Note: This is a one-way outbound integration. Alerts created or updated in Plerion will appear in AWS Security Hub, but changes made directly in Security Hub will not sync back to Plerion.
Steps to integrate AWS Security Hub with Plerion
1
On the Plerion dashboard, go to Settings > Integrations

2
Find Security Hub and click the + button

3
Enter a name for your integration

4
Click Add to save the integration
5
Accept findings in AWS Security Hub
Open the AWS Security Hub console and accept findings from Plerion.

Steps to remove AWS Security Hub integration
1
Delete the integration in Plerion
Go to the integration information page and click the icon.

2
Stop accepting findings in AWS Security Hub
In the AWS Security Hub console, stop accepting findings from Plerion.

Architecture

- Delivery status and alert state are tracked in a database.
- Failed deliveries are stored in a Dead-Letter Queue (DLQ) for review and resubmission.
FAQ
-
How long does it take for findings to appear in AWS Security Hub?
Findings are delivered within 2–3 minutes of being generated in Plerion. -
How is the Plerion risk score mapped to the ASFF severity label?
Risk score ASFF severity label 0.0 INFORMATIONAL 0.1–3.999 LOW 4.0–6.999 MEDIUM 7.0–8.999 HIGH 9.0–10.0 CRITICAL -
How are alerts mapped to ASFF findings?
Alerts are transformed into AWS Security Finding Format (ASFF) objects. Example: