AWS Security Hub

AWS Security Hub

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog

Connect AWS Security Hub to PostHog to sync your data into the PostHog data warehouse for analysis and modeling.

Sync Security Hub CSPM findings, standards, and custom insights from the configured AWS region.

Grant securityhub:GetFindings, securityhub:DescribeStandards, securityhub:GetEnabledStandards, and securityhub:GetInsights to the IAM user or role. Enter its access key ID and secret access key. Add a session token for temporary credentials. Enable Security Hub CSPM in the selected region. If you select an aggregation region, AWS can also return findings from linked regions.

Configuration

OptionDescription
AWS access key ID
Type: text
Required: True
AWS secret access key
Type: password
Required: True
AWS session token
Type: password
Required: False

Temporary credentials expire. Reconnect with new credentials when the session token expires.

AWS region
Type: text
Required: True

Linking AWS Security Hub to PostHog

  1. Go to the Data pipeline page in PostHog
  2. Click New source and select AWS Security Hub
  3. Fill in the required configuration fields
  4. Click Next, select the tables you want to sync, and then press Import

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
findings

Security findings with severity, resources, compliance status, and workflow status.

Incremental, Full refreshupdated_at—
standards

Available security standards and their descriptions.

Full refresh——
enabled_standards

Enabled security standards and their subscription status.

Full refresh——
insights

Custom insights with their filters and grouping fields. AWS managed insights are excluded.

Full refresh——