AWS detection is split across services: CloudTrail records API activity, GuardDuty detects threats, and Security Hub aggregates findings. This page describes the pipeline that connects them, then each service in turn.

The findings pipeline

AWS’s detective services each produce findings, but none keeps them long. The notes describe the same pipeline: detect, aggregate, route, and export.

flowchart LR
    accTitle: AWS security findings pipeline
    accDescr: GuardDuty and other services send findings to Security Hub CSPM for aggregation; findings go to EventBridge for automated response and are exported to S3 for long-term retention.
    G[GuardDuty, Inspector, Macie] --> H[Security Hub CSPM]
    H --> E[EventBridge: response automation]
    E --> S[S3: long-term retention]

Retention is short everywhere

ServiceBuilt-in retention
GuardDuty findings90 days, fixed
Security Hub CSPM findings90 days
CloudTrail event history90 days, cannot be extended

So every note recommends exporting: GuardDuty findings to S3, Security Hub findings archived through EventBridge, and CloudTrail events to a trail or Lake event data store.123

Wiring rules

  • A service’s findings reach Security Hub only if that service and its integration are enabled in the same Region.2
  • Filters and suppression rules hide findings; they do not fix causes.1

Across many accounts, these services run from a delegated administrator account; see AWS multi-account governance.

AWS CloudTrail

CloudTrail records actions taken by users, roles, and AWS services as events, for auditing, governance, and compliance. It has three layers of increasing commitment.

LayerWhat it keeps
Event historyThe past 90 days of management events per Region; free, on by default, cannot be extended
TrailManagement events and selected data and Insights events delivered to S3, optionally to CloudWatch Logs and EventBridge
CloudTrail LakeAn event data store queried with SQL, kept up to 2,557 days (about 7 years) or 3,653 days (about 10 years) depending on pricing

As described in the note.

Management events are control-plane operations; data events are resource operations such as S3 object access or Lambda invocations, which is why they are recorded selectively to control cost. Insights events flag unusual API rates and errors.3

Practices

  • An organization trail from the management account to a dedicated, encrypted, private, versioned S3 bucket; member accounts cannot disable it.
  • Alarm on trail status so logging does not stop silently, and restrict StopLogging and DeleteTrail with IAM and SCPs.3

Troubleshooting

SymptomCheck
No events deliveredTrail logging, bucket policy, KMS key permissions
Data events missingEvent selectors
Only 90 days availableEvent history is fixed; create a trail or Lake store

As tabled in the note.3

Amazon GuardDuty

GuardDuty continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs, using threat intelligence and machine learning to produce security findings. Optional protection plans add EKS audit logs, RDS logins, S3 data events, malware scanning, runtime monitoring, Lambda network activity, and AI workloads.1

Concepts

  • One detector per account per Region; findings have Low, Medium, or High severity.
  • Foundational sources start ingesting as soon as it is enabled; protection plans are enabled separately.
  • Filters and suppression rules reduce noise but hide findings rather than fix causes.1

Practices

  • Enable in all Regions and accounts, managed through Organizations with a delegated administrator.
  • Send findings to EventBridge and Security Hub CSPM, and export to S3 to keep them beyond 90 days.
  • Test the pipeline with sample findings.1

Troubleshooting and limits

SymptomCheck
No findingsDetector enabled, sources ingesting; generate samples
Missing S3, EKS, or RDS detectionThe matching protection plan in the same Region
Accidental deletiondelete-detector removes findings; suspend with update-detector --no-enable instead

As tabled in the note. Findings are kept 90 days (fixed); up to 6 threat intelligence sets and 100 filters per detector.1 See Security findings pipeline.

AWS Security Hub CSPM

Security Hub Cloud Security Posture Management (CSPM) gives a consolidated view of an environment’s security state: it collects findings from services such as GuardDuty, Inspector, and Macie and from partners, and runs continuous checks against standards.2

Concepts

  • Findings are normalized into the AWS Security Finding Format (ASFF).
  • Standards include AWS Foundational Security Best Practices (FSBP), CIS, PCI DSS, and NIST; each contains controls that run configuration checks, and most controls need AWS Config recording in the account and Region.
  • Security scores, insights, automation rules, and cross-Region aggregation.2

Practices

  • Enable in all supported Regions with cross-Region aggregation, and enable AWS Config for the resource types standards check.
  • Use a delegated administrator; route findings to EventBridge for remediation; disable unused standards to control cost.2

Troubleshooting and limits

SymptomCheck
No findings after enablingAWS Config recording, standards enabled, Region supported
GuardDuty or Inspector findings absentThe service and its integration in the same Region
Unexpected costsDisable unused standards and controls

As tabled in the note. Findings are kept 90 days; archive to S3 through EventBridge for longer.2 See Security findings pipeline.

Footnotes

  1. Amazon GuardDuty - Runbook & Reference, original ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  2. AWS Security Hub CSPM - Runbook & Reference, original ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  3. AWS CloudTrail - Runbook & Reference, original ↩ ↩2 ↩3 ↩4