- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to ingest Security Hub log into Splunk- apart from HEC method
Hi,
How to ingest Security Hub logs to splunk without using HEC token, do we have any Add-on? to ingest Security Hub logs to splunk?
GuardDuty will be integrated into Security Hub first then sent out from security hub together with other events into splunk.
Thanks,
Vijay Sri S
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@gcusello do you have the steps to configure the app?
I have installed the app but not sure on further steps. The steps provided in the installation page is not clear
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @VijaySrrie,
No sorry I didn't used it, here you can find some docs
https://www.splunk.com/en_us/form/stay-afloat-using-aws-security-hub.html
https://www.youtube.com/watch?v=7pd2PLMVqrA
https://github.com/splunk/splunk-for-securityHub
https://pages.awscloud.com/rs/112-TZM-766/images/Global_PTNR_AWS_Splunk_Ebook_09252019.pdf
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @VijaySrrie,
did you tried to use AWS Security Hub App (https://splunkbase.splunk.com/app/5767/)?
It's a Splunk supported App, so you can also open a case to Splunk.
Ciao.
Giuseppe
