EvoHub Docs Sign in

Integrations

AWS EventBridge (GuardDuty, Security Hub, AWS Health)

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

EvoHub receives AWS events from Amazon EventBridge, either directly through an API destination or through an SNS topic. GuardDuty findings, Security Hub findings and AWS Health events are read field by field; any other event you route opens one alert per event.

Set it up

Create the integration

In EvoHub, go to On-Call → Integrations → + Add Integration, choose AWS EventBridge, pick an Escalation Policy and click Create Integration. Copy the Webhook URL; the integration key is the value after key=.

Create the API destination

In the EventBridge console, go to API destinations → Create API destination. Set API destination endpoint to your webhook URL and HTTP method to POST. Create a new connection with Authorization type API Key, API key name X-EvoHub-Key and the integration key as Value.

Create a rule

Go to Rules → Create rule, choose an event pattern (see below) and select the API destination as the target. Keep the target input as Matched events — do not add an input transformer; EvoHub needs the event as AWS sends it.

Or use an SNS topic

Make an SNS topic the rule's target and add a subscription with Protocol HTTPS and Endpoint your webhook URL. EvoHub verifies the SNS signature on every message and confirms the subscription by itself; check in SNS that it shows an ARN rather than PendingConfirmation. Raw message delivery can be on or off.

Event patterns

GuardDuty findings of high severity and above:

{"source": ["aws.guardduty"], "detail-type": ["GuardDuty Finding"], "detail": {"severity": [{"numeric": [">=", 7]}]}}

Security Hub findings — pick the format your Security Hub sends:

{"source": ["aws.securityhub"], "detail-type": ["Security Hub Findings - Imported"]}
{"source": ["aws.securityhub"], "detail-type": ["Findings Imported V2"]}

AWS Health events:

{"source": ["aws.health"], "detail-type": ["AWS Health Event"]}

GuardDuty findings are also imported into Security Hub. Route one of the two to EvoHub, not both, or every finding pages twice.

What EvoHub reads

Event Title Severity Resolves when
GuardDuty finding The finding title. 9.0–10 critical, 7.0–8.9 high, 4.0–6.9 medium, below 4 low. GuardDuty sends no recovery — resolve in EvoHub. An archived finding, if sent, resolves.
Security Hub finding (ASFF) Title. Severity.Label: critical, high, medium, low, informational. The record is archived, the workflow status is resolved or suppressed, or the control check passes.
Security Hub finding (OCSF) finding_info.title. severity (or severity_id). The status is suppressed, resolved or archived, the finding is closed, or the compliance check passes.
AWS Health event Service and event type code. Issue high, investigation medium, scheduled change low, account notification info. statusCode is closed.
Any other event The detail type and first resource. Medium. Never — resolve in EvoHub.

The description is the finding description with its remediation text, the Health event description, or the event's detail for any other event. Every alert is labelled with the AWS source, detail_type, account and region; findings also carry the resource, finding type, product and a console or remediation link.

Deduplication

  • A GuardDuty finding that recurs is sent again with the same ID and is recorded as Retriggered on the open alert.
  • Security Hub findings are keyed by product and finding ID; each finding in an event is its own alert.
  • AWS Health events are keyed by event ARN and affected account. Backup copies that AWS delivers in a second Region are ignored.

Last updated