Skip to content

aws.cloudwatch.describe_alarms

Example SQL Queries

SELECT * FROM
aws.cloudwatch.describe_alarms;

Description

Retrieves the specified alarms. You can filter the results by specifying a prefix for the alarm name, the alarm state, or a prefix for any action.

To use this operation and return information about composite alarms, you must be signed on with the cloudwatch:DescribeAlarms permission that is scoped to *. You can't return information about composite alarms if your cloudwatch:DescribeAlarms permission has a narrower scope.

Table Definition

Column NameColumn Data Type
action_prefix Input Column

Use this parameter to filter the results of the operation to only those alarms that use a certain alarm action. For example, you could specify the ARN of an SNS topic to find all alarms that send notifications to that topic.

VARCHAR
alarm_name_prefix Input Column

An alarm name prefix. If you specify this parameter, you receive information about all alarms that have names that start with this prefix.

If this parameter is specified, you cannot specify AlarmNames.

VARCHAR
alarm_names Input Column

The names of the alarms to retrieve information about.

VARCHAR[]
Show child fields
alarm_names[]
alarm_types Input Column

Use this parameter to specify whether you want the operation to return metric alarms or composite alarms. If you omit this parameter, only metric alarms are returned, even if composite alarms exist in the account.

For example, if you omit this parameter or specify MetricAlarms, the operation returns only a list of metric alarms. It does not return any composite alarms, even if composite alarms exist in the account.

If you specify CompositeAlarms, the operation returns only a list of composite alarms, and does not return any metric alarms.

VARCHAR[]
Show child fields
alarm_types[]
children_of_alarm_name Input Column

If you use this parameter and specify the name of a composite alarm, the operation returns information about the "children" alarms of the alarm you specify. These are the metric alarms and composite alarms referenced in the AlarmRule field of the composite alarm that you specify in ChildrenOfAlarmName. Information about the composite alarm that you name in ChildrenOfAlarmName is not returned.

If you specify ChildrenOfAlarmName, you cannot specify any other parameters in the request except for MaxRecords and NextToken. If you do so, you receive a validation error.

Only the Alarm Name, ARN, StateValue (OK/ALARM/INSUFFICIENT_DATA), and StateUpdatedTimestamp information are returned by this operation when you use this parameter. To get complete information about these alarms, perform another DescribeAlarms operation and specify the parent alarm names in the AlarmNames parameter.

VARCHAR
parents_of_alarm_name Input Column

If you use this parameter and specify the name of a metric or composite alarm, the operation returns information about the "parent" alarms of the alarm you specify. These are the composite alarms that have AlarmRule parameters that reference the alarm named in ParentsOfAlarmName. Information about the alarm that you specify in ParentsOfAlarmName is not returned.

If you specify ParentsOfAlarmName, you cannot specify any other parameters in the request except for MaxRecords and NextToken. If you do so, you receive a validation error.

Only the Alarm Name and ARN are returned by this operation when you use this parameter. To get complete information about these alarms, perform another DescribeAlarms operation and specify the parent alarm names in the AlarmNames parameter.

VARCHAR
state_value Input Column

Specify this parameter to receive information only about alarms that are currently in the state that you specify.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

composite_alarms

The information about any composite alarms returned by the operation.

STRUCT(
"actions_enabled" BOOLEAN,
"alarm_actions" VARCHAR[],
"alarm_arn" VARCHAR,
"alarm_configuration_updated_timestamp" TIMESTAMP_S,
"alarm_description" VARCHAR,
"alarm_name" VARCHAR,
"alarm_rule" VARCHAR,
"insufficient_data_actions" VARCHAR[],
"ok_actions" VARCHAR[],
"state_reason" VARCHAR,
"state_reason_data" VARCHAR,
"state_updated_timestamp" TIMESTAMP_S,
"state_value" VARCHAR,
"state_transitioned_timestamp" TIMESTAMP_S,
"actions_suppressed_by" VARCHAR,
"actions_suppressed_reason" VARCHAR,
"actions_suppressor" VARCHAR,
"actions_suppressor_wait_period" BIGINT,
"actions_suppressor_extension_period" BIGINT
)[]
Show child fields
composite_alarms[]
Show child fields
composite_alarms[].actions_enabled

Indicates whether actions should be executed during any changes to the alarm state.

composite_alarms[].actions_suppressed_by

When the value is ALARM, it means that the actions are suppressed because the suppressor alarm is in ALARM When the value is WaitPeriod, it means that the actions are suppressed because the composite alarm is waiting for the suppressor alarm to go into into the ALARM state. The maximum waiting time is as specified in ActionsSuppressorWaitPeriod. After this time, the composite alarm performs its actions. When the value is ExtensionPeriod, it means that the actions are suppressed because the composite alarm is waiting after the suppressor alarm went out of the ALARM state. The maximum waiting time is as specified in ActionsSuppressorExtensionPeriod. After this time, the composite alarm performs its actions.

composite_alarms[].actions_suppressed_reason

Captures the reason for action suppression.

composite_alarms[].actions_suppressor

Actions will be suppressed if the suppressor alarm is in the ALARM state. ActionsSuppressor can be an AlarmName or an Amazon Resource Name (ARN) from an existing alarm.

composite_alarms[].actions_suppressor_extension_period

The maximum time in seconds that the composite alarm waits after suppressor alarm goes out of the ALARM state. After this time, the composite alarm performs its actions.

ExtensionPeriod is required only when ActionsSuppressor is specified.

composite_alarms[].actions_suppressor_wait_period

The maximum time in seconds that the composite alarm waits for the suppressor alarm to go into the ALARM state. After this time, the composite alarm performs its actions.

WaitPeriod is required only when ActionsSuppressor is specified.

composite_alarms[].alarm_actions[]
composite_alarms[].alarm_arn

The Amazon Resource Name (ARN) of the alarm.

composite_alarms[].alarm_configuration_updated_timestamp

The time stamp of the last update to the alarm configuration.

composite_alarms[].alarm_description

The description of the alarm.

composite_alarms[].alarm_name

The name of the alarm.

composite_alarms[].alarm_rule

The rule that this alarm uses to evaluate its alarm state.

composite_alarms[].insufficient_data_actions[]
composite_alarms[].ok_actions[]
composite_alarms[].state_reason

An explanation for the alarm state, in text format.

composite_alarms[].state_reason_data

An explanation for the alarm state, in JSON format.

composite_alarms[].state_transitioned_timestamp

The timestamp of the last change to the alarm's StateValue.

composite_alarms[].state_updated_timestamp

Tracks the timestamp of any state update, even if StateValue doesn't change.

composite_alarms[].state_value

The state value for the alarm.

metric_alarms

The information about any metric alarms returned by the operation.

STRUCT(
"alarm_name" VARCHAR,
"alarm_arn" VARCHAR,
"alarm_description" VARCHAR,
"alarm_configuration_updated_timestamp" TIMESTAMP_S,
"actions_enabled" BOOLEAN,
"ok_actions" VARCHAR[],
"alarm_actions" VARCHAR[],
"insufficient_data_actions" VARCHAR[],
"state_value" VARCHAR,
"state_reason" VARCHAR,
"state_reason_data" VARCHAR,
"state_updated_timestamp" TIMESTAMP_S,
"metric_name" VARCHAR,
"namespace" VARCHAR,
"statistic" VARCHAR,
"extended_statistic" VARCHAR,
"dimensions" STRUCT(
"name" VARCHAR,
"value" VARCHAR
)[],
"period" BIGINT,
"unit" VARCHAR,
"evaluation_periods" BIGINT,
"datapoints_to_alarm" BIGINT,
"threshold" DOUBLE,
"comparison_operator" VARCHAR,
"treat_missing_data" VARCHAR,
"evaluate_low_sample_count_percentile" VARCHAR,
"metrics" STRUCT(
"id" VARCHAR,
"metric_stat" STRUCT(
"metric" STRUCT(
"namespace" VARCHAR,
"metric_name" VARCHAR,
"dimensions" STRUCT(
"name" VARCHAR,
"value" VARCHAR
)[]
),
"period" BIGINT,
"stat" VARCHAR,
"unit" VARCHAR
),
"expression" VARCHAR,
"label" VARCHAR,
"return_data" BOOLEAN,
"period" BIGINT,
"account_id" VARCHAR
)[],
"threshold_metric_id" VARCHAR,
"evaluation_state" VARCHAR,
"state_transitioned_timestamp" TIMESTAMP_S
)[]
Show child fields
metric_alarms[]
Show child fields
metric_alarms[].actions_enabled

Indicates whether actions should be executed during any changes to the alarm state.

metric_alarms[].alarm_actions[]
metric_alarms[].alarm_arn

The Amazon Resource Name (ARN) of the alarm.

metric_alarms[].alarm_configuration_updated_timestamp

The time stamp of the last update to the alarm configuration.

metric_alarms[].alarm_description

The description of the alarm.

metric_alarms[].alarm_name

The name of the alarm.

metric_alarms[].comparison_operator

The arithmetic operation to use when comparing the specified statistic and threshold. The specified statistic value is used as the first operand.

metric_alarms[].datapoints_to_alarm

The number of data points that must be breaching to trigger the alarm.

metric_alarms[].dimensions[]
Show child fields
metric_alarms[].dimensions[].name

The name of the dimension. Dimension names must contain only ASCII characters, must include at least one non-whitespace character, and cannot start with a colon (:). ASCII control characters are not supported as part of dimension names.

metric_alarms[].dimensions[].value

The value of the dimension. Dimension values must contain only ASCII characters and must include at least one non-whitespace character. ASCII control characters are not supported as part of dimension values.

metric_alarms[].evaluate_low_sample_count_percentile

Used only for alarms based on percentiles. If ignore, the alarm state does not change during periods with too few data points to be statistically significant. If evaluate or this parameter is not used, the alarm is always evaluated and possibly changes state no matter how many data points are available.

metric_alarms[].evaluation_periods

The number of periods over which data is compared to the specified threshold.

metric_alarms[].evaluation_state

If the value of this field is PARTIAL_DATA, the alarm is being evaluated based on only partial data. This happens if the query used for the alarm returns more than 10,000 metrics. For more information, see Create alarms on Metrics Insights queries.

metric_alarms[].extended_statistic

The percentile statistic for the metric associated with the alarm. Specify a value between p0.0 and p100.

metric_alarms[].insufficient_data_actions[]
metric_alarms[].metric_name

The name of the metric associated with the alarm, if this is an alarm based on a single metric.

metric_alarms[].metrics[]
Show child fields
metric_alarms[].metrics[].account_id

The ID of the account where the metrics are located.

If you are performing a GetMetricData operation in a monitoring account, use this to specify which account to retrieve this metric from.

If you are performing a PutMetricAlarm operation, use this to specify which account contains the metric that the alarm is watching.

metric_alarms[].metrics[].expression

This field can contain either a Metrics Insights query, or a metric math expression to be performed on the returned data. For more information about Metrics Insights queries, see Metrics Insights query components and syntax in the Amazon CloudWatch User Guide.

A math expression can use the Id of the other metrics or queries to refer to those metrics, and can also use the Id of other expressions to use the result of those expressions. For more information about metric math expressions, see Metric Math Syntax and Functions in the Amazon CloudWatch User Guide.

Within each MetricDataQuery object, you must specify either Expression or MetricStat but not both.

metric_alarms[].metrics[].id

A short name used to tie this object to the results in the response. This name must be unique within a single call to GetMetricData. If you are performing math expressions on this set of data, this name represents that data and can serve as a variable in the mathematical expression. The valid characters are letters, numbers, and underscore. The first character must be a lowercase letter.

metric_alarms[].metrics[].label

A human-readable label for this metric or expression. This is especially useful if this is an expression, so that you know what the value represents. If the metric or expression is shown in a CloudWatch dashboard widget, the label is shown. If Label is omitted, CloudWatch generates a default.

You can put dynamic expressions into a label, so that it is more descriptive. For more information, see Using Dynamic Labels.

metric_alarms[].metrics[].metric_stat

The metric to be returned, along with statistics, period, and units. Use this parameter only if this object is retrieving a metric and not performing a math expression on returned data.

Within one MetricDataQuery object, you must specify either Expression or MetricStat but not both.

Show child fields
metric_alarms[].metrics[].metric_stat.metric

The metric to return, including the metric name, namespace, and dimensions.

Show child fields
metric_alarms[].metrics[].metric_stat.metric.dimensions[]
Show child fields
metric_alarms[].metrics[].metric_stat.metric.dimensions[].name

The name of the dimension. Dimension names must contain only ASCII characters, must include at least one non-whitespace character, and cannot start with a colon (:). ASCII control characters are not supported as part of dimension names.

metric_alarms[].metrics[].metric_stat.metric.dimensions[].value

The value of the dimension. Dimension values must contain only ASCII characters and must include at least one non-whitespace character. ASCII control characters are not supported as part of dimension values.

metric_alarms[].metrics[].metric_stat.metric.metric_name

The name of the metric. This is a required field.

metric_alarms[].metrics[].metric_stat.metric.namespace

The namespace of the metric.

metric_alarms[].metrics[].metric_stat.period

The granularity, in seconds, of the returned data points. For metrics with regular resolution, a period can be as short as one minute (60 seconds) and must be a multiple of 60. For high-resolution metrics that are collected at intervals of less than one minute, the period can be 1, 5, 10, 30, 60, or any multiple of 60. High-resolution metrics are those metrics stored by a PutMetricData call that includes a StorageResolution of 1 second.

If the StartTime parameter specifies a time stamp that is greater than 3 hours ago, you must specify the period as follows or no data points in that time range is returned:

  • Start time between 3 hours and 15 days ago - Use a multiple of 60 seconds (1 minute).

  • Start time between 15 and 63 days ago - Use a multiple of 300 seconds (5 minutes).

  • Start time greater than 63 days ago - Use a multiple of 3600 seconds (1 hour).

metric_alarms[].metrics[].metric_stat.stat

The statistic to return. It can include any CloudWatch statistic or extended statistic.

metric_alarms[].metrics[].metric_stat.unit

When you are using a Put operation, this defines what unit you want to use when storing the metric.

In a Get operation, if you omit Unit then all data that was collected with any unit is returned, along with the corresponding units that were specified when the data was reported to CloudWatch. If you specify a unit, the operation returns only data that was collected with that unit specified. If you specify a unit that does not match the data collected, the results of the operation are null. CloudWatch does not perform unit conversions.

metric_alarms[].metrics[].period

The granularity, in seconds, of the returned data points. For metrics with regular resolution, a period can be as short as one minute (60 seconds) and must be a multiple of 60. For high-resolution metrics that are collected at intervals of less than one minute, the period can be 1, 5, 10, 30, 60, or any multiple of 60. High-resolution metrics are those metrics stored by a PutMetricData operation that includes a StorageResolution of 1 second.

metric_alarms[].metrics[].return_data

When used in GetMetricData, this option indicates whether to return the timestamps and raw data values of this metric. If you are performing this call just to do math expressions and do not also need the raw data returned, you can specify false. If you omit this, the default of true is used.

When used in PutMetricAlarm, specify true for the one expression result to use as the alarm. For all other metrics and expressions in the same PutMetricAlarm operation, specify ReturnData as False.

metric_alarms[].namespace

The namespace of the metric associated with the alarm.

metric_alarms[].ok_actions[]
metric_alarms[].period

The period, in seconds, over which the statistic is applied.

metric_alarms[].state_reason

An explanation for the alarm state, in text format.

metric_alarms[].state_reason_data

An explanation for the alarm state, in JSON format.

metric_alarms[].state_transitioned_timestamp

The date and time that the alarm's StateValue most recently changed.

metric_alarms[].state_updated_timestamp

The time stamp of the last update to the value of either the StateValue or EvaluationState parameters.

metric_alarms[].state_value

The state value for the alarm.

metric_alarms[].statistic

The statistic for the metric associated with the alarm, other than percentile. For percentile statistics, use ExtendedStatistic.

metric_alarms[].threshold

The value to compare with the specified statistic.

metric_alarms[].threshold_metric_id

In an alarm based on an anomaly detection model, this is the ID of the ANOMALY_DETECTION_BAND function used as the threshold for the alarm.

metric_alarms[].treat_missing_data

Sets how this alarm is to handle missing data points. The valid values are breaching, notBreaching, ignore, and missing. For more information, see Configuring how CloudWatch alarms treat missing data.

If this parameter is omitted, the default behavior of missing is used.

metric_alarms[].unit

The unit of the metric associated with the alarm.