
AWS GuardDuty
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Connect AWS GuardDuty to PostHog to sync your data into the PostHog data warehouse for analysis and modeling.
Sync GuardDuty findings, detectors, and member accounts from one AWS region. Enable GuardDuty in that region before syncing. Grant guardduty:ListDetectors, guardduty:GetDetector, guardduty:ListFindings, guardduty:GetFindings, and guardduty:ListMembers for all tables. The members table requires a GuardDuty administrator account. Findings use incremental sync through their update time. Other tables use full refresh.
Configuration
| Option | Description |
|---|---|
AWS access key IDType: text Required: True | |
AWS secret access keyType: password Required: True | |
AWS session tokenType: password Required: False | Temporary credentials expire. Reconnect with current credentials when the session token expires. |
AWS regionType: text Required: True |
Linking AWS GuardDuty to PostHog
- Go to the Data pipeline page in PostHog
- Click New source and select AWS GuardDuty
- Fill in the required configuration fields
- Click Next, select the tables you want to sync, and then press Import
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
findings | Threat findings, including severity, affected resources, and detection details. | Incremental, Full refresh | updated_at | — |
detectors | Detector status, enabled features, and configuration in the selected region. | Full refresh | — | — |
members | Member accounts and their relationship with the GuardDuty administrator account. | Full refresh | — | — |