Do this after you've prepared your AWS environment and created the role.
-
Log in to Spotter.
-
Go to Admin → Integrations → AWS.
-
Click add new.
The form has three steps. All three are needed before you can save.
1. Master account
-
Account ID — the management (root) account ID of your AWS Organization.
-
Name — optional, a name to show in Spotter.
-
Role name — the name of the role you created, for example
Cloud2Spotter. -
External ID — shown here, ready to copy. Use it in the trust relationship of your role.
2. Security account
-
Account ID — the account where your Security Hub findings are collected.
-
Region — the region those findings are collected in.
3. Config account
-
Account ID — the account hosting your AWS Config aggregator.
-
Region — the region of the aggregator.
-
Aggregator name — the name you gave the aggregator.
Check the details and click add new to save. Data starts arriving on the next collection run.
Cost data
The CUR 2 export is set up separately — see AWS CUR 2 Export Setup for Spotter. Send the S3 URI to the Spotter team; there's no field for it in the form.
Adding more accounts later
Open the integration and use add security account or add config account if your findings or resources are collected in more than one account or region.