Aggregate and normalize findings from AWS Security Hub

domain: docs.aws.amazon.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Enable Security Hub in the aggregator account and enable cross-region aggregation if you want findings from multiple regions consolidated into one region
  2. In a multi-account organization, designate an administrator account and use the organization integration to automatically enroll member accounts so their findings are forwarded
  3. Call GetFindings with a Filters object to query findings by ProductName, ComplianceStatus, SeverityLabel, WorkflowStatus, and RecordState; combine with SortCriteria for ordered results
  4. Paginate results using the NextToken in the response; each page returns up to 100 findings by default
  5. Update finding workflow status (NOTIFIED, SUPPRESSED, RESOLVED) via BatchUpdateFindings to reflect investigation state without modifying the original product finding
  6. Create Security Hub Insights (saved filter queries) for recurring views like all open critical findings from a specific product, and subscribe an EventBridge rule to the findings import event for automation

Known gotchas

Related routes

Aggregate and normalize menu data from multiple channels using Otter (Aggregator) as a central menu management hub
food-general · 5 steps · unrated
Create AWS Security Hub automation rules to auto-suppress and auto-escalate findings by severity
docs.aws.amazon.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans