Skip to content
Release: Australia · Updated: 2026-04-02 · Official documentation · View source

Data retrieval settings for AWS Security Hub

The following filters are available for the AWS Security Hub Host Vulnerability, Container Vulnerability, and Test Results Integrations. These filters control which findings are retrieved from AWS Inspector.

Role required: sn_vul_aws.configure_integration - to configure the integrations.

Note: For Text-based filters, a maximum of nine values is supported for Host and Test Results configurations. Eight filters for container vulnerability configuration are supported.

Host Vulnerabilities Configuration tab

ColumnTypeValues
Severityglide_listINFORMATIONAL, LOW, HIGH, MEDIUM, CRITICAL, UNKNOWN, FATAL, OTHER.
VulnerabilitystringCVE IDs
Resource typechoiceBOTH, AWS::EC2::Instance, AWS::Lambda::Function
Account idstringAWS account IDs
Batch sizeintegerDefault: 1000
CVSS base scoredecimalMinimum CVSS base score filter
Finding statusglide_listNew, In Progress, Resolved, Suppressed, Archived, Unknown, Other
Exploit availablechoiceTrue, False
Fix availablechoiceTrue, False
First observed atglide_date_timeFilter by first observed date
Last observed atglide_date_timeFilter by last observed date
Modified atglide_date_timeFilter by modified date. Used for delta sync.
Resource tagsstringFilter by resource tags
Finding tagsstringFilter by finding tags
Vendor severityglide_listINFORMATIONAL, LOW, HIGH, MEDIUM, CRITICAL
Regionglide_listAWS regions

Container Vulnerabilities Configuration tab

ColumnTypeValues
Severityglide_listINFORMATIONAL, LOW, HIGH, MEDIUM, CRITICAL, UNKNOWN, FATAL, OTHER.
VulnerabilitystringCVE IDs
Account idstringAWS account IDs
Batch sizeintegerDefault: 1000
CVSS base scoredecimalMinimum CVSS base score filter
Finding statusglide_listNew, In Progress, Resolved, Suppressed, Archived, Unknown, Other.
Exploit availablechoiceTrue, False
Fix availablechoiceTrue, False
First observed atglide_date_timeFilter by first observed date
Last observed atglide_date_timeFilter by last observed date
Modified atglide_date_timeFilter by modified date
Resource tagsstringFilter by resource tags
Finding tagsstringFilter by finding tags
Vendor severityglide_listINFORMATIONAL, LOW, HIGH, MEDIUM, CRITICAL
Regionglide_listAWS regions
Repository NamestringECR repository name filter
Registry UIDstringECR registry UID filter

Test Results Configuration tab

ColumnTypeValues
Severityglide_listINFORMATIONAL, LOW, HIGH, MEDIUM, CRITICAL, UNKNOWN, FATAL, OTHER.
ControlstringControl identifiers
Control Statusglide_listPASS, FAIL, WARNING, UNKNOWN
Control StandardsstringCompliance standards
Finding Statusglide_listNew, In Progress, Resolved, Suppressed, Archived, Unknown, Other
Account IDstringAWS account IDs
Resource TypestringAWS resource types
First observed atglide_date_timeFilter by first observed date
Last observed atglide_date_timeFilter by last observed date
Modified atglide_date_timeFilter by modified date
Resource TagsstringFilter by resource tags
Finding TagsstringFilter by finding tags
Vendor severityglide_listINFORMATIONAL, LOW, HIGH, MEDIUM, CRITICAL.