All Services

Security & IAM

Amazon Security Lake

Amazon Security Lake builds and manages an S3-backed security data lake in the customer's account, normalizing supported AWS sources to Apache Parquet and the Open Cybersecurity Schema Framework for query and subscriber access.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon Security Lake.

Amazon Security Lake pricing and cost programs

Pricing model: Security data ingestion and storage usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Data ingestion · Normalization · S3 storage · Queries and subscriber access

Programs and modes: AWS source collection · Custom sources · Rollup Regions

Security Lake charges and connected S3, Glue, Athena, and event services can all contribute.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement Amazon Security Lake?

  • Centralizes supported AWS, third-party, SaaS, on-premises, and custom security events while the customer retains ownership of the S3 data.
  • Normalizes native AWS sources into OCSF and Parquet, partitions data, catalogs it with Glue, and exposes Lake Formation tables for analytics.
  • Supports multi-account and multi-Region rollups, source-scoped data or query subscribers, and configurable retention and storage tiers.

How to implement Amazon Security Lake

  1. Designate a delegated administrator, choose source accounts and Regions, data-residency and rollup strategy, KMS key, source versions, custom-source OCSF contract, retention, owners, consumers, and query budget.
  2. Enable the data lake and sources centrally, verify delivery and schema, create data-access or query-access subscribers with only required sources and Regions, and connect Athena, OpenSearch, a SIEM, or other approved consumers.
  3. Run completeness and latency checks from source to table and subscriber, version queries for OCSF changes, configure lifecycle through Security Lake rather than editing S3 lifecycle directly, and monitor ingestion, storage, Glue, query, and subscriber cost.

Amazon Security Lake best practices

  • Grant subscribers source-by-source least privilege, isolate third parties, protect Lake Formation, S3, KMS and cross-account roles, and audit every subscriber and custom source lifecycle.
  • Set retention explicitly because the documented default stores data indefinitely in S3 Standard; account for Security Lake, S3, Glue, EventBridge, SQS, and query charges.
  • Do not enable S3 Object Lock or manually modify lifecycle settings in ways the service warns can interrupt delivery or remove metadata; test OCSF field mappings and detection queries as schemas evolve.

Amazon Security Lake use cases and server impact

  • Organization-wide security log normalization
  • Long-horizon threat hunting with Athena or OpenSearch
  • Feeding SIEM and incident-response subscribers

Replaces much security-lake ingestion, normalization, catalog, and sharing infrastructure, while source completeness, detection content, subscriber security, retention, query performance, and investigation remain yours.

Official implementation resources

Commonly paired AWS services

Planning guides that use Amazon Security Lake