Introducing Streamhouse: the open data architecture for AI | Learn More

Confluent + Amazon Security Lake

Confluent’s data streaming platform turbocharges Amazon Security Lake, enabling real-time monitoring and rapid incident response. Elevate your security game with the power of real-time data.

Streamline Your Security Data Operations

Data breaches can have a profound financial and brand impact – the global average cost of a data breach in 2023 is $4.3 million. To stay ahead of threats, Amazon Security Lake centralizes data from on-premises and cloud infrastructure, firewalls, and endpoint security solutions – from CloudTrail and Lambda to AWS Security Hub, GuardDuty, and the AWS Firewall Manager. The Open Cybersecurity Schema Framework (OCSF) makes it easy to integrate tools, allowing data to flow seamlessly into data lakes and analytics tools.

Confluent enhances the capabilities of Amazon Security Lake by providing real-time data streaming, integrations, and scalability for managing and processing security data. Gain visibility and valuable real-time insights into your security data, respond rapidly to security incidents, and leverage event-driven architecture to trigger automated remediation actions.

Stream and centralize security data at scale from any source (on-premises and in any cloud) into a single data lake.

Stream process high-volume data in real time, before it lands in Amazon Security Lake.

Derive real-time security insights and reduce incident response times.

Lower the TCO for lifecycle management of security data with fully managed services and leveraging a standards-based format.

Build with Confluent

This use case leverages the following building blocks in Confluent Cloud.

Reference Architecture

Data Ingestion

Produce events directly using one of Confluent’s client libraries (e.g., Java, C/C++, Python, Go, .NET) or leverage 120+ pre-built connectors to stream from relational DBs (e.g., Oracle, PostgreSQL, MySQL, SQL Server), SaaS apps, SIEM tools, and more.

Stream Processing

Confluent provides high scalability and availability to do stream processing on high-volume data using Flink.

Data Delivery

Use Confluent’s S3 sink connector to send OCSF events to a Security Lake-managed S3 bucket.

Stream Governance

Schema Registry allows you to set up and enforce specific schemas, like OCSF, at a topic level. Events that do not conform to OCSF will be rejected.

Resources

Book an Expert Consult