Amazon Security Hub · Arazzo Workflow
Amazon Security Hub Triage and Update Findings
Version 1.0.0
Retrieve high-severity findings and update them by re-importing the modified records.
Provider
Workflows
triage-and-update-findings
Get findings by severity, then update them via re-import.
Retrieves findings filtered by severity label and compliance status, then re-imports the supplied set of updated findings to apply new workflow and severity values.
1
getFindings
GetFindings
Query Security Hub for findings matching the requested severity label and compliance status so they can be reviewed before updating.
2
updateFindings
BatchImportFindings
Re-import the supplied finding objects with their revised workflow status and severity so Security Hub applies the updated attributes.