Amazon Security Lake
Amazon Security Lake is a service that automatically centralizes an organization's security data from cloud, on-premises, and custom sources into a purpose-built data lake stored in your own Amazon S3. It manages the data lifecycle to help you optimize storage and supports OCSF (Open Cybersecurity Schema Framework) for normalized security data analysis.
Amazon Security Lake publishes 3 APIs on the APIs.io network: Data Lakes API, Log Sources API, and Subscribers API. Tagged areas include Data Lake, Security, SIEM, and Threat Detection.
The Amazon Security Lake catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Amazon Security Lake’s developer surface includes authentication, developer portal, getting-started guide, documentation, API reference, developer console, signup flow, and 33 more developer resources.
Kin Score
APIs 3
Individual APIs this provider publishes, each with its own machine-readable definition.
Amazon Security Lake Data Lakes API
Data lake creation and management
Amazon Security Lake Log Sources API
AWS and custom log source management
Amazon Security Lake Subscribers API
Subscriber management for data access
Postman Collections 1
Ready-to-run Postman collections for exercising this provider's APIs.
Amazon Security Lake API
POSTMANOpen Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Amazon Security Lake API
OPEN COLLECTIONArazzo Workflows 7
Multi-step API workflows described with the Arazzo specification.
Amazon Security Lake Decommission Data Lake
Resolve a data lake, update its configuration, then delete its configuration object.
ARAZZOAmazon Security Lake Offboard Subscriber
Confirm a subscriber exists, then delete it and verify it is removed from the list.
ARAZZOAmazon Security Lake Onboard AWS Log Source
Add a natively supported AWS service as a log source and confirm it is collecting.
ARAZZOAmazon Security Lake Provision Data Lake
Create a Security Lake data lake, confirm it is listed, and inspect its collecting sources.
ARAZZOAmazon Security Lake Provision Subscriber
Create a subscriber, confirm its identity and status, and verify it is listed.
ARAZZOAmazon Security Lake Register Custom Source
Register a third-party custom log source and confirm it appears in the source list.
ARAZZOAmazon Security Lake Rename Subscriber
Find a subscriber by name, confirm it, and update its name and description.
ARAZZOScroll for all 7
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Amazon Security Lake Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Features 8
Notable capabilities this provider offers.
Automatic Data Centralization
Automatically centralizes security data from AWS services, third-party tools, and custom sources into a single data lake.
OCSF Normalization
Converts security data to the Open Cybersecurity Schema Framework (OCSF) for standardized analysis across tools.
Apache Parquet Format
Stores all security data in Apache Parquet format optimized for analytical query performance.
Multi-Account Support
Centralizes security data across an entire AWS Organization from all accounts and regions.
Lifecycle Management
Automatically manages storage lifecycle with configurable retention and tiering policies.
Subscriber Access
Grant third-party SIEMs and analytics tools direct query access to your security data lake.
Native AWS Integration
Native connectors for CloudTrail, VPC Flow Logs, Route 53, Security Hub, and EKS audit logs.
Custom Log Sources
Ingest custom and third-party security data sources in OCSF format.
Scroll for all 8
Semantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Amazon Security Lake Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Amazon Security Lake API Rules
SPECTRALAmazon Security Lake API Rules
SPECTRALJSON Schema 3
Standalone JSON Schema definitions for this provider's data models.
JSON Structure 3
JSON Structure definitions describing this provider's data shapes.
Amazon Security Lake Data Lake Structure
JSON STRUCTUREAmazon Security Lake Log Source Structure
JSON STRUCTUREAmazon Security Lake Subscriber Structure
JSON STRUCTUREExamples 3
Example request and response payloads for these APIs.
Security Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 6
What developers build with this provider.
Security Data Centralization
Aggregate all security data from across a multi-account AWS environment into one queryable data lake.
SIEM Integration
Provide SIEM platforms like Splunk, Sumo Logic, and Microsoft Sentinel direct access to normalized security data.
Threat Hunting
Enable security analysts to query normalized OCSF data for threat hunting and forensic investigation.
Compliance Data Retention
Retain security logs in a cost-optimized data lake for compliance audit requirements.
Security Analytics
Run advanced analytics and ML models against normalized security data for anomaly detection.
Multi-Cloud Security Data
Centralize security data from on-premises and other cloud providers alongside AWS security data.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 13
Pagination, idempotency, versioning, errors, and events
Scroll for all 13
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 5
Authentication, authorization, and security posture
Learn 1
Tutorials, courses, talks, and written guidance
Operate 4
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API
Other 1
Properties that don't map to a standard resource type