Security & IAM
Amazon Security Lake
Amazon Security Lake builds and manages an S3-backed security data lake in the customer's account, normalizing supported AWS sources to Apache Parquet and the Open Cybersecurity Schema Framework for query and subscriber access.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon Security Lake.
Amazon Security Lake pricing and cost programs
Pricing model: Security data ingestion and storage usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Data ingestion · Normalization · S3 storage · Queries and subscriber access
Programs and modes: AWS source collection · Custom sources · Rollup Regions
Security Lake charges and connected S3, Glue, Athena, and event services can all contribute.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement Amazon Security Lake?
- Centralizes supported AWS, third-party, SaaS, on-premises, and custom security events while the customer retains ownership of the S3 data.
- Normalizes native AWS sources into OCSF and Parquet, partitions data, catalogs it with Glue, and exposes Lake Formation tables for analytics.
- Supports multi-account and multi-Region rollups, source-scoped data or query subscribers, and configurable retention and storage tiers.
How to implement Amazon Security Lake
- Designate a delegated administrator, choose source accounts and Regions, data-residency and rollup strategy, KMS key, source versions, custom-source OCSF contract, retention, owners, consumers, and query budget.
- Enable the data lake and sources centrally, verify delivery and schema, create data-access or query-access subscribers with only required sources and Regions, and connect Athena, OpenSearch, a SIEM, or other approved consumers.
- Run completeness and latency checks from source to table and subscriber, version queries for OCSF changes, configure lifecycle through Security Lake rather than editing S3 lifecycle directly, and monitor ingestion, storage, Glue, query, and subscriber cost.
Amazon Security Lake best practices
- Grant subscribers source-by-source least privilege, isolate third parties, protect Lake Formation, S3, KMS and cross-account roles, and audit every subscriber and custom source lifecycle.
- Set retention explicitly because the documented default stores data indefinitely in S3 Standard; account for Security Lake, S3, Glue, EventBridge, SQS, and query charges.
- Do not enable S3 Object Lock or manually modify lifecycle settings in ways the service warns can interrupt delivery or remove metadata; test OCSF field mappings and detection queries as schemas evolve.
Amazon Security Lake use cases and server impact
- Organization-wide security log normalization
- Long-horizon threat hunting with Athena or OpenSearch
- Feeding SIEM and incident-response subscribers
Replaces much security-lake ingestion, normalization, catalog, and sharing infrastructure, while source completeness, detection content, subscriber security, retention, query performance, and investigation remain yours.
Official implementation resources
Commonly paired AWS services
- Amazon GuardDuty — Threat detection
- AWS Security Hub — Security posture
- Amazon Macie — Sensitive data discovery
- Amazon Simple Storage Service — Object storage
- AWS Glue — Serverless ETL
- Amazon Athena — Query S3 with SQL
- AWS Lake Formation — Data lake governance
- AWS Key Management Service — Key management
Planning guides that use Amazon Security Lake
- Amazon Detective planning guide — Evaluate Security Lake integration and its separate data and cost boundaries where applicable.