Table: aws_securityhub_findings

This table shows data for AWS Security Hub Findings.

https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindings.html (opens in a new tab) The request_account_id and request_region columns are added to show the account and region of where the request was made from. This is useful when multi region and account aggregation is enabled.

The composite primary key for this table is (request_account_id, request_region, aws_account_id, created_at, description, generator_id, id, product_arn, schema_version, title, updated_at, region).

Columns

NameType
_cq_source_nameString
_cq_sync_timeTimestamp
_cq_idUUID
_cq_parent_idUUID
request_account_id (PK)String
request_region (PK)String
aws_account_id (PK)String
created_at (PK)Timestamp
description (PK)String
generator_id (PK)String
id (PK)String
product_arn (PK)String
resourcesJSON
schema_version (PK)String
title (PK)String
updated_at (PK)Timestamp
actionJSON
company_nameString
complianceJSON
confidenceInt
criticalityInt
finding_provider_fieldsJSON
first_observed_atTimestamp
last_observed_atTimestamp
malwareJSON
networkJSON
network_pathJSON
noteJSON
patch_summaryJSON
processJSON
product_fieldsJSON
product_nameString
record_stateString
region (PK)String
related_findingsJSON
remediationJSON
sampleBool
severityJSON
source_urlString
threat_intel_indicatorsJSON
threatsJSON
typesStringArray
user_defined_fieldsJSON
verification_stateString
vulnerabilitiesJSON
workflowJSON
workflow_stateString