Aqua Wave can send alerts to AWS SNS endpoints.
This setup requires you to alter the IAM permissions of the cross account role created for Aqua Wave.
You may incur charges through your AWS account for the use of SNS. These charges are independent of Aqua Wave and are pursuant to your AWS rates. To read more about AWS pricing for SNS, click here.
Configuring this integration requires setup in both systems.
Configuring The Destination
Prepare your AWS account to receive alerts from Aqua Wave by performing the following steps.
- Log into your AWS account and open the SNS Dashboard.
- Click on "Topics" and "Create new topic".
Give it a name and description of your choosing.
Create the topic and then copy its ARN (e.g "arn:aws:sns:us-east-1:0123456789:cloudsploit-sns").
Click on the topic, then click the "Other topic actions" dropdown and select "Edit topic policy".
Under "Allow these users to publish messages to this topic", enter Aqua Wave's account number next to "Only these AWS users".
- Subscribe to your SNS topic with your desired format/transport.
Configuring The Integration To The Destination
Configure Aqua Wave to send alerts to SNS.
- Log in to the Aqua Wave console.
- On the menu on the left, click "Integrations".
- Click the "Create Integrations" button.
- In the "Create New Integration" box, enter values for the following fields.
- Name (of the integration)
- Integration type, choose one:
- SNS ARN, which was created in the previous set of steps.
- Click the "Create Integration" button.
The integration is now available for use.
Best Practice to Integrate other SIEM Solutions
Integrate SIEM solutions by setting up Aqua CSPM to send notifications to AWS SNS. This allows AWS native integrations between SNS and other services like Lambda rather than these services reading data directly from CSPM APIs.
- Aqua CSPM sends scan and alerts notifications to AWS SNS.
- From SNS, the customers can route their requests to services such as AWS Lambda, SQS, and other supported destinations.
SNS is flexible and allows the customers to route the requests to any of the destinations they desire.