Integrations
AWS EventBridge (GuardDuty, Security Hub, AWS Health)
EvoHub receives AWS events from Amazon EventBridge, either directly through an API destination or through an SNS topic. GuardDuty findings, Security Hub findings and AWS Health events are read field by field; any other event you route opens one alert per event.
Set it up
Create the integration
In EvoHub, go to On-Call → Integrations → + Add Integration, choose AWS EventBridge, pick an Escalation Policy and click Create Integration. Copy the Webhook URL; the integration key is the value after key=.
Or use an SNS topic
Make an SNS topic the rule's target and add a subscription with Protocol HTTPS and Endpoint your webhook URL. EvoHub verifies the SNS signature on every message and confirms the subscription by itself; check in SNS that it shows an ARN rather than PendingConfirmation. Raw message delivery can be on or off.
Event patterns
GuardDuty findings of high severity and above:
{"source": ["aws.guardduty"], "detail-type": ["GuardDuty Finding"], "detail": {"severity": [{"numeric": [">=", 7]}]}}
Security Hub findings — pick the format your Security Hub sends:
{"source": ["aws.securityhub"], "detail-type": ["Security Hub Findings - Imported"]}
{"source": ["aws.securityhub"], "detail-type": ["Findings Imported V2"]}
AWS Health events:
{"source": ["aws.health"], "detail-type": ["AWS Health Event"]}
GuardDuty findings are also imported into Security Hub. Route one of the two to EvoHub, not both, or every finding pages twice.
What EvoHub reads
| Event | Title | Severity | Resolves when |
|---|---|---|---|
| GuardDuty finding | The finding title. | 9.0–10 critical, 7.0–8.9 high, 4.0–6.9 medium, below 4 low. | GuardDuty sends no recovery — resolve in EvoHub. An archived finding, if sent, resolves. |
| Security Hub finding (ASFF) | Title. |
Severity.Label: critical, high, medium, low, informational. |
The record is archived, the workflow status is resolved or suppressed, or the control check passes. |
| Security Hub finding (OCSF) | finding_info.title. |
severity (or severity_id). |
The status is suppressed, resolved or archived, the finding is closed, or the compliance check passes. |
| AWS Health event | Service and event type code. | Issue high, investigation medium, scheduled change low, account notification info. | statusCode is closed. |
| Any other event | The detail type and first resource. | Medium. | Never — resolve in EvoHub. |
The description is the finding description with its remediation text, the Health event description, or the event's detail for any other event. Every alert is labelled with the AWS source, detail_type, account and region; findings also carry the resource, finding type, product and a console or remediation link.
Deduplication
- A GuardDuty finding that recurs is sent again with the same ID and is recorded as Retriggered on the open alert.
- Security Hub findings are keyed by product and finding ID; each finding in an event is its own alert.
- AWS Health events are keyed by event ARN and affected account. Backup copies that AWS delivers in a second Region are ignored.
Related
Was this page helpful?
