- Print
- DarkLight
Aqua CSPM (Cloud Security Posture Management) is a cloud-native security solution by Aqua Security, designed to monitor and secure cloud environments by identifying and mitigating configuration risks, compliance gaps, and threats. It provides continuous visibility into cloud infrastructure security across multiple cloud platforms, including AWS, Azure, and Google Cloud.
Integration Method: API
Tables: Compliance Finding, Scan Activity, Detection Finding
This integration has been tested against the Aqua Enterprise API v2.
Aqua CSPM Configuration
Aqua user requirements
You need an Aqua user to authenticate with the REST API before using any of the API endpoints. This user must be configured as follows:
Role: At least one of the user's roles includes one or more permission sets and application scopes, which meet the requirements defined below. There are no other requirements.
Permission set(s): Your applications will generally require either read-only and/or write access to certain types of Aqua Platform objects (e.g., images or security policies). In your permission set(s), assign View Only and/or Edit permissions, respectively, to these types of objects. Refer to Permission Sets for information on creating and configuring permission sets.
Application scope(s): Your applications will be able to access Aqua Platform objects within the application scope(s) associated with the user that has been authenticated. Refer to Application Scopes for information on creating and configuring application scopes.
Generate a CSPM API key and secret
Login to your Aqua Security dashboard account.
In Aqua Security UI, navigate to Account Management.
In the Account Management page, navigate to Settings > API Keys.
Click Generate Key.
Copy and save the API Key and Secret values before closing the pop-up window.
DataBee Configuration
Log into the DataBee console, navigate to the Data tab and click on the Add New Data Source button
Search for the Aqua CSPM option using the search bar in the Add New Data Source page.
Select the API Ingest option and enter appropriate details in the Configure Data source form. Click on Next button.
In the configuration details dialog, enter the following:
Authorization Method: HMAC Auth
Integration Key: Paste the generated API key
Secret Key: Paste the generated secret key
Click Submit