Spotter reads data from the following AWS services:
-
AWS Organizations — the list of accounts in your organization.
-
AWS IAM — the account alias of each account.
-
AWS Config — your resources, through a configuration aggregator.
-
AWS Security Hub CSPM — compliance findings.
-
AWS Trusted Advisor — recommendations.
-
AWS Cost Explorer — cost forecasts, cost allocation tags, and savings plan, reservation and rightsizing recommendations.
-
AWS Cost Optimization Hub — resource savings recommendations.
-
AWS Cost and Usage Report (CUR 2) — your cost and usage data, read from your S3 bucket.
Spotter reads this data by assuming a role you create in your own accounts. The next pages cover what to set up, which permissions the role needs, and how to create the integration in Spotter.