Supported third-party sources for data sources - Amazon CloudWatch Logs
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

Supported third-party sources for data sources

The following table lists the third-party sources that are automatically categorized by CloudWatch Logs as data sources when ingested through pipelines:

Data Source Name (@data_source_name field) Data Source Type (@data_source_type field)
cisco_umbrella data_security_finding
cisco_umbrella dns_activity
cisco_umbrella entity_management
cisco_umbrella network_activity
crowdstrike_falcon detection_finding
crowdstrike_falcon process_activity
github_auditlogs account_change
github_auditlogs api_activity
github_auditlogs entity_management
microsoft_entraid account_change
microsoft_entraid authentication
microsoft_entraid entity_management
microsoft_entraid user_access_management
microsoft_office365 account_change
microsoft_office365 application_lifecycle
microsoft_office365 authentication
microsoft_office365 compliance_finding
microsoft_office365 detection_finding
microsoft_office365 email_activity
microsoft_office365 file_hosting_activity
microsoft_office365 group_management
microsoft_office365 incident_finding
microsoft_office365 user_access_management
microsoft_office365 vulnerability_finding
microsoft_office365 web_resources_activity
microsoft_windows account_change
microsoft_windows authentication
microsoft_windows entity_management
microsoft_windows event_log_activity
microsoft_windows file_system_activity
microsoft_windows group_management
microsoft_windows kernel_activity
okta_auth0 api_activity
okta_auth0 authentication
okta_sso api_activity
okta_sso authentication
okta_sso detection_finding
okta_sso entity_management
paloaltonetworks_nextgenerationfirewall authentication
paloaltonetworks_nextgenerationfirewall detection_finding
paloaltonetworks_nextgenerationfirewall network_activity
paloaltonetworks_nextgenerationfirewall process_activity
sentinelone_endpointsecurity dns_activity
sentinelone_endpointsecurity file_system_activity
sentinelone_endpointsecurity http_activity
sentinelone_endpointsecurity process_activity
servicenow_cmdb api_activity
servicenow_cmdb datastore_activity
servicenow_cmdb entity_management
wiz_cnapp api_activity
wiz_cnapp authentication
wiz_cnapp compliance_finding
wiz_cnapp detection_finding
wiz_cnapp vulnerability_finding
zscaler_internetaccess authentication
zscaler_internetaccess dns_activity
zscaler_internetaccess http_activity
zscaler_internetaccess network_activity

Additional third-party sources via AWS Security Hub CSPM

Additional third-party security findings are available through AWS Security Hub CSPM integration. The following partners send findings to Security Hub CSPM, which are then available as data sources in CloudWatch Logs. For comprehensive details about these integrations, see Third-party product integrations with Security Hub CSPM in the AWS Security Hub User Guide.

Partner Integration
3CORESec – NTASends findings via Security Hub CSPM
Alert Logic – SIEMless Threat ManagementSends findings via Security Hub CSPM
Aqua Security – Cloud Native Security PlatformSends findings via Security Hub CSPM
Aqua Security – Kube-benchSends findings via Security Hub CSPM
Armor – Armor AnywhereSends findings via Security Hub CSPM
AttackIQSends findings via Security Hub CSPM
Barracuda Networks – Cloud Security GuardianSends findings via Security Hub CSPM
BigID – BigID EnterpriseSends findings via Security Hub CSPM
Blue HexagonSends findings via Security Hub CSPM
Check Point – CloudGuard IaaSSends findings via Security Hub CSPM
Check Point – CloudGuard Posture ManagementSends findings via Security Hub CSPM
Claroty – xDomeSends findings via Security Hub CSPM
Cloud Storage Security – Antivirus for Amazon S3Sends findings via Security Hub CSPM
Contrast Security – Contrast AssessSends findings via Security Hub CSPM
CrowdStrike – CrowdStrike FalconSends findings via Security Hub CSPM
CyberArk – Privileged Threat AnalyticsSends findings via Security Hub CSPM
Data TheoremSends findings via Security Hub CSPM
DrataSends findings via Security Hub CSPM
Forcepoint – CASBSends findings via Security Hub CSPM
Forcepoint – Cloud Security GatewaySends findings via Security Hub CSPM
Forcepoint – DLPSends findings via Security Hub CSPM
Forcepoint – NGFWSends findings via Security Hub CSPM
FugueSends findings via Security Hub CSPM
Guardicore – CentraSends findings via Security Hub CSPM
HackerOne – Vulnerability IntelligenceSends findings via Security Hub CSPM
JFrog – XraySends findings via Security Hub CSPM
Juniper Networks – vSRX Next Generation FirewallSends findings via Security Hub CSPM
k9 Security – Access AnalyzerSends findings via Security Hub CSPM
LaceworkSends findings via Security Hub CSPM
McAfee – MVISION CNAPPSends findings via Security Hub CSPM
NETSCOUT – Cyber InvestigatorSends findings via Security Hub CSPM
Orca – Cloud Security PlatformSends findings via Security Hub CSPM
Palo Alto Networks – Prisma Cloud ComputeSends findings via Security Hub CSPM
Palo Alto Networks – Prisma Cloud EnterpriseSends findings via Security Hub CSPM
Plerion – Cloud Security PlatformSends findings via Security Hub CSPM
ProwlerSends findings via Security Hub CSPM
Qualys – Vulnerability ManagementSends findings via Security Hub CSPM
Rapid7 – InsightVMSends findings via Security Hub CSPM
SentinelOneSends findings via Security Hub CSPM
SnykSends findings via Security Hub CSPM
Sonrai Security – Sonrai DigSends findings via Security Hub CSPM
Sophos – Server ProtectionSends findings via Security Hub CSPM
StackRox – Kubernetes SecuritySends findings via Security Hub CSPM
Sumo Logic – Machine Data AnalyticsSends findings via Security Hub CSPM
Symantec – Cloud Workload ProtectionSends findings via Security Hub CSPM
Tenable.ioSends findings via Security Hub CSPM
Trend Micro – Cloud OneSends findings via Security Hub CSPM
Vectra – Cognito DetectSends findings via Security Hub CSPM
WizSends findings via Security Hub CSPM
Caveonix – Caveonix CloudSends and receives findings via Security Hub CSPM
Cloud CustodianSends and receives findings via Security Hub CSPM
DisruptOpsSends and receives findings via Security Hub CSPM
KionSends and receives findings via Security Hub CSPM
TurbotSends and receives findings via Security Hub CSPM
Note

This list reflects the Security Hub partner integrations that send findings at the time of writing. Because AWS Security Hub regularly adds new partner integrations, refer to Third-party product integrations with Security Hub CSPM in the AWS Security Hub User Guide for the most up-to-date list of available partners.