# Amazon Security Lake User Guide - [What is Amazon Security Lake?](https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.md) - [Concepts and terminology](https://docs.aws.amazon.com/security-lake/latest/userguide/service-concepts.md) - [Managing multiple accounts](https://docs.aws.amazon.com/security-lake/latest/userguide/multi-account-management.md) - [Lifecycle management](https://docs.aws.amazon.com/security-lake/latest/userguide/lifecycle-management.md) - [Open Cybersecurity Schema Framework (OCSF)](https://docs.aws.amazon.com/security-lake/latest/userguide/open-cybersecurity-schema-framework.md) - [Logging API calls](https://docs.aws.amazon.com/security-lake/latest/userguide/securitylake-cloudtrail.md) - [Supported Regions and endpoints](https://docs.aws.amazon.com/security-lake/latest/userguide/supported-regions.md) - [Disabling Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/disable-security-lake.md) - [Document history](https://docs.aws.amazon.com/security-lake/latest/userguide/doc-history.md) ## [Getting started](https://docs.aws.amazon.com/security-lake/latest/userguide/getting-started.md) - [Setting up your AWS account](https://docs.aws.amazon.com/security-lake/latest/userguide/initial-account-setup.md): Before you can enable Amazon Security Lake, you must have an AWS account. - [Considerations when enabling Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/enable-securitylake-considerations.md): Before enabling Security Lake, consider the following: - [Using the console](https://docs.aws.amazon.com/security-lake/latest/userguide/get-started-console.md): This tutorial explains how to enable and configure Security Lake through the AWS Management Console. - [Using the AWS CLI or API](https://docs.aws.amazon.com/security-lake/latest/userguide/get-started-programmatic.md): This tutorial explains how to enable and start using Security Lake programmatically. ## [Managing Regions](https://docs.aws.amazon.com/security-lake/latest/userguide/manage-regions.md) - [Configuring rollup Regions](https://docs.aws.amazon.com/security-lake/latest/userguide/add-rollup-region.md): A rollup Region consolidates data from one or more contributing Regions. ## [Source management](https://docs.aws.amazon.com/security-lake/latest/userguide/source-management.md) ### [Collecting data from AWS services](https://docs.aws.amazon.com/security-lake/latest/userguide/internal-sources.md) Learn about collecting security logs and events in Security Lake from supported AWS services. - [Updating role permissions](https://docs.aws.amazon.com/security-lake/latest/userguide/update-role-permissions.md): If you don't have the required role permissions or resources—new AWS Lambda function and Amazon Simple Queue Service (Amazon SQS) queue—to ingest data from a new version of the data source, you must update your AmazonSecurityLakeMetaStoreManagerV2 role permissions and create a new set of resources to process data from your sources. - [Removing an AWS service as a source](https://docs.aws.amazon.com/security-lake/latest/userguide/remove-internal-sources.md): Choose your access method, and follow these steps to remove a natively-supported AWS service as a Security Lake source. - [CloudTrail event logs](https://docs.aws.amazon.com/security-lake/latest/userguide/cloudtrail-event-logs.md): AWS CloudTrail provides you with a history of AWS API calls for your account, including API calls made using the AWS Management Console, the AWS SDKs, the command line tools, and certain AWS services. - [Amazon EKS Audit Logs](https://docs.aws.amazon.com/security-lake/latest/userguide/eks-audit-logs.md): When you add Amazon EKS Audit Logs as a source, Security Lake starts collecting in-depth information about the activities performed on the Kubernetes resources running in your Elastic Kubernetes Service (EKS) clusters. - [Route 53 resolver query logs](https://docs.aws.amazon.com/security-lake/latest/userguide/route-53-logs.md): Route 53 resolver query logs track DNS queries made by resources within your Amazon Virtual Private Cloud (Amazon VPC). - [Security Hub CSPM findings](https://docs.aws.amazon.com/security-lake/latest/userguide/security-hub-findings.md): Security Hub CSPM findings help you understand your security posture in AWS and let you check your environment against security industry standards and best practices. - [VPC Flow Logs](https://docs.aws.amazon.com/security-lake/latest/userguide/vpc-flow-logs.md): The VPC Flow Logs feature of Amazon VPC captures information about the IP traffic going to and from network interfaces within your environment. - [AWS WAF logs](https://docs.aws.amazon.com/security-lake/latest/userguide/aws-waf.md): When you add AWS WAF as a log source in Security Lake, Security Lake immediately starts collecting the logs. ### [Collecting data from custom sources](https://docs.aws.amazon.com/security-lake/latest/userguide/custom-sources.md) Learn about collecting security logs and events in Security Lake from custom, third-party sources. - [Adding a custom source](https://docs.aws.amazon.com/security-lake/latest/userguide/adding-custom-sources.md): After creating the IAM role to invoke the AWS Glue crawler, follow these steps to add a custom source in Security Lake. - [Deleting a custom source](https://docs.aws.amazon.com/security-lake/latest/userguide/delete-custom-source.md): Delete a custom source to stop sending data from the source to Security Lake. ## [Subscriber management](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-management.md) ### [Subscriber data access](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-data-access.md) Learn about how to set up data access for subscribers in Security Lake. - [Prerequisites](https://docs.aws.amazon.com/security-lake/latest/userguide/prereqs-creating-subscriber.md): You must complete the following prerequisites before you can create a subscriber with data access in Security Lake. - [Creating a subscriber with data access](https://docs.aws.amazon.com/security-lake/latest/userguide/create-subscriber-data-access.md): Choose one of the following access methods to create a subscriber with access to data in the current AWS Region. - [Updating a data subscriber](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-update.md): You can update a subscriber by changing the sources from which the subscriber consumes. - [Removing a data subscriber](https://docs.aws.amazon.com/security-lake/latest/userguide/remove-data-access-subscriber.md): If you no longer want a subscriber to consume data from Security Lake, you can remove the subscriber by following these steps. ### [Subscriber query access](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-query-access.md) Learn about how to set up query access for subscribers in Security Lake. - [Prerequisites](https://docs.aws.amazon.com/security-lake/latest/userguide/prereqs-query-subscriber.md): You must complete the following prerequisites before you can create a subscriber with data access in Security Lake. - [Creating a subscriber with query access](https://docs.aws.amazon.com/security-lake/latest/userguide/create-query-subscriber-procedures.md): Choose your preferred method to create a subscriber with query access in the current AWS Region. - [Editing a subscriber with query access](https://docs.aws.amazon.com/security-lake/latest/userguide/editing-query-access-subscriber.md): Security Lake supports making edits to a subscriber with query access. ## [Security Lake queries](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-query-examples.md) ### [Security Lake queries source version 1](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-query-examples1.md) Get querying guidance and example queries for subscribers that have query access in Security Lake. - [Queries for CloudTrail data](https://docs.aws.amazon.com/security-lake/latest/userguide/cloudtrail-query-examples.md): Get example queries for AWS CloudTrail data that is stored in Security Lake. - [Queries for Route 53 resolver query logs](https://docs.aws.amazon.com/security-lake/latest/userguide/route53_1_0-query-examples.md): Get example queries for Amazon Route 53 resolver query logs that are stored in Security Lake. - [Queries for Security Hub CSPM findings](https://docs.aws.amazon.com/security-lake/latest/userguide/security-hub-query-examples.md): Here are some example queries for Security Hub CSPM findings that are stored in Security Lake for AWS source version 1. - [Queries for Amazon VPC Flow Logs](https://docs.aws.amazon.com/security-lake/latest/userguide/vpc-query-examples.md): Here are some example queries for Amazon VPC Flow Logs that are stored in Security Lake for AWS source version 1. ### [Security Lake queries source version 2](https://docs.aws.amazon.com/security-lake/latest/userguide/subscriber-query-examples2.md) Get querying guidance and example queries for subscribers that have query access in Security Lake. - [Queries for CloudTrail data](https://docs.aws.amazon.com/security-lake/latest/userguide/cloudtrail-query-examples-sourceversion2.md): Here are some example queries for AWS CloudTrail data that is stored in Security Lake for AWS source version 2. - [Queries for Route 53 resolver query logs](https://docs.aws.amazon.com/security-lake/latest/userguide/route53_1_0-query-examples-sourceversion2.md): Here are some example queries for Amazon Route 53 resolver query logs that are stored in Security Lake for AWS source version 2. - [Queries for Security Hub CSPM findings](https://docs.aws.amazon.com/security-lake/latest/userguide/security-hub-query-examples-sourceversion2.md): Here are some example queries for Security Hub CSPM findings that are stored in Security Lake for AWS source version 2. - [Queries for Amazon VPC Flow Logs](https://docs.aws.amazon.com/security-lake/latest/userguide/vpc-query-examples-sourceversion2.md): Here are some example queries for Amazon VPC Flow Logs that are stored in Security Lake for AWS source version 2. - [Queries for AWS WAFv2 logs](https://docs.aws.amazon.com/security-lake/latest/userguide/example-queries-waf-sourceversion2.md): Here are some example queries for AWS WAFv2 logs that are stored in Security Lake for AWS source version 2. ## [Integrations](https://docs.aws.amazon.com/security-lake/latest/userguide/integrations-overview.md) ### [AWS service integrations](https://docs.aws.amazon.com/security-lake/latest/userguide/aws-integrations.md) Learn how to use Amazon Security Lake with other AWS services. - [Amazon Bedrock integration](https://docs.aws.amazon.com/security-lake/latest/userguide/bedrock-integration.md): Learn how to use the Amazon Security Lake integration with Amazon Bedrock. - [Amazon Detective integration](https://docs.aws.amazon.com/security-lake/latest/userguide/detective-integration.md): Learn how to use the Security Lake integration with Amazon Detective. - [Amazon OpenSearch Service integration](https://docs.aws.amazon.com/security-lake/latest/userguide/opensearch-integration.md): Learn how to use Amazon Security Lake integration with Amazon OpenSearch Service - [Amazon OpenSearch Service Ingestion pipeline integration](https://docs.aws.amazon.com/security-lake/latest/userguide/opensearch-ingestion-pipeline-integration.md): Integration type:Subscriber, Source - [Amazon OpenSearch Service zero-ETL direct query integration](https://docs.aws.amazon.com/security-lake/latest/userguide/opensearch-datasource-integration.md): Integration type: Subscriber (Query) - [Quick integration](https://docs.aws.amazon.com/security-lake/latest/userguide/quicksight-integration.md): Learn how to use the Security Lake integration with Amazon Quick - [Amazon SageMaker AI integration](https://docs.aws.amazon.com/security-lake/latest/userguide/sagemaker-integration.md): Learn how to use the Security Lake integration with Amazon SageMaker AI - [AWS AppFabric integration](https://docs.aws.amazon.com/security-lake/latest/userguide/appfabric-integration.md): Learn how to use the Amazon Security Lake integration with AWS AppFabric. - [AWS Security Hub CSPM integration](https://docs.aws.amazon.com/security-lake/latest/userguide/securityhub-integration.md): Learn how to use the Amazon Security Lake integration with AWS Security Hub CSPM. - [Third-party integrations](https://docs.aws.amazon.com/security-lake/latest/userguide/integrations-third-party.md): Learn about third-party integrations with Security Lake. ## [Security](https://docs.aws.amazon.com/security-lake/latest/userguide/security.md) ### [Identity and access management](https://docs.aws.amazon.com/security-lake/latest/userguide/security-iam.md) How to authenticate requests and manage access your Security Lake resources. - [How Security Lake works with IAM](https://docs.aws.amazon.com/security-lake/latest/userguide/security_iam_service-with-iam.md): Before you use IAM to manage access to Security Lake, learn what IAM features are available to use with Security Lake. - [Identity-based policy examples](https://docs.aws.amazon.com/security-lake/latest/userguide/security_iam_id-based-policy-examples.md): By default, users and roles don't have permission to create or modify Security Lake resources. - [AWS managed policies](https://docs.aws.amazon.com/security-lake/latest/userguide/security-iam-awsmanpol.md): Learn about AWS managed policies for Security Lake and recent changes to those policies. ### [Using service-linked roles](https://docs.aws.amazon.com/security-lake/latest/userguide/using-service-linked-roles.md) How to use service-linked roles to give Security Lake access to resources in your AWS account. - [SLR permissions for Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/slr-permissions.md): Security Lake uses the service-linked role named AWSServiceRoleForSecurityLake. - [SLR permissions for resource management](https://docs.aws.amazon.com/security-lake/latest/userguide/AWSServiceRoleForSecurityLakeResourceManagement.md): Learn how Security Lake uses a service-linked role to manage the metadata and resources in your AWS account. ### [Data protection](https://docs.aws.amazon.com/security-lake/latest/userguide/data-protection.md) Learn about how the AWS shared responsibility model applies to data protection in Security Lake. - [Opting out of using your data for service improvement](https://docs.aws.amazon.com/security-lake/latest/userguide/opting-out-of-using-your-data.md): Learn how you can opt-out of using your data for Security Lake improvement. - [Compliance validation](https://docs.aws.amazon.com/security-lake/latest/userguide/compliance-validation.md): Learn what AWS services are in scope of a specific compliance program. - [Security best practices for Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/best-practices-overview.md): Learn about Security Lake security best practices. - [Resilience](https://docs.aws.amazon.com/security-lake/latest/userguide/disaster-recovery-resiliency.md): Learn how AWS architecture supports data redundancy, and learn about specific Security Lake features for data resiliency. - [Infrastructure security](https://docs.aws.amazon.com/security-lake/latest/userguide/infrastructure-security.md): Learn how Security Lake isolates service traffic. - [Configuration and vulnerability analysis in Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/configuration-vulnerability-analysis.md): Learn about Security Lake configuration and vulnerability analysis. - [VPC endpoints (AWS PrivateLink)](https://docs.aws.amazon.com/security-lake/latest/userguide/security-vpc-endpoints.md): You can use an interface VPC endpoint to create a private connection between your VPC and Amazon Security Lake without requiring access over the internet or through a NAT device, a VPN connection, or an Direct Connect connection. ### [Monitoring](https://docs.aws.amazon.com/security-lake/latest/userguide/monitoring-overview.md) Monitor Security Lake to maintain reliability, availability, and performance. - [CloudWatch metrics for Amazon Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/cloudwatch-metrics.md): Monitor Security Lake in CloudWatch to maintain reliability, availability, and performance. ## [Tagging resources](https://docs.aws.amazon.com/security-lake/latest/userguide/tagging-resources.md) - [Tagging fundamentals](https://docs.aws.amazon.com/security-lake/latest/userguide/tags-basics.md): A resource can have as many as 50 tags. - [Using tags in IAM policies](https://docs.aws.amazon.com/security-lake/latest/userguide/tags-iam.md): After you start tagging resources, you can define tag-based, resource-level permissions in AWS Identity and Access Management (IAM) policies. - [Adding tags to resources](https://docs.aws.amazon.com/security-lake/latest/userguide/tags-add.md): To add tags to an Amazon Security Lake resource, you can use the Security Lake console or the Security Lake API. - [Editing tags for resources](https://docs.aws.amazon.com/security-lake/latest/userguide/tags-update.md): To edit the tags (tag keys or tag values) for an Amazon Security Lake resource, you can use the Security Lake console or the Security Lake API. - [Removing tags from resources](https://docs.aws.amazon.com/security-lake/latest/userguide/tags-remove.md): To remove tags from an Amazon Security Lake resource, you can use the Security Lake console or the Security Lake API. ## [Troubleshooting](https://docs.aws.amazon.com/security-lake/latest/userguide/security-lake-troubleshoot.md) - [Troubleshooting data lake status](https://docs.aws.amazon.com/security-lake/latest/userguide/securitylake-data-lake-troubleshoot.md): The Issues page of the Security Lake console shows you a summary of issues that are affecting your data lake. - [Troubleshooting Lake Formation issues](https://docs.aws.amazon.com/security-lake/latest/userguide/securitylake-lf-troubleshoot.md): Use the following information to help you diagnose and fix common issues that you might encounter when working with Security Lake and AWS Lake Formation databases or tables. - [Troubleshooting querying in Amazon Athena](https://docs.aws.amazon.com/security-lake/latest/userguide/querying-troubleshoot.md): Use the following information to help you diagnose and fix common issues that you might encounter when using Athena to query objects that are stored in your Security Lake S3 bucket. - [Troubleshooting Organizations issues](https://docs.aws.amazon.com/security-lake/latest/userguide/securitylake-orgs-troubleshoot.md): Use the following information to help you diagnose and fix common issues that you might encounter when working with Security Lake and AWS Organizations. - [Troubleshooting IAM issues](https://docs.aws.amazon.com/security-lake/latest/userguide/security_iam_troubleshoot.md): Use the following information to help you diagnose and fix common issues that you might encounter when working with Security Lake and IAM. ## [Security Lake pricing](https://docs.aws.amazon.com/security-lake/latest/userguide/estimating-costs.md) - [Reviewing usage and estimated costs](https://docs.aws.amazon.com/security-lake/latest/userguide/reviewing-usage-costs.md): Learn how to review your Security Lake usage and estimate costs.