AWS GuardDuty

AWS GuardDuty

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog

Connect AWS GuardDuty to PostHog to sync your data into the PostHog data warehouse for analysis and modeling.

Sync GuardDuty findings, detectors, and member accounts from one AWS region. Enable GuardDuty in that region before syncing. Grant guardduty:ListDetectors, guardduty:GetDetector, guardduty:ListFindings, guardduty:GetFindings, and guardduty:ListMembers for all tables. The members table requires a GuardDuty administrator account. Findings use incremental sync through their update time. Other tables use full refresh.

Configuration

OptionDescription
AWS access key ID
Type: text
Required: True
AWS secret access key
Type: password
Required: True
AWS session token
Type: password
Required: False

Temporary credentials expire. Reconnect with current credentials when the session token expires.

AWS region
Type: text
Required: True

Linking AWS GuardDuty to PostHog

  1. Go to the Data pipeline page in PostHog
  2. Click New source and select AWS GuardDuty
  3. Fill in the required configuration fields
  4. Click Next, select the tables you want to sync, and then press Import

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
findings

Threat findings, including severity, affected resources, and detection details.

Incremental, Full refreshupdated_at—
detectors

Detector status, enabled features, and configuration in the selected region.

Full refresh——
members

Member accounts and their relationship with the GuardDuty administrator account.

Full refresh——