Skip to content

Commit 67fe9d1

Browse files
committed
Adds AWS Inspector cloud workflows guide & reorganizes docs section
1 parent c0172ce commit 67fe9d1

File tree

11 files changed

+43
-19
lines changed

11 files changed

+43
-19
lines changed

solutions/security/cloud/integrations/aws-config-integration.md renamed to solutions/security/cloud/integrations/aws-config.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,12 +12,12 @@ products:
1212

1313
This page explains how to make data from the AWS Config integration appear in the following places within {{elastic-sec}}:
1414

15-
- **Findings page**: Data appears on the Findings page's [Misconfigurations](/solutions/security/cloud/findings-page.md) tab.
15+
- **Findings page**: Data appears on the [Misconfigurations](/solutions/security/cloud/findings-page.md) tab.
1616
- **Alert and Entity details flyouts**: Data appears in the Insights section of the [Alert](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) and [Entity](/solutions/security/advanced-entity-analytics/view-entity-details.md#insights) details flyouts.
1717

1818

1919
In order for AWS Config data to appear in these workflows:
2020

2121
* Follow the steps to [set up the AWS Config integration](https://docs.elastic.co/en/integrations/aws/config).
2222
* Make sure the integration version is at least 4.0.0.
23-
* Ensure you have `read` privileges for the following indices: `security_solution-*.misconfiguration_latest`.
23+
* Ensure you have `read` privileges for the following index: `security_solution-*.misconfiguration_latest`.
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
applies_to:
3+
stack: ga 9.2
4+
serverless:
5+
security: all
6+
products:
7+
- id: security
8+
- id: cloud-serverless
9+
---
10+
11+
# AWS Inspector
12+
13+
This page explains how to make data from the AWS Inspector integration appear in the following places within {{elastic-sec}}:
14+
15+
- **Findings page**: Data appears on the [Vulnerabilities](/solutions/security/cloud/findings-page.md) tab.
16+
- **Alert and Entity details flyouts**: Data appears in the Insights section of the [Alert](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) and [Entity](/solutions/security/advanced-entity-analytics/view-entity-details.md#insights) details flyouts.
17+
18+
19+
In order for AWS Inspector data to appear in these workflows:
20+
21+
* Follow the steps to [set up the AWS Inspector integration](https://www.elastic.co/docs/reference/integrations/aws/inspector).
22+
* Make sure the integration version is at least 4.0.0.
23+
* Ensure you have `read` privileges for the following index: `security_solution-*.vulnerability_latest`.
File renamed without changes.
File renamed without changes.

solutions/security/cloud/integrations/google-security-command-center.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ products:
1212

1313
This page explains how to make data from the Google Security Command Center integration appear in the following workflows within {{elastic-sec}}:
1414

15-
- **Findings page**: Data appears on the [Findings page's](/solutions/security/cloud/findings-page.md) **Vulnerabilities** tab and **Misconfigurations** tab.
15+
- **Findings page**: Data appears on the [Vulnerabilities](/solutions/security/cloud/findings-page-3.md) tab and the [Misconfiguations](/solutions/security/cloud/findings-page.md) tab.
1616
- **Alert and Entity details flyouts**: Data appears in the **Insights** section of the [Alert](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) and [Entity](/solutions/security/advanced-entity-analytics/view-entity-details.md#insights) details flyouts.
1717

1818

solutions/security/cloud/ingest-third-party-cloud-security-data.md renamed to solutions/security/cloud/integrations/ingest-third-party-cloud-security-data.md

Lines changed: 16 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -29,10 +29,21 @@ You can ingest third-party cloud security alerts into {{elastic-sec}} to view th
2929

3030
You can ingest third-party data into {{elastic-sec}} to review and investigate it alongside data collected by {{elastic-sec}}'s native cloud security integrations. Once ingested, cloud security posture and vulnerability data appears on the [Findings](/solutions/security/cloud/findings-page.md) page, on the [Cloud Posture dashboard](/solutions/security/dashboards/cloud-security-posture-dashboard.md), and in the [entity details](/solutions/security/advanced-entity-analytics/view-entity-details.md#entity-details-flyout) and [alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) flyouts.
3131

32+
::::{note}
33+
Data from third-party integration does not appear on the [CNVM dashboard](/solutions/security/cloud/cnvm-dashboard.md).
34+
::::
35+
3236
Data from each of the following integrations can feed into at least some of these workflows:
3337

34-
* [AWS Security Hub](/solutions/security/cloud/ingest-aws-security-hub-data.md).
35-
* [Wiz](/solutions/security/cloud/ingest-wiz-data.md).
36-
* [Rapid7 InsightVM](/solutions/security/cloud/integration-rapid7.md).
37-
* [Tenable VM](/solutions/security/cloud/integration-tenablevm.md).
38-
* [Qualys VMDR](/solutions/security/cloud/integration-qualys.md).
38+
* [AWS Config](solutions/security/cloud/integrations/aws-config.md)
39+
* [AWS Inspector](solutions/security/cloud/integrations/aws-inspector.md)
40+
* [AWS Security Hub](/solutions/security/cloud/integrations/aws-security-hub.md).
41+
* [CNCF Falco](/solutions/security/cloud/integrations/cncf-falco.md)
42+
* [Google Security Command Center](/solutions/security/cloud/integrations/google-security-command-center.md)
43+
* [Microsoft Defender for Cloud](/solutions/security/cloud/integrations/microsoft-defender-for-cloud.md).
44+
* [Microsoft Defender for Endpoint](/solutions/security/cloud/integrations/microsoft-defender-for-endpoint.md).
45+
* [Microsoft Defender XDR](/solutions/security/cloud/integrations/microsoft-defender-xdr.md).
46+
* [Qualys VMDR](/solutions/security/cloud/integrations/qualys.md).
47+
* [Rapid7 InsightVM](/solutions/security/cloud/integrations/rapid7.md).
48+
* [Tenable VM](/solutions/security/cloud/integrations/tenablevm.md).
49+
* [Wiz](/solutions/security/cloud/integrations/wiz.md).

solutions/security/cloud/integration-qualys.md renamed to solutions/security/cloud/integrations/qualys.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,6 @@ This page explains how to make data from the Qualys Vulnerability Management, De
1515
- **Findings page**: Data appears on the [Vulnerabilities](/solutions/security/cloud/findings-page-3.md) tab.
1616
- **Alert and Entity details flyouts**: Applicable data appears in the [Insights section](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section).
1717

18-
:::{note}
19-
Data from this integration does not appear on the [CNVM dashboard](/solutions/security/cloud/cnvm-dashboard.md).
20-
:::
21-
2218
In order for Qualys VMDR data to appear in these workflows:
2319

2420
- Ensure you have read privileges for the following index: `security_solution-*.vulnerability_latest`.

solutions/security/cloud/integration-rapid7.md renamed to solutions/security/cloud/integrations/rapid7.md

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,6 @@ This page explains how to make data from the Rapid7 InsightVM integration (Rapid
1515
- **Findings page**: Data appears on the [Vulnerabilities](/solutions/security/cloud/findings-page-3.md) tab.
1616
- **Alert and Entity details flyouts**: Applicable data appears in the [Insights section](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section).
1717

18-
:::{note}
19-
Data from this integration does not appear on the [CNVM dashboard](/solutions/security/cloud/cnvm-dashboard.md).
20-
:::
2118

2219
In order for Rapid7 data to appear in these workflows:
2320

solutions/security/cloud/integration-tenablevm.md renamed to solutions/security/cloud/integrations/tenablevm.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,6 @@ This page explains how to make data from the Tenable Vulnerability Management in
1515
- **Findings page**: Data appears on the [Vulnerabilities](/solutions/security/cloud/findings-page-3.md) tab.
1616
- **Alert and Entity details flyouts**: Applicable data appears in the [Insights section](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section).
1717

18-
::::{note}
19-
Data from this integration does not appear on the [CNVM dashboard](/solutions/security/cloud/cnvm-dashboard.md).
20-
::::
21-
2218
In order for Tenable VM data to appear in these workflows:
2319

2420
- Ensure you have read privileges for the following index: `security_solution-*.vulnerability_latest`.
File renamed without changes.

0 commit comments

Comments
 (0)