| Column Name | Column Data Type |
import_id Required Input Column
The ID of the import. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
created_timestamp
The timestamp of the import's creation. | TIMESTAMP_S |
destinations
The ARN of the destination event data store. | VARCHAR[] |
Show child fields- destinations[]
|
end_event_time
Used with StartEventTime to bound a StartImport request, and limit imported trail events to only those events logged within a specified time period. | TIMESTAMP_S |
import_source
The source S3 bucket. | STRUCT( "s3" STRUCT( "s3_location_uri" VARCHAR, "s3_bucket_region" VARCHAR, "s3_bucket_access_role_arn" VARCHAR ) ) |
Show child fields- import_source.s3
The source S3 bucket. Show child fields- import_source.s3.s3_bucket_access_role_arn
The IAM ARN role used to access the source S3 bucket.
- import_source.s3.s3_bucket_region
The Region associated with the source S3 bucket.
- import_source.s3.s3_location_uri
The URI for the source S3 bucket.
|
import_statistics
Provides statistics for the import. CloudTrail does not update import statistics in real-time. Returned values for parameters such as EventsCompleted may be lower than the actual value, because CloudTrail updates statistics incrementally over the course of the import. | STRUCT( "prefixes_found" BIGINT, "prefixes_completed" BIGINT, "files_completed" BIGINT, "events_completed" BIGINT, "failed_entries" BIGINT ) |
Show child fields- import_statistics.events_completed
The number of trail events imported into the event data store.
- import_statistics.failed_entries
The number of failed entries.
- import_statistics.files_completed
The number of log files that completed import.
- import_statistics.prefixes_completed
The number of S3 prefixes that completed import.
- import_statistics.prefixes_found
The number of S3 prefixes found for the import.
|
import_status
The status of the import. | VARCHAR |
start_event_time
Used with EndEventTime to bound a StartImport request, and limit imported trail events to only those events logged within a specified time period. | TIMESTAMP_S |
updated_timestamp
The timestamp of when the import was updated. | TIMESTAMP_S |