How the security agent connects to GuardDuty
The Runtime Monitoring security agent delivers runtime events to GuardDuty. The data remains within the AWS network. There is no additional cost for the connectivity that GuardDuty configures. To authenticate the agent, GuardDuty uses Instance identity roles. For Amazon ECS on Fargate, GuardDuty uses the task execution role; see Permissions requirements.
With automated agent configuration, GuardDuty establishes connectivity automatically. If you manage the agent manually, you need to create an Amazon VPC endpoint.
Amazon VPC endpoint connectivity
The agent connects to the GuardDuty backend through an Amazon VPC endpoint. It resolves and connects
to the endpoint's private DNS name. For a non-FIPS endpoint, this is
guardduty-data.. The AWS Region
(us-east-1.amazonaws.comus-east-1) changes based on your Region.
The resource must have a valid network path to an active guardduty-data Amazon VPC
endpoint. GuardDuty selects the subnet based on IP availability, so for advanced network topologies,
validate that connectivity is possible.
Prerequisites
For prerequisites, see Prerequisites to enabling Runtime Monitoring.
Considerations
-
All VPCs – With automated agent configuration, GuardDuty sets up connectivity across all your VPCs, including centralized and spoke VPCs. For more information about centralized VPCs, see Interface VPC endpoints in the AWS Whitepaper - Building a Scalable and Secure Multi-VPC AWS Network Infrastructure.
-
Shared VPC – If you use a shared VPC, GuardDuty uses that shared VPC to receive runtime events from your resources after the prerequisites are met. See Using shared VPC with Runtime Monitoring.