|
| 1 | +--- |
| 2 | +mapped_pages: |
| 3 | + - https://www.elastic.co/guide/en/security/current/ingest-third-party-cloud-security-data.html |
| 4 | + - https://www.elastic.co/guide/en/serverless/current/ingest-third-party-cloud-security-data.html |
| 5 | +applies_to: |
| 6 | + stack: all |
| 7 | + serverless: |
| 8 | + security: all |
| 9 | +products: |
| 10 | + - id: security |
| 11 | + - id: cloud-serverless |
| 12 | +--- |
| 13 | + |
| 14 | +# Ingest third-party cloud security data |
| 15 | + |
| 16 | +This section describes how to ingest cloud security data from third-party tools into {{es}}. Once ingested, this data can provide additional context and enrich your {{elastic-sec}} workflows. |
| 17 | + |
| 18 | +You can ingest both third-party cloud workload protection data and third-party security posture and vulnerability data. |
| 19 | + |
| 20 | + |
| 21 | +## Ingest third-party workload protection data [_ingest_third_party_workload_protection_data] |
| 22 | + |
| 23 | +You can ingest third-party cloud security alerts into {{elastic-sec}} to view them on the [Alerts page](/solutions/security/advanced-entity-analytics/view-analyze-risk-score-data.md#alerts-page) and incorporate them into your triage and threat hunting workflows. |
| 24 | + |
| 25 | +* Learn to [ingest alerts from Sysdig Falco](/solutions/security/cloud/integrations/cncf-falco.md). |
| 26 | + |
| 27 | + |
| 28 | +## Ingest third-party security posture and vulnerability data [_ingest_third_party_security_posture_and_vulnerability_data] |
| 29 | + |
| 30 | +You can ingest third-party data into {{elastic-sec}} to review and investigate it alongside data collected by {{elastic-sec}}'s native cloud security integrations. Once ingested, cloud security posture and vulnerability data appears on the [**Findings**](/solutions/security/cloud/findings-page.md) page and in the [entity details](/solutions/security/advanced-entity-analytics/view-entity-details.md#entity-details-flyout) and [alert details](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) flyouts. |
| 31 | + |
| 32 | +::::{note} |
| 33 | +Data from third-party integrations does not appear on the [CNVM dashboard](/solutions/security/cloud/cnvm-dashboard.md) or the [Cloud Posture dashboard](/solutions/security/dashboards/cloud-security-posture-dashboard.md), |
| 34 | +:::: |
| 35 | + |
| 36 | +Data from each of the following integrations can feed into at least some of these workflows: |
| 37 | + |
| 38 | +* [AWS Config](/solutions/security/cloud/integrations/aws-config.md) |
| 39 | +* [AWS Inspector](/solutions/security/cloud/integrations/aws-inspector.md) |
| 40 | +* [AWS Security Hub](/solutions/security/cloud/integrations/aws-security-hub.md) |
| 41 | +* [Google Security Command Center](/solutions/security/cloud/integrations/google-security-command-center.md) |
| 42 | +* [Microsoft Defender for Cloud](/solutions/security/cloud/integrations/microsoft-defender-for-cloud.md) |
| 43 | +* [Microsoft Defender for Endpoint](/solutions/security/cloud/integrations/microsoft-defender-for-endpoint.md) |
| 44 | +* [Microsoft Defender XDR](/solutions/security/cloud/integrations/microsoft-defender-xdr.md) |
| 45 | +* [Qualys VMDR](/solutions/security/cloud/integrations/qualys.md) |
| 46 | +* [Rapid7 InsightVM](/solutions/security/cloud/integrations/rapid7.md) |
| 47 | +* [Tenable VM](/solutions/security/cloud/integrations/tenablevm.md) |
| 48 | +* [Wiz](/solutions/security/cloud/integrations/wiz.md) |
0 commit comments