Amazon CloudWatch now supports ingesting Security Hub CSPM findings with organization-wide enablement
Amazon CloudWatch ยท 2026-03-31
Actions
Technical Details
| Regions | all |
|---|---|
| Cost Impact | Increase |
| IaC Impact | High |
What This Means
For DevOps Teams
Configure CloudWatch enablement rules to automatically deliver Security Hub findings to CloudWatch Logs for specific accounts or the entire organization, leveraging CloudWatch Logs Insights and S3 Tables integration for advanced analytics and monitoring.
For Platform Teams
Adopt the new capability to ingest Security Hub CSPM findings in CloudWatch Logs, enabling standardized security data ingestion and advanced analytics to strengthen the organization's security posture.
For Executives
Evaluate the integration of Security Hub CSPM findings into CloudWatch Logs to enhance centralized security monitoring and improve threat detection capabilities across your AWS environment, leading to faster identification and response to security threats.
Source
Related Amazon CloudWatch Updates
- Amazon CloudWatch Logs introduces lookup query command (2026-03-31)
- AWS Direct Connect adds CloudWatch metrics for BGP monitoring (2026-03-30)
- Amazon CloudWatch now supports multi-account and region log centralization based on data source (2026-03-30)
- Amazon CloudWatch Logs now supports data protection, OpenSearch PPL and OpenSearch SQL for the Infrequent Access ingestion class (2026-03-27)
- Amazon CloudWatch Logs now supports log ingestion using HTTP-based protocol (2026-03-16)