Skip to content

aws.cloudtrail.get_import

Example SQL Queries

SELECT * FROM
aws.cloudtrail.get_import
WHERE
"import_id" = 'VALUE';

Description

Returns information about a specific import.

Table Definition

Column NameColumn Data Type
import_id Required Input Column

The ID of the import.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
created_timestamp

The timestamp of the import's creation.

TIMESTAMP_S
destinations

The ARN of the destination event data store.

VARCHAR[]
Show child fields
destinations[]
end_event_time

Used with StartEventTime to bound a StartImport request, and limit imported trail events to only those events logged within a specified time period.

TIMESTAMP_S
import_source

The source S3 bucket.

STRUCT(
"s3" STRUCT(
"s3_location_uri" VARCHAR,
"s3_bucket_region" VARCHAR,
"s3_bucket_access_role_arn" VARCHAR
)
)
Show child fields
import_source.s3

The source S3 bucket.

Show child fields
import_source.s3.s3_bucket_access_role_arn

The IAM ARN role used to access the source S3 bucket.

import_source.s3.s3_bucket_region

The Region associated with the source S3 bucket.

import_source.s3.s3_location_uri

The URI for the source S3 bucket.

import_statistics

Provides statistics for the import. CloudTrail does not update import statistics in real-time. Returned values for parameters such as EventsCompleted may be lower than the actual value, because CloudTrail updates statistics incrementally over the course of the import.

STRUCT(
"prefixes_found" BIGINT,
"prefixes_completed" BIGINT,
"files_completed" BIGINT,
"events_completed" BIGINT,
"failed_entries" BIGINT
)
Show child fields
import_statistics.events_completed

The number of trail events imported into the event data store.

import_statistics.failed_entries

The number of failed entries.

import_statistics.files_completed

The number of log files that completed import.

import_statistics.prefixes_completed

The number of S3 prefixes that completed import.

import_statistics.prefixes_found

The number of S3 prefixes found for the import.

import_status

The status of the import.

VARCHAR
start_event_time

Used with EndEventTime to bound a StartImport request, and limit imported trail events to only those events logged within a specified time period.

TIMESTAMP_S
updated_timestamp

The timestamp of when the import was updated.

TIMESTAMP_S