# AWS EventBridge (GuardDuty, Security Hub, AWS Health)

EvoHub receives AWS events from **Amazon EventBridge**, either directly through an **API destination** or through an **SNS topic**. GuardDuty findings, Security Hub findings and AWS Health events are read field by field; any other event you route opens one alert per event.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **AWS EventBridge**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**; the integration key is the value after `key=`.
### Create the API destination
In the EventBridge console, go to **API destinations → Create API destination**. Set **API destination endpoint** to your webhook URL and **HTTP method** to `POST`. Create a new **connection** with **Authorization type** *API Key*, **API key name** `X-EvoHub-Key` and the integration key as **Value**.
### Create a rule
Go to **Rules → Create rule**, choose an event pattern (see below) and select the API destination as the target. Keep the target input as **Matched events** — do not add an input transformer; EvoHub needs the event as AWS sends it.
:::

### Or use an SNS topic

Make an SNS topic the rule's target and add a subscription with **Protocol** HTTPS and **Endpoint** your webhook URL. EvoHub verifies the SNS signature on every message and confirms the subscription by itself; check in SNS that it shows an ARN rather than *PendingConfirmation*. Raw message delivery can be on or off.

### Event patterns

GuardDuty findings of high severity and above:

```json
{"source": ["aws.guardduty"], "detail-type": ["GuardDuty Finding"], "detail": {"severity": [{"numeric": [">=", 7]}]}}
```

Security Hub findings — pick the format your Security Hub sends:

```json
{"source": ["aws.securityhub"], "detail-type": ["Security Hub Findings - Imported"]}
```

```json
{"source": ["aws.securityhub"], "detail-type": ["Findings Imported V2"]}
```

AWS Health events:

```json
{"source": ["aws.health"], "detail-type": ["AWS Health Event"]}
```

:::warning
GuardDuty findings are also imported into Security Hub. Route one of the two to EvoHub, not both, or every finding pages twice.
:::

## What EvoHub reads

| Event | Title | Severity | Resolves when |
| --- | --- | --- | --- |
| GuardDuty finding | The finding title. | 9.0–10 critical, 7.0–8.9 high, 4.0–6.9 medium, below 4 low. | GuardDuty sends no recovery — resolve in EvoHub. An archived finding, if sent, resolves. |
| Security Hub finding (ASFF) | `Title`. | `Severity.Label`: critical, high, medium, low, informational. | The record is archived, the workflow status is resolved or suppressed, or the control check passes. |
| Security Hub finding (OCSF) | `finding_info.title`. | `severity` (or `severity_id`). | The status is suppressed, resolved or archived, the finding is closed, or the compliance check passes. |
| AWS Health event | Service and event type code. | Issue high, investigation medium, scheduled change low, account notification info. | `statusCode` is closed. |
| Any other event | The detail type and first resource. | Medium. | Never — resolve in EvoHub. |

The description is the finding description with its remediation text, the Health event description, or the event's `detail` for any other event. Every alert is labelled with the AWS `source`, `detail_type`, `account` and `region`; findings also carry the resource, finding type, product and a console or remediation link.

## Deduplication

- A GuardDuty finding that recurs is sent again with the same ID and is recorded as **Retriggered** on the open alert.
- Security Hub findings are keyed by product and finding ID; each finding in an event is its own alert.
- AWS Health events are keyed by event ARN and affected account. Backup copies that AWS delivers in a second Region are ignored.

## Related

- [AWS CloudTrail](https://docs-dev.evohub.io/aws-cloudtrail.md)
- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
