Skip to content
Notifications
Clear all

What is the best way to handle alerting for our 100+ AWS accounts?

1 Posts
1 Users
0 Reactions
1 Views
(@clarak)
Active Member
Joined: 1 day ago
Posts: 3
Topic starter   [#21539]

Our organization is currently evaluating Lacework as a potential central platform for security and compliance monitoring across a multi-account AWS environment, which currently stands at over 100 accounts and is expected to scale. The primary objective is to consolidate and rationalize alerting to reduce noise and operational fatigue, while ensuring critical findings are actioned appropriately.

I have conducted a preliminary analysis of Lacework's capabilities against our requirements, but I am seeking insights from practitioners who have implemented it at a similar scale. My core concerns are as follows:

* **Alert Routing & Hierarchical Structure:** With accounts spanning multiple business units and environments (prod, dev, staging), a single, flat alerting channel is untenable. What is the recommended strategy for mapping Lacework alerts to specific on-call teams? Is the primary method through integration with existing ticketing systems (e.g., ServiceNow, Jira), or are you leveraging the platform's native capabilities to segment by AWS account, resource tag, or specific policy violation?
* **Policy Customization & Noise Reduction:** The out-of-the-box policies are comprehensive but can generate significant volume. For those with large deployments, what has been your approach to policy tuning? Are you creating custom policies based on your specific compliance frameworks, and how effective has the policy exception process been for handling acceptable deviations?
* **Cost Implications of Scale:** Lacework's pricing model is based on a combination of data ingestion and monitored cloud resources. At our scale, even minor per-resource costs aggregate significantly. Have you implemented specific filtering or data exclusion strategies at the account or resource level to manage costs without compromising security posture? What was the impact on alert efficacy?
* **Operational Workflow Integration:** How are you handling the lifecycle of an alert—from detection in Lacework, to assignment, through to remediation verification? I am particularly interested in any automation you've built to close the loop, such as triggering AWS Systems Manager documents or Lambda functions directly from Lacework alerts.

The theoretical documentation is clear, but I am looking for empirical data on pitfalls, performance at scale, and the actual administrative overhead required to maintain an effective alerting regime. Comparisons to a previous toolset or a multi-tool approach would also be valuable context.



   
Quote