AWS Environment Preparation
Set up the following in your AWS environment before creating a Spotter integration.
Configure AWS Config
Spotter uses AWS Config to gather data about your resources.
-
Enable AWS Config in one of your AWS accounts.
-
Create an aggregator and note its name (e.g.
organization-aggregator). -
Configure the aggregator to gather data from every account and region.
It's advised to use a separate Config account in your environment.
Configure Security Hub CSPM
Spotter reads your compliance findings from Security Hub CSPM.
-
Enable Security Hub CSPM in one of your AWS accounts, and make it the administrator account for your organization.
-
Make its region the aggregation region, so findings from every account and region are collected there.
It's advised to use a separate security account in your environment.
Enable cost data
-
Create a CUR 2 export in your management account so Spotter can read your cost data. See AWS CUR 2 Export Setup for Spotter.
-
Enable rightsizing recommendations in Cost Explorer of the management account.
-
Enable Cost Optimization Hub in the management account. Choose Enable Cost Optimization Hub for this account and all member accounts so it covers every member account. This needs all features turned on in your organization.
-
Opt in to Compute Optimizer in the management account if you want the rightsizing recommendations.
-
Best practices
-
Enable Security Hub CSPM and Trusted Advisor in all accounts in your environment.
-
Trusted Advisor needs a paid AWS support plan on every account you want data from: Business Support+, Enterprise Support, or Unified Operations.
-
Spotter reads Trusted Advisor through its API. On Basic support that API returns nothing — not even the checks you can see in the console there.