You can edit an existing custom insight to change the grouping value and filters. After you make the changes, you can save the updates to the original insight, or save the updated version as a new insight.
In AWS Security Hub, custom insights can be used to collect a specific set of findings and track issues that are unique to your environment. For background information about custom insights, see Understanding custom insights in Security Hub.
To edit a custom insight, choose your preferred method, and follow the instructions.
To edit a custom insight (console)
Open the AWS Security Hub console at https://console.aws.amazon.com/securityhub/
. -
In the navigation pane, choose Insights.
-
Choose the custom insight to modify.
-
Edit the insight configuration as needed.
-
To change the attribute used to group findings in the insight:
-
To remove the existing grouping, choose the X next to the Group by setting.
-
Choose the search box.
-
Select the attribute to use for grouping.
-
Choose Apply.
-
-
To remove a filter from the insight, choose the circled X next to the filter.
-
To add a filter to the insight:
-
Choose the search box.
-
Select the attribute and value to use as a filter.
-
Choose Apply.
-
-
-
When you complete the updates, choose Save insight.
-
When prompted, do one of the following:
-
To update the existing insight to reflect your changes, choose Update
<Insight_Name>
and then choose Save insight. -
To create a new insight with the updates, choose Save new insight. Enter an Insight name, and then choose Save insight.
-