| 
 | 1 | +---  | 
 | 2 | +mapped_pages:  | 
 | 3 | +  - https://www.elastic.co/guide/en/security/current/ingest-third-party-cloud-security-data.html  | 
 | 4 | +  - https://www.elastic.co/guide/en/serverless/current/ingest-third-party-cloud-security-data.html  | 
 | 5 | +applies_to:  | 
 | 6 | +  stack: all  | 
 | 7 | +  serverless:  | 
 | 8 | +    security: all  | 
 | 9 | +products:  | 
 | 10 | +  - id: security  | 
 | 11 | +  - id: cloud-serverless  | 
 | 12 | +---  | 
 | 13 | + | 
 | 14 | +# Ingest third-party cloud security data  | 
 | 15 | + | 
 | 16 | +This section describes how to ingest cloud security data from third-party tools into {{es}}. Once ingested, this data can provide additional context and enrich your {{elastic-sec}} workflows.  | 
 | 17 | + | 
 | 18 | +You can ingest both third-party cloud workload protection data and third-party security posture and vulnerability data.  | 
 | 19 | + | 
 | 20 | + | 
 | 21 | +## Ingest third-party workload protection data [_ingest_third_party_workload_protection_data]  | 
 | 22 | + | 
 | 23 | +You can ingest third-party cloud security alerts into {{elastic-sec}} to view them on the [Alerts page](/solutions/security/advanced-entity-analytics/view-analyze-risk-score-data.md#alerts-page) and incorporate them into your triage and threat hunting workflows.  | 
 | 24 | + | 
 | 25 | +* Learn to [ingest alerts from Sysdig Falco](/solutions/security/cloud/integrations/cncf-falco.md).  | 
 | 26 | + | 
 | 27 | + | 
 | 28 | +## Ingest third-party security posture and vulnerability data [_ingest_third_party_security_posture_and_vulnerability_data]  | 
 | 29 | + | 
 | 30 | +You can ingest third-party data into {{elastic-sec}} to review and investigate it alongside data collected by {{elastic-sec}}'s native cloud security integrations. Once ingested, cloud security posture and vulnerability data appears on the [**Findings**](/solutions/security/cloud/findings-page.md) page and in the [entity details](/solutions/security/advanced-entity-analytics/view-entity-details.md#entity-details-flyout) and [alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) flyouts.  | 
 | 31 | + | 
 | 32 | +::::{note}  | 
 | 33 | +Data from third-party integrations does not appear on the [CNVM dashboard](/solutions/security/cloud/cnvm-dashboard.md) or the [Cloud Posture dashboard](/solutions/security/dashboards/cloud-security-posture-dashboard.md),  | 
 | 34 | +::::  | 
 | 35 | + | 
 | 36 | +Data from each of the following integrations can feed into at least some of these workflows:  | 
 | 37 | + | 
 | 38 | +* [AWS Config](/solutions/security/cloud/integrations/aws-config.md)  | 
 | 39 | +* [AWS Inspector](/solutions/security/cloud/integrations/aws-inspector.md)  | 
 | 40 | +* [AWS Security Hub](/solutions/security/cloud/integrations/aws-security-hub.md)  | 
 | 41 | +* [Google Security Command Center](/solutions/security/cloud/integrations/google-security-command-center.md)  | 
 | 42 | +* [Microsoft Defender for Cloud](/solutions/security/cloud/integrations/microsoft-defender-for-cloud.md)  | 
 | 43 | +* [Microsoft Defender for Endpoint](/solutions/security/cloud/integrations/microsoft-defender-for-endpoint.md)  | 
 | 44 | +* [Microsoft Defender XDR](/solutions/security/cloud/integrations/microsoft-defender-xdr.md)  | 
 | 45 | +* [Qualys VMDR](/solutions/security/cloud/integrations/qualys.md)  | 
 | 46 | +* [Rapid7 InsightVM](/solutions/security/cloud/integrations/rapid7.md)  | 
 | 47 | +* [Tenable VM](/solutions/security/cloud/integrations/tenablevm.md)  | 
 | 48 | +* [Wiz](/solutions/security/cloud/integrations/wiz.md)  | 
0 commit comments