Skip to main content

AWS GuardDuty

Describes an older version of the product

The Install the Application section is verified against the 2026-07 interface capture. Other platform-side steps on this page describe an earlier interface and have not been re-verified.

AWS GuardDuty combines ML and integrated threat intelligence from AWS and leading third parties to help protect AWS accounts, workloads, and data from threats. Fluency can ingest GuardDuty findings, allowing correlation with other data streams.

Fluency offers several CloudFormation scripts to facilitate integration. While these scripts are free to use, keep in mind that AWS CloudFormation is a paid service, and you will incur a charge from AWS for using it.

AWS CloudFormation allows you to configure AWS resources from script/code. This makes deployment easy, consistent, and greately decreases the possiblity of errors or misconfigurations.

For supported AWS integrations, deploying via CloudFormation is always recommended, if the script is avaliable.

Install the Application

Go to Platform → Applications → Install Application From Template and choose Amazon GuardDuty from the AWS Services category.

ParameterNotes
AWS RegionsMulti-select drop-down, opens on Select Values. Choose every region to collect findings from.
IAM access key
IAM access secret

Setup New Amazon GuardDuty Application panel

Press Install. The application then appears in the Installed Applications view, where its badge reads Running once the pipeline is up.

Fluency Integration Configuration

Sign in to your Fluency portal at https://<companyname>.app.ingext.io — see Fluency Web Interface for the URL formats.

Choose the Integrations option under the Platform menu in the navigation bar.

Navigation bar with the Platform menu open on the Integrations option

On the Integrations page, go to the New Integrations tab and choose the AWS GuardDuty integration, under Cloud Infrastructure (IaaS).

Integrations page with the New Integrations tab selected

Cloud Infrastructure (IaaS) section of the integration catalog

On the left-side panel, enter the required information:

Left-side panel with the AWS GuardDuty region and credential fields

Once added, the new integration will show up under Existing Integrations.