Issue
A GuardDuty finding is visible in AWS but not found in the Red Canary Portal. The GuardDuty alerts are being processed status check is passing for the affected account and other findings from that account can be seen on the Alerts page.
Environment
Red Canary Portal
AWS Integration
Resolution
There are a few things to verify when an expected GuardDuty finding is not found in search results on the Alerts page.
- Adjust time range in search filter: Search through your Red Canary Portal alerts by the finding's Created At timestamp in GuardDuty, rather than the Last Seen or Updated At timestamp.
- Check for GuardDuty suppressions: Lift any relevant rules that may be suppressing the affected finding.
Cause
GuardDuty findings are stored in Red Canary based on the Created At timestamp in AWS. If searching by the timestamp of when the finding last reasserted (i.e. Last Seen/Updated At), the finding will appear missing in Red Canary as these reassertions are typically appended to the original alert record.
If a finding is archived by a suppression rule, the suppressed finding will not be ingested into Red Canary.