You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
To integrate Wazuh with Amazon Security Lake, we have chosen the OCSF's Detection Finding class to map Wazuh's security events. This class in included in OCSF v1.1.0. Although ASL supports this version of OCSF, the class is not included in the form to create the Custom Source. This has been reported to Amazon, but by the time of creation of this issue, it's still not clear whether the form is updated to OCSF v1.1.0, or even if Amazon Security Lake is.
Below is the AWS CLI command used. Note that the values for roleArn, externalId and principal configurations need to be replaced accordingly, as per Prerequisites to adding a custom source.
Description
Related issue: #128
To integrate Wazuh with Amazon Security Lake, we have chosen the OCSF's Detection Finding class to map Wazuh's security events. This class in included in OCSF v1.1.0. Although ASL supports this version of OCSF, the class is not included in the form to create the Custom Source. This has been reported to Amazon, but by the time of creation of this issue, it's still not clear whether the form is updated to OCSF v1.1.0, or even if Amazon Security Lake is.
We need to investigate if it is possible to create a Custom Source for ASL using the AWS CLI.
The text was updated successfully, but these errors were encountered: