail-type": ["Security Hub Findings - Imported"] }
如果需要做更细粒度的过滤,比如只匹配你示例中的EC2.9规则的INFORMATIONAL级别告警,可扩展为如下模式:
{ "source": ["aws.securityhub"], "detail-type": ["Security Hub Findings - Imported"], "detail": { "Findings": { "GeneratorId": ["aws-foundational-security-best-practices/v/1.0.0/EC2.9"], "Severity": { "Label": ["INFORMATIONAL"] } } } }
测试与推送配置校验
- 匹配测试:不要直接用你手头的导出JSON测试,按照上述EventBridge标准事件结构构造测试数据,把你拿到的Findings数组放在
detail字段下即可测试通过 - Kinesis Firehose推送校验:规则匹配通过后如果无法正常推送,检查两个权限配置:
- EventBridge规则关联的IAM执行角色,必须包含
firehose:PutRecord权限,且资源字段指定目标Firehose的ARN - Kinesis Firehose自身的IAM权限配置正常,可正常写入下游存储目标
- EventBridge规则关联的IAM执行角色,必须包含
内容的提问来源于stack exchange,提问作者Bokambo
相关产品推荐
相关产品推荐

