‎22 Jan 2024 02:21 PM
Hyperscalers provide offerings such as AWS Security Hub, through which security-related events give insights into potential threats. These events must be triaged, analyzed, and remediated by the owners of the affected resources, and reaching hundreds of thousands of such alerts is common.
In this Observability Clinic, we have Tobias Aichinger @Tobias_Aichinge , Cloud Security Engineer at Dynatrace, walking us through how Dynatrace internally uses the Dynatrace platform capabilities to analyze 400k AWS Security Alerts daily and reduces the noise to just about three tickets per day that get automatically assigned to the owners of the problematic cloud resources.
The good news is that every Dynatrace user can do the same with Dynatrace as the Dynatrace Workflow that is used to do the automatic analysis, enrichment, and ticket creation is shared in the following documentation page: https://dynatr.ac/4b5hsvV
Also, learn how to forward logs from the AWS Security Hub: https://dynatr.ac/4b5hxjd
Chapter List:
00:00 - Introduction
01:24 - Architectural Overview
03:54 - Demo Overview
04:18 - LIVE DEMO
16:08 - How to implement this yourself
The recording is available also on the Dynatrace University: LINK
- - -
Subscribe to our YT channel
Stay up-to-date with Dynatrace! Follow us on Facebook, Instagram, LinkedIn, Twitter, Twitch