Amazon Security Lake website screenshot

Amazon Security Lake

Amazon Security Lake is a service that automatically centralizes an organization's security data from cloud, on-premises, and custom sources into a purpose-built data lake stored in your own Amazon S3. It manages the data lifecycle to help you optimize storage and supports OCSF (Open Cybersecurity Schema Framework) for normalized security data analysis.

Amazon Security Lake publishes 3 APIs on the APIs.io network: Data Lakes API, Log Sources API, and Subscribers API. Tagged areas include Data Lake, Security, SIEM, and Threat Detection.

The Amazon Security Lake catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Amazon Security Lake’s developer surface includes authentication, developer portal, getting-started guide, documentation, API reference, developer console, signup flow, and 33 more developer resources.

68.5/100 exemplar ▼ -6.8 Agent 37/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
3 APIs 8 Features 6 Use Cases
Data LakeSecuritySIEMThreat Detection

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 68.5/100 · exemplar
Contract Quality 16.3 / 25
Developer Ergonomics 12.6 / 20
Commercial Clarity 17.4 / 20
Operational Transparency 6.8 / 13
Governance 8.3 / 12
Discoverability 7.2 / 10
Agent readiness — 37/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/amazon-security-lake: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 3

Individual APIs this provider publishes, each with its own machine-readable definition.

Amazon Security Lake Data Lakes API

Data lake creation and management

Amazon Security Lake Log Sources API

AWS and custom log source management

Amazon Security Lake Subscribers API

Subscriber management for data access

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Amazon Security Lake API

OPEN COLLECTION

Arazzo Workflows 7

Multi-step API workflows described with the Arazzo specification.

Amazon Security Lake Decommission Data Lake

Resolve a data lake, update its configuration, then delete its configuration object.

ARAZZO

Amazon Security Lake Offboard Subscriber

Confirm a subscriber exists, then delete it and verify it is removed from the list.

ARAZZO

Amazon Security Lake Onboard AWS Log Source

Add a natively supported AWS service as a log source and confirm it is collecting.

ARAZZO

Amazon Security Lake Provision Data Lake

Create a Security Lake data lake, confirm it is listed, and inspect its collecting sources.

ARAZZO

Amazon Security Lake Provision Subscriber

Create a subscriber, confirm its identity and status, and verify it is listed.

ARAZZO

Amazon Security Lake Register Custom Source

Register a third-party custom log source and confirm it appears in the source list.

ARAZZO

Amazon Security Lake Rename Subscriber

Find a subscriber by name, confirm it, and update its name and description.

ARAZZO

Scroll for all 7

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Automatic Data Centralization

Automatically centralizes security data from AWS services, third-party tools, and custom sources into a single data lake.

OCSF Normalization

Converts security data to the Open Cybersecurity Schema Framework (OCSF) for standardized analysis across tools.

Apache Parquet Format

Stores all security data in Apache Parquet format optimized for analytical query performance.

Multi-Account Support

Centralizes security data across an entire AWS Organization from all accounts and regions.

Lifecycle Management

Automatically manages storage lifecycle with configurable retention and tiering policies.

Subscriber Access

Grant third-party SIEMs and analytics tools direct query access to your security data lake.

Native AWS Integration

Native connectors for CloudTrail, VPC Flow Logs, Route 53, Security Hub, and EKS audit logs.

Custom Log Sources

Ingest custom and third-party security data sources in OCSF format.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Amazon Security Lake Context

3 classes · 18 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Amazon Security Lake API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Amazon Security Lake API Rules

27 rules · 8 errors 15 warnings 4 info

SPECTRAL

JSON Schema 3

Standalone JSON Schema definitions for this provider's data models.

DataLake

6 properties

JSON SCHEMA

LogSource

3 properties

JSON SCHEMA

Subscriber

9 properties

JSON SCHEMA

JSON Structure 3

JSON Structure definitions describing this provider's data shapes.

Amazon Security Lake Data Lake Structure

6 properties

JSON STRUCTURE

Amazon Security Lake Log Source Structure

3 properties

JSON STRUCTURE

Amazon Security Lake Subscriber Structure

9 properties

JSON STRUCTURE

Examples 3

Example request and response payloads for these APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Amazon Security Lake Authentication

apiKey · 1 scheme

SECURITY

Amazon Security Lake Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Amazon Security Lake Vulnerability Disclosure

security.txt · contact published

SECURITY

Amazon Security Lake Trust Center

PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Amazon Security Lake Agentic Access

13 operations · 9 acting

13 operations · 9 acting

AGENTIC

Use Cases 6

What developers build with this provider.

Security Data Centralization

Aggregate all security data from across a multi-account AWS environment into one queryable data lake.

SIEM Integration

Provide SIEM platforms like Splunk, Sumo Logic, and Microsoft Sentinel direct access to normalized security data.

Threat Hunting

Enable security analysts to query normalized OCSF data for threat hunting and forensic investigation.

Compliance Data Retention

Retain security logs in a cost-optimized data lake for compliance audit requirements.

Security Analytics

Run advanced analytics and ML models against normalized security data for anomaly detection.

Multi-Cloud Security Data

Centralize security data from on-premises and other cloud providers alongside AWS security data.

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 13

Pagination, idempotency, versioning, errors, and events

Scroll for all 13

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/amazon-security-lake.png
name: Amazon Security Lake
description: Amazon Security Lake is a service that automatically centralizes an organization's security data from cloud,
  on-premises, and custom sources into a purpose-built data lake stored in your own Amazon S3. It manages the data lifecycle
  to help you optimize storage and supports OCSF (Open Cybersecurity Schema Framework) for normalized security data analysis.
url: https://aws.amazon.com/security-lake/
baseURL: https://securitylake.amazonaws.com
kind: company
created: '2026-03-16'
modified: '2026-05-19'
tags:
- AWS
- Data Lake
- Security
- SIEM
- Threat Detection
apis:
- aid: amazon-security-lake:amazon-security-lake-data-lakes-api
  name: Amazon Security Lake Data Lakes API
  description: Data lake creation and management
  humanURL: https://docs.aws.amazon.com/security-lake/latest/APIReference/Welcome.html
  baseURL: https://securitylake.{region}.amazonaws.com
  tags:
  - Data Lakes
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-lake-data-lakes-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/security-lake/latest/APIReference/Welcome.html
  - type: JSONSchema
    url: json-schema/amazon-security-lake-data-lake-schema.json
  - type: JSONSchema
    url: json-schema/amazon-security-lake-log-source-schema.json
  - type: JSONSchema
    url: json-schema/amazon-security-lake-subscriber-schema.json
- aid: amazon-security-lake:amazon-security-lake-log-sources-api
  name: Amazon Security Lake Log Sources API
  description: AWS and custom log source management
  humanURL: https://docs.aws.amazon.com/security-lake/latest/APIReference/Welcome.html
  baseURL: https://securitylake.{region}.amazonaws.com
  tags:
  - Log Sources
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-lake-log-sources-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/security-lake/latest/APIReference/Welcome.html
  - type: JSONSchema
    url: json-schema/amazon-security-lake-data-lake-schema.json
  - type: JSONSchema
    url: json-schema/amazon-security-lake-log-source-schema.json
  - type: JSONSchema
    url: json-schema/amazon-security-lake-subscriber-schema.json
- aid: amazon-security-lake:amazon-security-lake-subscribers-api
  name: Amazon Security Lake Subscribers API
  description: Subscriber management for data access
  humanURL: https://docs.aws.amazon.com/security-lake/latest/APIReference/Welcome.html
  baseURL: https://securitylake.{region}.amazonaws.com
  tags:
  - Subscribers
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-lake-subscribers-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/security-lake/latest/APIReference/Welcome.html
  - type: JSONSchema
    url: json-schema/amazon-security-lake-data-lake-schema.json
  - type: JSONSchema
    url: json-schema/amazon-security-lake-log-source-schema.json
  - type: JSONSchema
    url: json-schema/amazon-security-lake-subscriber-schema.json
common:
- type: AgenticAccess
  url: agentic-access/amazon-security-lake-agentic-access.yml
- type: TrustCenter
  url: security/amazon-security-lake-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/amazon-security-lake-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/amazon-security-lake-domain-security.yml
- type: Authentication
  url: authentication/amazon-security-lake-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/amazon-security-lake/overview
- type: Arazzo
  url: arazzo/amazon-security-lake-decommission-data-lake-workflow.yml
  name: Amazon Security Lake Decommission Data Lake
- type: Arazzo
  url: arazzo/amazon-security-lake-offboard-subscriber-workflow.yml
  name: Amazon Security Lake Offboard Subscriber
- type: Arazzo
  url: arazzo/amazon-security-lake-onboard-aws-log-source-workflow.yml
  name: Amazon Security Lake Onboard AWS Log Source
- type: Arazzo
  url: arazzo/amazon-security-lake-provision-data-lake-workflow.yml
  name: Amazon Security Lake Provision Data Lake
- type: Arazzo
  url: arazzo/amazon-security-lake-provision-subscriber-workflow.yml
  name: Amazon Security Lake Provision Subscriber
- type: Arazzo
  url: arazzo/amazon-security-lake-register-custom-source-workflow.yml
  name: Amazon Security Lake Register Custom Source
- type: Arazzo
  url: arazzo/amazon-security-lake-rename-subscriber-workflow.yml
  name: Amazon Security Lake Rename Subscriber
- type: Portal
  url: https://aws.amazon.com/security-lake/
- type: GettingStarted
  url: https://aws.amazon.com/security-lake/getting-started/
- type: Documentation
  url: https://docs.aws.amazon.com/security-lake/
- type: APIReference
  url: https://docs.aws.amazon.com/security-lake/latest/APIReference/
- type: Console
  url: https://console.aws.amazon.com/securitylake/
- type: Signup
  url: https://portal.aws.amazon.com/billing/signup
- type: Pricing
  url: https://aws.amazon.com/security-lake/pricing/
- type: FAQ
  url: https://aws.amazon.com/security-lake/faqs/
- type: Blog
  url: https://aws.amazon.com/blogs/security/tag/amazon-security-lake/
- type: StatusPage
  url: https://health.aws.amazon.com/health/status
- type: Support
  url: https://aws.amazon.com/premiumsupport/
- type: TermsOfService
  url: https://aws.amazon.com/service-terms/
- type: PrivacyPolicy
  url: https://aws.amazon.com/privacy/
- type: Compliance
  url: https://aws.amazon.com/compliance/
- type: GitHubOrganization
  url: https://github.com/aws
- type: YouTube
  url: https://www.youtube.com/user/AmazonWebServices
- type: StackOverflow
  url: https://stackoverflow.com/questions/tagged/amazon-security-lake
- type: KnowledgeCenter
  url: https://repost.aws/knowledge-center
- type: SpectralRules
  url: rules/amazon-security-lake-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/amazon-security-lake-vocabulary.yaml
- type: Features
  data:
  - name: Automatic Data Centralization
    description: Automatically centralizes security data from AWS services, third-party tools, and custom sources into a single
      data lake.
  - name: OCSF Normalization
    description: Converts security data to the Open Cybersecurity Schema Framework (OCSF) for standardized analysis across
      tools.
  - name: Apache Parquet Format
    description: Stores all security data in Apache Parquet format optimized for analytical query performance.
  - name: Multi-Account Support
    description: Centralizes security data across an entire AWS Organization from all accounts and regions.
  - name: Lifecycle Management
    description: Automatically manages storage lifecycle with configurable retention and tiering policies.
  - name: Subscriber Access
    description: Grant third-party SIEMs and analytics tools direct query access to your security data lake.
  - name: Native AWS Integration
    description: Native connectors for CloudTrail, VPC Flow Logs, Route 53, Security Hub, and EKS audit logs.
  - name: Custom Log Sources
    description: Ingest custom and third-party security data sources in OCSF format.
- type: UseCases
  data:
  - name: Security Data Centralization
    description: Aggregate all security data from across a multi-account AWS environment into one queryable data lake.
  - name: SIEM Integration
    description: Provide SIEM platforms like Splunk, Sumo Logic, and Microsoft Sentinel direct access to normalized security
      data.
  - name: Threat Hunting
    description: Enable security analysts to query normalized OCSF data for threat hunting and forensic investigation.
  - name: Compliance Data Retention
    description: Retain security logs in a cost-optimized data lake for compliance audit requirements.
  - name: Security Analytics
    description: Run advanced analytics and ML models against normalized security data for anomaly detection.
  - name: Multi-Cloud Security Data
    description: Centralize security data from on-premises and other cloud providers alongside AWS security data.
- type: Integrations
  data:
  - name: AWS CloudTrail
    description: Native connector for management event and data event logs from CloudTrail.
  - name: Amazon VPC Flow Logs
    description: Ingest VPC network flow logs for network traffic analysis.
  - name: Amazon Route 53
    description: Collect DNS query logs for domain analysis and threat detection.
  - name: AWS Security Hub
    description: Aggregate Security Hub findings into the security data lake.
  - name: Amazon EKS
    description: Ingest Kubernetes audit logs from Amazon EKS clusters.
  - name: Amazon S3
    description: All security data is stored in S3 buckets within your own AWS account.
  - name: AWS Lake Formation
    description: Control fine-grained subscriber access using AWS Lake Formation permissions.
  - name: Splunk
    description: SIEM subscriber integration for Splunk to query Security Lake data directly.
  - name: Microsoft Sentinel
    description: Connect Microsoft Sentinel as a subscriber to consume OCSF-normalized data.
  - name: CrowdStrike
    description: Ingest CrowdStrike endpoint detection findings as a custom log source.
- type: JSONLD
  url: json-ld/amazon-security-lake-context.jsonld
- type: JSONStructure
  url: json-structure/amazon-security-lake-data-lake-structure.json
- type: JSONStructure
  url: json-structure/amazon-security-lake-log-source-structure.json
- type: JSONStructure
  url: json-structure/amazon-security-lake-subscriber-structure.json
- type: Examples
  url: examples/amazon-security-lake-data-lake-example.json
- type: Examples
  url: examples/amazon-security-lake-log-source-example.json
- type: Examples
  url: examples/amazon-security-lake-subscriber-example.json
- type: Integrations
  url: https://aws.amazon.com/partners/
integrations:
- name: Partner Programs
- name: Resources
- name: Success Stories
- name: Work with an AWS Partner
- name: AWS Marketplace
- name: AWS Partner Central
- name: Partner Paths
- name: co-sell with AWS
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com