diff --git a/solutions/security/cloud/integrations/aws-config-integration.md b/solutions/security/cloud/integrations/aws-config-integration.md new file mode 100644 index 0000000000..212adff71b --- /dev/null +++ b/solutions/security/cloud/integrations/aws-config-integration.md @@ -0,0 +1,23 @@ +--- +applies_to: + stack: ga 9.2 + serverless: + security: all +products: + - id: security + - id: cloud-serverless +--- + +# AWS Config + +This page explains how to make data from the AWS Config integration appear in the following places within {{elastic-sec}}: + +- **Findings page**: Data appears on the Findings page's [Misconfigurations](/solutions/security/cloud/findings-page.md) tab. +- **Alert and Entity details flyouts**: Data appears in the Insights section of the [Alert](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) and [Entity](/solutions/security/advanced-entity-analytics/view-entity-details.md#insights) details flyouts. + + +In order for AWS Config data to appear in these workflows: + +* Follow the steps to [set up the AWS Config integration](https://docs.elastic.co/en/integrations/aws/config). +* Make sure the integration version is at least 4.0.0. +* Ensure you have `read` privileges for the following indices: `security_solution-*.misconfiguration_latest`. \ No newline at end of file diff --git a/solutions/toc.yml b/solutions/toc.yml index c0607d0918..325671d671 100644 --- a/solutions/toc.yml +++ b/solutions/toc.yml @@ -681,6 +681,7 @@ toc: - file: security/cloud/integration-qualys.md - file: security/cloud/integration-tenablevm.md - file: security/cloud/integration-rapid7.md + - file: security/cloud/integrations/aws-config-integration.md - file: security/investigate.md children: - file: security/investigate/timeline.md