AWS Security Hub + Alert24

Stream events from AWS Security Hub into Alert24 to correlate changes with incidents and shorten time to resolution.

Receive AWS Security Hub aggregated security findings via SNS/EventBridge.

Auto-detected payloads

Alert24 recognizes AWS Security Hub webhooks out of the box and maps fields to incidents automatically.

On-call routing & escalations

Page the right engineer over SMS, voice, push, email, or chat with policy-driven escalations.

Auto-updating status pages

Promote incidents to a public or private status page with one click and keep customers informed.

Change correlation & AI RCA

Recent deploys, infra updates, and feature flag flips surface alongside the incident for faster root cause.

Quick Setup

Copy Webhook URL

Go to your Alert24 dashboard and copy the webhook URL for AWS Security Hub.

Configure AWS Security Hub

Add the webhook URL in your AWS Security Hub settings.

Auto-Detected

Alert24 auto-detects AWS Security Hub payloads and maps them to incidents.

Step-by-Step Setup Instructions

AWS Security Hub Webhook Setup

1.Create an SNS Topic for Security Hub findings
2.In EventBridge, create a rule matching Security Hub finding events:

- Source: aws.securityhub

- Detail type: Security Hub Findings - Imported

3.Set the target to your SNS topic
4.Add an HTTPS subscription to the SNS topic using the webhook URL above
5.Confirm the subscription

Example Webhook Payload

This is a sample payload that AWS Security Hub sends to Alert24 when an alert fires.

{
  "version": "0",
  "source": "aws.securityhub",
  "detail-type": "Security Hub Findings - Imported",
  "detail": {
    "findings": [
      {
        "SchemaVersion": "2018-10-08",
        "Id": "arn:aws:securityhub:us-east-1:123456789012:finding/abc123",
        "Title": "S3 bucket my-bucket has public read access enabled",
        "Severity": {
          "Label": "HIGH",
          "Normalized": 70
        },
        "Workflow": {
          "Status": "NEW"
        },
        "Resources": [
          {
            "Type": "AwsS3Bucket",
            "Id": "my-bucket"
          }
        ]
      }
    ]
  }
}

How Alert24 Maps AWS Security Hub Data

Status Field

detail.findings.0.Workflow.Status

Message Field

detail.findings.0.Title

Auto-Create Incidents

Yes

Auto-Resolve Incidents

Yes

Status Mapping

Alert24 StatusAWS Security Hub Values
operational
RESOLVED
degraded
NOTIFIED
down
NEW

Connect AWS Security Hub to Alert24 in minutes

Free plan includes 5 monitors, 1 status page, and incident management. No credit card required.

More Cloud Platforms Integrations