Set up Splunk Add-on for AWS Security Hub
Initial set up of Splunk Add-on for AWS Security Hub
Follow these steps for the initial set up of Splunk Add-on for AWS Security Hub:
-
In Splunk Web, go to the Manage Apps dashboard and select the Apps next to the apps list. Alternatively, you can select Apps and Manage Apps from the navigation menu.
-
Select Splunk Add-on for AWS Security Hub to open the Initial setup page and configure administrator AWS accounts before enabling export of data to AWS Security Hub.
-
In Delegated Administrator Account ID, enter your 12 digit AWS Account ID.
-
Select Add.
Set up the role definition
-
Select AWS setup button that is next to the added AWS Admin ID to view the instructions to set up a role in the Identity and Access Management Console that lets you export findings from the AWS Security Hub.
-
After you set up all the policies for your role, go to Export to Security Hub:data input section in the Initial setup page.
-
In Export pause time, enter the time in seconds to specify the time interval between each export to AWS Security Hub.
-
Enter values for the fields: Initial earliest delta, Latest delta time, and Overlap delta time, based on how far back in time you want to view the findings.
-
Enter values in Update tracking maximum size based on the maximum number of findings that you want to retain in the update tracking cache.Note: Removal of less frequently updated findings is prioritized.
-
In the Update tracking retention, enter a value for the maximum number of days for which you want to retain a finding in the update tracking cache. This value matches the AWS finding retention period.
-
In the Max retries field, enter a value for the maximum number of tries allowed to update a finding after an error.