External Findings

The External Finding resource has methods to send findings from an external source to CloudGuard, for entities in cloud accounts that are onboarded to CloudGuard. These findings are recorded in CloudGuard along with findings discovered by CloudGuard (internal findings).

The resource has methods to send findings (in bulk), archive them in CloudGuard, or delete them from CloudGuard. Archived findings remain as records in CloudGuard, and are searchable. Deleted findings are permanently removed.

Findings are sent to CloudGuard as a bulk list, using the POST method. The response includes a list of findings from the list that were rejected by CloudGuard, along with the reason.

Resource Types

The table below shows the codes for the different entity types.

Entity typeDescription
sgSecurity Groups
elbClassic Load Balancer
vpcVPC
subnetSubnet
naclNetwork ACLs
dbInstanceRDS DB Instances
vpcEndpointVPC Endpoints
vpcPeeringConnectionVPC Peering
lambdaAWS Lambda
cloudTrailAWS CloudTrail
cloudWatchCloudWatch
s3BucketS3 Buckets
appLBApplication Load Balancer
volumeEBS Volumes
redshiftRedshift
vpcFlowLogVPC Flow Logs
configurationConfiguration Recorder
snsSubscriptionAWS::SNS::Subscription
directConnectAWS Direct Connect
vpnGatewayVpnGateway
efsAmazon Elastic File System
internetGatewayInternet Gateways
routeTableRoute Tables
elastiCacheAmazon ElastiCache
ecsClusterECS Clusters
inspectorInspector
networkInterfaceElastic Network Interfaces
ecsTaskDefinitionAmazon ECS Task Definitions
route53Route 53
kinesisStreamKinesis Data Streams
acmCertificateAWS Certificate Manager
dynamoDbTableDynamoDB table
ec2ImageAmazon Machine Images
wafRegionalAWS WAF Regional
vpnConnectionVPN Connections
ecsTaskECS Task Definitions
CustomerGatewayCustomer Gateway
elasticIpElastic IP Addresses
GuardDutyDetectorAmazon GuardDuty detector.
Ec2InstanceEC2
ApiGatewayAPI Gateway
kmsKms

See also

Use the CloudGuard REST API to send findings to CloudGuard from an external system