Amazon Security Lake
Amazon Security Lake is a service that automatically centralizes an organization's security data from cloud, on-premises, and custom sources into a purpose-built data lake stored in your own Amazon S3. It manages the data lifecycle to help you optimize storage and supports OCSF (Open Cybersecurity Schema Framework) for normalized security data analysis.
APIs
Amazon Security Lake API
The Amazon Security Lake API provides programmatic access to create and manage data lakes, data sources, subscribers, and log sources for centralizing and analyzing security dat...
Capabilities
Amazon Security Lake Security Data Lake
Unified capability for managing a centralized security data lake including data lake configuration, log source ingestion, and subscriber access management. Used by Security Data...
Run with NaftikoFeatures
Automatically centralizes security data from AWS services, third-party tools, and custom sources into a single data lake.
Converts security data to the Open Cybersecurity Schema Framework (OCSF) for standardized analysis across tools.
Stores all security data in Apache Parquet format optimized for analytical query performance.
Centralizes security data across an entire AWS Organization from all accounts and regions.
Automatically manages storage lifecycle with configurable retention and tiering policies.
Grant third-party SIEMs and analytics tools direct query access to your security data lake.
Native connectors for CloudTrail, VPC Flow Logs, Route 53, Security Hub, and EKS audit logs.
Ingest custom and third-party security data sources in OCSF format.
Use Cases
Aggregate all security data from across a multi-account AWS environment into one queryable data lake.
Provide SIEM platforms like Splunk, Sumo Logic, and Microsoft Sentinel direct access to normalized security data.
Enable security analysts to query normalized OCSF data for threat hunting and forensic investigation.
Retain security logs in a cost-optimized data lake for compliance audit requirements.
Run advanced analytics and ML models against normalized security data for anomaly detection.
Centralize security data from on-premises and other cloud providers alongside AWS security data.
Integrations
Native connector for management event and data event logs from CloudTrail.
Ingest VPC network flow logs for network traffic analysis.
Collect DNS query logs for domain analysis and threat detection.
Aggregate Security Hub findings into the security data lake.
Ingest Kubernetes audit logs from Amazon EKS clusters.
All security data is stored in S3 buckets within your own AWS account.
Control fine-grained subscriber access using AWS Lake Formation permissions.
SIEM subscriber integration for Splunk to query Security Lake data directly.
Connect Microsoft Sentinel as a subscriber to consume OCSF-normalized data.
Ingest CrowdStrike endpoint detection findings as a custom log source.