From Alert Fatigue to Action: Native Security Hub Findings in Splunk
Security for AWS Security Hub Extended helps solve that challenge. Security Hub findings flow directly into Splunk Enterprise Security as native detections in near real time. There is no custom parsing and no need to write additional detection rules. Findings appear as first-class events inside Splunk ES.