FAQ¶
Does AI SIEM require Log Processor?¶
Yes. AI SIEM deploys on the VPC and OpenSearch domain created by Log Processor. This avoids duplicating infrastructure and enables cross-domain correlation between logs, metrics, and security events.
Does any data leave my AWS account?¶
No customer data goes to any non-AWS endpoint. All processing runs inside your account, and playbook/report prose is generated by Amazon Bedrock in your own account and region — the threat context sent to Bedrock (principal, IP, account, region, resource identifiers, MITRE mapping) stays within AWS, and Bedrock does not retain it or train on it. The only calls that leave AWS are an entitlement check to verify your Marketplace subscription (no customer data transmitted) and, if you enable it, optional threat-intelligence feed lookups you can turn off.
Are identifiers kept out of the AI prompts?¶
Yes, always — on every tier, with no setting to turn it off. Real identifiers (IAM principals and ARNs, IP addresses, account and resource IDs) are replaced with type-preserving placeholders before anything is sent to Bedrock — the model sees <PUBLIC_IP> or <ROOT_PRINCIPAL>, not the literal value — and the real values are restored only when the result is shown to your analyst. For generated playbooks, the cached copy is stored with its identifiers redacted and the lookup map encrypted with a dedicated KMS key in your account, so real identifiers are never written to the AI cache in the clear. If a redacted identifier ever escapes into the model's output, the playbook is discarded and a safe deterministic template is used instead.
How quickly does it detect threats?¶
Static rules (known-bad patterns like impossible travel, credential stuffing) fire within minutes of event ingestion. ML behavioral anomalies require a 7–14 day baseline learning period before alerting.
What does auto-remediation actually do?¶
Enterprise tier only, opt-in per threat type. You map a threat to an AWS Systems Manager Automation runbook — an AWS-managed prebuilt (disable a key, isolate an instance, block public access), one of the samples AI SIEM ships, or your own — and AI SIEM runs it under an AutomationAssumeRole you create and scope. AI SIEM itself only calls StartAutomationExecution and reads status; it holds no standing IAM or EC2 write power, so a runbook can never do more than the role you granted. Every action can be staged for one-click approval, scheduled to a window, and auto-resolved on success; the request, approval, start, and outcome all land in the tamper-evident WORM audit trail. See response & remediation.
How does it compare to AWS Security Hub / GuardDuty / Detective?¶
AI SIEM correlates all of those into a single timeline with behavioral ML that learns your account's normal patterns. GuardDuty detects; AI SIEM correlates, explains, and responds. Security Hub aggregates; AI SIEM connects the dots into attack narratives.
What AWS infrastructure costs should I expect?¶
Depends on event volume. Typical: $20–$80/mo for Lambda, S3, DynamoDB, and Bedrock. OpenSearch is shared with Log Processor (no additional cluster cost). CloudTrail and VPC Flow Logs have their own AWS charges regardless of AI SIEM.
Won't VPC Flow Log processing get expensive?¶
Flow logs are the highest-volume source a SIEM handles, so AI SIEM defaults to an Athena mode that keeps their cost flat and predictable. Instead of running every flow record through the pipeline, flow logs stay in S3 and scheduled queries scan them for the patterns that matter — port scanning and large data egress. Cost scales with how often those queries run, not with your traffic volume or account count, and the built-in VPC Flow panel shows the estimated scan cost. Every flow log is still retained in S3 and fully queryable for forensics. Detection latency is a short sweep interval (roughly 15 minutes for port-scan, hourly for exfiltration) rather than seconds. You can also set detection thresholds per VPC and exclude VPCs you don't want scanned at all. See the flow-log cost guardrail.
Can I use it with AI Monitor and Log Processor?¶
Yes, and this is where the platform becomes more than the sum of its parts. All three products share one OpenSearch domain, so integration is zero-infrastructure — AI SIEM reads the anomalies the others already record, with nothing new to wire up.
- AI Monitor watches CloudWatch metrics (CPU, network, database connections) and records anomaly detections into the shared OpenSearch domain; AI SIEM reads them and merges them into its threat timeline. For severe network anomalies, AI SIEM can automatically enable detailed flow logging for just those minutes — capturing forensic detail at on-demand query cost. You control which subscriptions correlate from the editor.
- Log Processor ingests application and service logs and runs pattern detection on them. A per-pattern CloudWatch metric — error spikes, unusual query patterns, crash loops, failed-login spikes, a sudden log-volume drop — is baselined by AI Monitor, and a spike surfaces in AI SIEM as a correlated security event. This closes the biggest gap in AWS-native security: attacks that operate within permissions an application already has, never touching IAM, invisible to CloudTrail and GuardDuty.
See cross-signal correlation for architecture detail and examples.
How do I upgrade tiers?¶
Update the Tier parameter in CloudFormation and run a stack update. Non-destructive — all data is preserved. Feature gates activate immediately.