Amazon Security Lake
Amazon Security Lake is a service that automatically centralizes an organization's security data from cloud, on-premises, and custom sources into a purpose-built data lake stored in your own Amazon S3. It manages the data lifecycle to help you optimize storage and supports OCSF (Open Cybersecurity Schema Framework) for normalized security data analysis.
API Rating
APIs
Amazon Security Lake API
The Amazon Security Lake API provides programmatic access to create and manage data lakes, data sources, subscribers, and log sources for centralizing and analyzing security dat...
Capabilities
Amazon Security Lake API — Data Lakes
Amazon Security Lake API — Data Lakes. 4 operations. Lead operation: Amazon Security Lake Create Data Lake. Self-contained Naftiko capability covering one Amazon Security Lake b...
Run with NaftikoAmazon Security Lake API — Log Sources
Amazon Security Lake API — Log Sources. 4 operations. Lead operation: Amazon Security Lake Get Data Lake Sources. Self-contained Naftiko capability covering one Amazon Security ...
Run with NaftikoAmazon Security Lake API — Subscribers
Amazon Security Lake API — Subscribers. 5 operations. Lead operation: Amazon Security Lake Create Subscriber. Self-contained Naftiko capability covering one Amazon Security Lake...
Run with NaftikoFeatures
Automatically centralizes security data from AWS services, third-party tools, and custom sources into a single data lake.
Converts security data to the Open Cybersecurity Schema Framework (OCSF) for standardized analysis across tools.
Stores all security data in Apache Parquet format optimized for analytical query performance.
Centralizes security data across an entire AWS Organization from all accounts and regions.
Automatically manages storage lifecycle with configurable retention and tiering policies.
Grant third-party SIEMs and analytics tools direct query access to your security data lake.
Native connectors for CloudTrail, VPC Flow Logs, Route 53, Security Hub, and EKS audit logs.
Ingest custom and third-party security data sources in OCSF format.
Use Cases
Aggregate all security data from across a multi-account AWS environment into one queryable data lake.
Provide SIEM platforms like Splunk, Sumo Logic, and Microsoft Sentinel direct access to normalized security data.
Enable security analysts to query normalized OCSF data for threat hunting and forensic investigation.
Retain security logs in a cost-optimized data lake for compliance audit requirements.
Run advanced analytics and ML models against normalized security data for anomaly detection.
Centralize security data from on-premises and other cloud providers alongside AWS security data.