Skip to content

aws.config.describe_config_rule_evaluation_status

Example SQL Queries

SELECT * FROM
aws.config.describe_config_rule_evaluation_status;

Description

Returns status information for each of your Config managed rules. The status includes information such as the last time Config invoked the rule, the last time Config failed to invoke the rule, and the related error for the last failure.

Table Definition

Column NameColumn Data Type
config_rule_names Input Column

The name of the Config managed rules for which you want status information. If you do not specify any names, Config returns status information for all Config managed rules that you use.

VARCHAR[]
Show child fields
config_rule_names[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
config_rule_arn

The Amazon Resource Name (ARN) of the Config rule.

VARCHAR
config_rule_id

The ID of the Config rule.

VARCHAR
config_rule_name

The name of the Config rule.

VARCHAR
first_activated_time

The time that you first activated the Config rule.

TIMESTAMP_S
first_evaluation_started

Indicates whether Config has evaluated your resources against the rule at least once.

  • true - Config has evaluated your Amazon Web Services resources against the rule at least once.

  • false - Config has not finished evaluating your Amazon Web Services resources against the rule at least once.

BOOLEAN
last_deactivated_time

The time that you last turned off the Config rule.

TIMESTAMP_S
last_debug_log_delivery_status

The status of the last attempted delivery of a debug log for your Config Custom Policy rules. Either Successful or Failed.

VARCHAR
last_debug_log_delivery_status_reason

The reason Config was not able to deliver a debug log. This is for the last failed attempt to retrieve a debug log for your Config Custom Policy rules.

VARCHAR
last_debug_log_delivery_time

The time Config last attempted to deliver a debug log for your Config Custom Policy rules.

TIMESTAMP_S
last_error_code

The error code that Config returned when the rule last failed.

VARCHAR
last_error_message

The error message that Config returned when the rule last failed.

VARCHAR
last_failed_evaluation_time

The time that Config last failed to evaluate your Amazon Web Services resources against the rule.

TIMESTAMP_S
last_failed_invocation_time

The time that Config last failed to invoke the Config rule to evaluate your Amazon Web Services resources.

TIMESTAMP_S
last_successful_evaluation_time

The time that Config last successfully evaluated your Amazon Web Services resources against the rule.

TIMESTAMP_S
last_successful_invocation_time

The time that Config last successfully invoked the Config rule to evaluate your Amazon Web Services resources.

TIMESTAMP_S