Set up Splunk Add-on for AWS Security Hub

Initial set up of Splunk Add-on for AWS Security Hub

Follow these steps for the initial set up of Splunk Add-on for AWS Security Hub:

Note: You must have a 12 digit AWS administrator ID to set up the Splunk Add-on for AWS Security Hub. Only admin accounts can identify the specific AWS findings that can
  1. In Splunk Web, go to the Manage Apps dashboard and select the Apps next to the apps list. Alternatively, you can select Apps and Manage Apps from the navigation menu.

  2. Select Splunk Add-on for AWS Security Hub to open the Initial setup page and configure administrator AWS accounts before enabling export of data to AWS Security Hub.

  3. In Delegated Administrator Account ID, enter your 12 digit AWS Account ID.

  4. Select Add.

Set up the role definition

  1. Select AWS setup button that is next to the added AWS Admin ID to view the instructions to set up a role in the Identity and Access Management Console that lets you export findings from the AWS Security Hub.

  2. After you set up all the policies for your role, go to Export to Security Hub:data input section in the Initial setup page.

  3. In Export pause time, enter the time in seconds to specify the time interval between each export to AWS Security Hub.

  4. Enter values for the fields: Initial earliest delta, Latest delta time, and Overlap delta time, based on how far back in time you want to view the findings.

  5. Enter values in Update tracking maximum size based on the maximum number of findings that you want to retain in the update tracking cache.
    Note: Removal of less frequently updated findings is prioritized.
  6. In the Update tracking retention, enter a value for the maximum number of days for which you want to retain a finding in the update tracking cache. This value matches the AWS finding retention period.

  7. In the Max retries field, enter a value for the maximum number of tries allowed to update a finding after an error.